Responsibilities
- Provide data analytics support and expertise in data science for specialized cybersecurity applications and big data analytical systems.
- Collect and analyze information on enterprise data sources, formats, and key stakeholder use cases.
- Transform data sets into a common schema by merging various event types to create enriched datasets.
- Assist in technical design, documentation, testing, and resolution of identified bugs/defects.
- Support the consolidation of metadata, data management, and search tools into a comprehensive Cybersecurity Data Catalog.
- Translate data into actionable insights through intelligent analytics.
- Define raw input requirements for data models, ensuring quick analysis and summary reporting for informed decision-making.
- Meet professional obligations through efficient work habits, including meeting deadlines, honoring schedules, and coordinating resources and meetings effectively.
Requirements
- Must be able to obtain Public Trust clearance
- Bachelor’s degree or equivalent with 7 years of related experience; or Master’s degree with 3-5 years of experience.
- Minimum 5 years of Linux scripting and automation experience using Bash, Python, and/or Java.
- Experience in installing and administering COTS applications on RHEL and/or CentOS Linux.
- Proficient in building, monitoring, tuning, and troubleshooting AWS instances.
- Ansible Automation expertise (or similar tool).
- Working knowledge of Elastic; DevOps experience is preferred.
- Provide development support for emerging requirements in event ingest and transformation into a common data schema.
- Design and develop Elastic Beats or Logstash configurations for efficient data collection.
- Establish and implement a Data Governance Workflow, emphasizing metadata, data sources, data quality, policies, and procedures.
Nice to Have
- Elastic Certified Engineer: Focuses on managing Elasticsearch clusters, developing search solutions, and cluster maintenance.
- Elastic Certified Analyst: Focuses on using Kibana for data visualization, building advanced dashboards, and detecting anomalies.
- Elastic Certified Observability Engineer: Focuses on unifying logs, metrics, and APM traces to monitor and troubleshoot complex ecosystems.
- Elastic Certified SIEM Analyst: Focuses on threat hunting and using Elastic Security for SIEM.
Work Arrangement
Remote (City/Region) — Alexandria, VA
Additional Information
- Applicants selected will be subject to a security investigation and must meet eligibility requirements for access to classified information
- Must be local to the D.C. Metro area
- This role supports remote work