ECS is seeking a Elastic Security Education & Enablement Consultant to work remotely. Please Note: This position is contingent upon contract award.
As a leading managed cybersecurity services provider, ECS delivers highly tailored cybersecurity solutions aligned to each customer’s mission needs. The Professional Services Team partners with customers to understand their environment, strengthen security posture, and deliver measurable outcomes across detection, response, and continuous improvement.
We are seeking an Education & Training Consultant with Elastic Security expertise to lead customer enablement, training delivery, and knowledge transfer efforts while also serving as a Security Analyst supporting Elastic Security operations and use cases. This role requires strong instructional and communication skills, the ability to translate technical concepts for diverse audiences, and hands-on experience with Elastic Security to support customer training, investigations, and best practice adoption.
Key Responsibilities
- Customer Training & Enablement (Primary): Develop and deliver instructor-led and virtual training sessions focused on Elastic Security, SIEM operations, threat detection, investigation workflows, and cybersecurity best practices.
- Curriculum Development: Create and maintain training materials, presentations, hands-on labs, student guides, exercises, and knowledge transfer documentation tailored to customer requirements.
- Learning Assessment & Adoption: Evaluate learner progress, gather feedback, and recommend improvements to training programs to maximize operational readiness and adoption.
- Elastic Platform Instruction: Teach customers how to effectively use Elastic Security, Kibana dashboards, detections, case management, visualizations, and reporting capabilities.
- Workshop Facilitation: Lead technical workshops, demonstrations, tabletop exercises, and hands-on sessions for security analysts, administrators, and leadership stakeholders.
- Knowledge Transfer: Support customer transitions through structured knowledge-sharing sessions and operational handoff activities.
- SIEM Operations (Elastic Security): Use Elastic Security to analyze security events, investigate alerts, identify indicators of compromise, and support customer security operations.
- Threat Detection & Analysis: Correlate data across network, cloud, and endpoint telemetry to identify suspicious activity and recommend investigative actions.
- Content Development: Develop and tune detections, dashboards, visualizations, and security content aligned with customer operational objectives.
- Incident Response Support: Assist customers with alert triage, incident investigations, containment recommendations, and root cause analysis activities.
- Threat Research: Research emerging threats, vulnerabilities, and adversary techniques to improve customer awareness and detection capabilities.
- Operational Documentation: Develop and maintain runbooks, training documentation, standard operating procedures, and best practices.
Salary Range: $100,000-$115,000
General Description of Benefits
Qualifications
- 2+ years of experience delivering technical training, cybersecurity education, or customer enablement programs
- Elastic Security proficiency including monitoring, detection, investigation, dashboards, and reporting capabilities
- Strong presentation, facilitation, and instructional communication skills
- Experience developing training materials, course content, lab exercises, or technical documentation
- Strong cybersecurity fundamentals including network protocols, common attack techniques, and security operations concepts
- Strong analytical skills for identifying patterns and anomalies across multiple data sources
- Experience supporting security investigations, alert triage, or threat analysis activities
- Strong written and verbal communication skills
- Ability to engage with technical and non-technical audiences
- Willingness to support domestic or international travel (short, planned engagements)
- Must possess and maintain a U.S. Passport
- Must have a Secret clearance, at minimum