Enterprise Logging Solution (ELS) Engineer
Accenturefederalservices · Washington, DC
About this role
## Enterprise Logging Solution (ELS) Engineer ### Overview Supports the Enterprise Logging Solution (ELS)/SIEM environment that provides centralized security monitoring and audit/reporting capabilities for agency System Owners, ISSMs/ISSOs, and the SOC—covering architecture, implementation, and ongoing operations & maintenance (on-premise and cloud). ### Key Responsibilities - Analyze, develop, and test ELS/SIEM enhancements using vendor/industry best practices; assess current capabilities against security/logging regulations and perform gap analyses. - Migrate/implement ELS/SIEM architecture in cloud and/or on-premise environments; architect and integrate streaming processing for data onboarding/ingestion. - Create implementation plans (including communications plans) for approved enhancements; verify test configurations and present change requests at Change Control Board meetings. - Onboard newly added systems into the ELS/SIEM (data design requirements, data collection, ingestion scheduling/testing) with System Owners/ISSOs and the Government ELS Team Lead. - Build dashboards for System Owners, ISSM/ISSO, executive management, and developers; maintain a Master Project Schedule reviewed bi-weekly with Government leadership. - Maintain SIEM collection/aggregation of IDS, firewall, proxy, DLP, antivirus, cloud log, and vulnerability-scanner data sources; operate streaming ingestion/analysis solutions. - Develop correlation rules, signatures, and risk-based scoring enhancements; maintain whitelists/blacklists for improved SIEM tuning. - Develop, deploy, and/or integrate Machine Learning (ML) and Artificial Intelligence (AI) into the Agency’s ELS/SIEM. - Provide general user support for ELS/SIEM dashboard use (including ISSO audit dashboard functionality) and respond to system-outage/data-feed issues. ### Basic Qualifications - Minimum **7 years** of experience in system administration, database administration, network engineering, software engineering, or software development with a concentration in **Cyber Security**; **or** - With a bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field: **5 years** of such experience. ### Preferred Certifications - Splunk Certified Architect - Splunk Certified Admin
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.