The Elastic Security Engineer will design, build, and maintain enterprise Elastic Stack solutions within a Federal DoD environment. They will also automate deployments using Ansible and perform continuous data normalization to support cyber operations.
Elastic Security Engineer (SIEM)
Location: Sierra Vista, AZ / Remote Employment Type: Full-Time
About SERVISS
At SERVISS, we deliver cutting-edge cybersecurity and IT solutions to government and commercial clients, with a mission to secure systems, data, and critical infrastructure through innovation and expertise. We don’t just deploy tools; we engineer mission platforms that become foundational systems of record for cyber operations, compliance automation, and national cyber readiness. From CISA CDM to DoW mission enclaves, our work shapes how government sees, governs, and defends its digital terrain.
As a provider of managed cybersecurity services, SERVISS delivers a highly tailored offering to each customer. Our mission is broad and our teams are agile; we look to your unique skills to approach and solve problems in your own way, whether engineering a system to clear a technical hurdle, protecting customer data, or consulting across a wide range of security topics. You are empowered to engage and lead across multiple groups.
Position Summary
SERVISS is seeking an Elastic Security Engineer to support a Federal DoD SIEM program. This is a technical, hands-on role in which you will work within a multi-disciplined team to design, build, secure, maintain, optimize, and document multiple Elastic Stack enterprise solutions (Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and SIEM) deployed globally in a Federal DoD environment, with automation support using Ansible.
You will perform continuous data-normalization functions and support the delivery of written technical deliverables such as SOPs and process workflows to optimize tool usage and contribute to new capabilities. Your infrastructure, data pipelines, and reporting automation will directly support internal engineering personnel and external customer requirements.
The Work
This is a hands-on engineering role. The selected candidate will:
Design, build, secure, maintain, optimize, and document multiple Elastic Stack enterprise solutions (Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and SIEM) deployed globally in a Federal DoD environment
Automate deployment and configuration using Ansible playbooks
Perform continuous data-normalization functions across diverse data sources
Build data pipelines and reporting automation that directly support internal engineering personnel and external customer requirements
Author written technical deliverables such as SOPs and process workflows to optimize tool usage and contribute to new capabilities
Key Responsibilities
Support a Federal DoD SIEM program as part of a multi-disciplined engineering team
Maintain, optimize, and secure enterprise Elastic Stack solutions deployed globally
Contribute to new capabilities and the continuous improvement of tool usage
Engage and collaborate across engineering teams and customer stakeholders
Required Qualifications
Active Top Secret security clearance
US citizenship
Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
At least 4 years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use cases (Elastic SIEM experience a plus)
Demonstrated experience with the full Elastic Stack: Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
Demonstrated ability to use Ansible playbooks
Preferred Qualifications
Experience integrating Elasticsearch with external systems (e.g., SOAR tools, threat intelligence platforms)
Experience with data management: hot/warm/cold architectures, shard allocation and re-allocation, snapshots and restoration
Strong experience evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administration
Experience integrating Elasticsearch with authentication mechanisms such as SAML, LDAP, and PKI
Experience supporting the Elastic Stack in on-prem and SaaS environments, including system monitoring and tuning
Experience securing the Elastic Stack and hardening hosting environments
Development experience in multiple languages (Python, Bash, PowerShell, Painless, etc.)
Experience designing and implementing highly scalable Elastic Stack solutions
Experience developing data structures and data mappings from various sources to achieve data normalization using Elastic Common Schema (ECS)
Experience developing custom Kibana visualizations and dashboards
Experience developing custom reporting solutions using APIs that leverage Elasticsearch and ElastiCache
Experience with end-to-end low-level design, development, administration, and delivery of Elasticsearch-based reporting solutions
Strong technical foundation in building reliable, scalable, and supportable systems
Experience with Red Hat Enterprise Linux deployment and administration
Freedom to Thrive.
Why Join SERVISS? Our goal as an employer is simple yet profound: to create an environment where you can be your best self, pursue your passions, and enjoy the freedom to thrive both personally and professionally. Your success is our success, and we're committed to supporting you every step of the way.
Highly competitive compensation and best in class benefits
100% of medical, vision, dental, and life insurance premiums paid for by SERVISS
Be part of an exciting company with ground floor opportunities in the Equity Participation Program
Opportunities for annual performance bonuses and growth incentives
401(k) retirement plan with 6% dollar for dollar match
Additional Considerations for HUBZone applicants: Preference may be given to applicants residing in a federal HUBZone in support of SERVISS LLC’s HUBZone workforce objectives; all qualified candidates are encouraged to apply.
How to Determine HUBZone Residency: Candidates can verify HUBZone eligibility by entering their home address into the SBA HUBZone Map at https://maps.certify.sba.gov/hubzone/map. If your residence falls within a designated HUBZone area on the map, you are considered a HUBZone resident for hiring preference purposes.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”