Today
Intel Agency (NSA, CIA, FBI, etc)
Unspecified
Polygraph
IT - Security
Remote/Hybrid• (Off-Site/Hybrid)
Endgame Systems, LLC provides consulting services related to Elastic technology to Government agencies with heightened security needs. Endgame Systems, LLC is a wholly-owned subsidiary of Elastic. Elastic is a free and open search company that powers enterprise search, observability, and security solutions built on one technology stack that can be deployed anywhere. From finding documents to monitoring infrastructure to hunting for threats, Elastic makes data usable in real-time and at scale. Thousands of organizations worldwide, including Barclays, Cisco, eBay, Fairfax, ING, Goldman Sachs, Microsoft, The Mayo Clinic, NASA, The New York Times, Wikipedia, and Verizon, use Elastic to power mission-critical systems. Founded in 2012, Elastic is a distributed company with Elasticians around the globe. Learn more at elastic.co . Endgame Systems, LLC, while a subsidiary of Elastic, is an independent entity focused on Government services.
Purpose
Elastic's Security Analyst will leverage cyber hunt methodologies to drive customer success, product adoption, and renewals. This individual will deliver consulting to customers in the US PUBSEC market. This role will engage directly with customers to solve their most challenging cyber security challenges, leveraging Elastic.
Responsibilities
AFS Addem
Tier 1 Analyst duties and responsibilities:
Tier 2 Analyst duties and responsibilities:
Join Elastic's Federal Consulting Team and help public sector organizations solve their most complex data challenges using the Elastic Stack. If you're passionate about cutting-edge technology, customer success, and working in mission-critical environments, we'd love to hear from you!
Compensation:
Compensation for this role is in the form of base salary. This role does not have a variable compensation component.
The typical starting salary range for new hires in this role is listed below. In select locations (including Seattle WA, Los Angeles CA, the San Francisco Bay Area CA, and the New York City Metro Area), an alternate range may apply as specified below.
These ranges represent the lowest to highest salary we reasonably and in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the ranges may be modified in the future.
An employee's position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs.
Elastic believes that employees should have the opportunity to share in the value that we create together for our shareholders. Therefore, in addition to cash compensation, this role is currently eligible to participate in Elastic's stock program. Our total rewards package also includes a company-matched 401k with dollar-for-dollar matching up to 6% of eligible earnings, along with a range of other benefits offered with a holistic emphasis on employee well-being.
The typical starting salary range for this role is:
$113,100 - $152,600 USD
Additional Information - We Take Care of Our People
As a distributed company, diversity drives our identity. Whether you're looking to launch a new career or grow an existing one, Endgame Systems is the type of company where you can balance great work with great life. Your age is only a number. It doesn't matter if you're just out of college or your children are; we need you for what you can do.
We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.
Different people approach problems differently. We need that. Endgame Systems is an equal opportunity/affirmative action employer committed to diversity, equity, and inclusion. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.
We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email candidate_accessibility@elastic.co We will reply to your request within 24 business hours of submission.
Applicants have rights under Federal Employment Laws, view posters linked below: Family and Medical Leave Act (FMLA) Poster; Pay Transparency Nondiscrimination Provision Poster; Employee Polygraph Protection Act (EPPA) Poster and Know Your Rights (Poster)
Please see here for our Privacy Statement.
Purpose
Elastic's Security Analyst will leverage cyber hunt methodologies to drive customer success, product adoption, and renewals. This individual will deliver consulting to customers in the US PUBSEC market. This role will engage directly with customers to solve their most challenging cyber security challenges, leveraging Elastic.
Responsibilities
- Deliver consulting aligned with up-to-date product strategies and general business needs
- Possess a solid familiarity with the MITRE ATT&CK framework and advanced attacker techniques
- Support, perform, and troubleshoot hardware and software installations independently
- Recognize and analyze malware based on a combination of behavioral activity and signature-based tippers
- Support the creation and maintenance of quality customer-facing documentation and self-help resources, including product implementation documentation and best practices.
- Understand customer business needs and use cases, driving product improvements
- Continually seek opportunities to increase customer satisfaction and deepen customer relationships, driving product adoption, expansion and renewals
- Specific tasks may include but are not limited to:
- Build visualizations/dashboards
- GenAI LLM features (Attack Discovery and Security Assistant)
- Build reports (canvas)
- Building rules
- KQL
- EQL
- ES|QL
- ML
- Indicator Match
- threshold
- Elastic integrations
- Tuning rules
- Apply an understanding of frequency analysis and how to tune out the most noisy false positives to give customers better visibility into lower frequency events that need to be investigated
- Understand and enable customers on the following workflows:
- Alert triage
- Cases
- Timeline
- Visualizations
- Integrations
- Elastic Agent Deployment strategies/ best practices
- Elastic Defend Installation
- Elastic Defend response actions
- Apply cybersecurity best practices
- Translate how to achieve any action from a previous SIEM or security tool in Elastic
- Understand latest threats and trends, and explain how Elastic helps secure customers form those threats
- Familiarity with host-based logs (Windows | Unix)
- Identify anomalous activity or potential threats in a customer environment
- Assist customers with root cause analysis of identified threats
- Identify gaps in customer security posture and make recommendations for improvement
- Assist the customer with threat hunting activities, such as:
- Building and tuning queries for threat hunts
- Explaining threat hunt results as they appear in Elastic
- Understand and describe pipeline requirements to assist engineers with data onboarding needs
- Other duties as assigned
- Bachelor's Degree in Computer Science or related field and 4+ years of security training, software implementation, consulting, customer support, SOC, IR, or related experience with demonstrated accomplishments in the role
- Strong understanding of Windows, Mac, and Linux internals, administration, and troubleshooting as well as experience with large-scale, complex enterprise troubleshooting
- Solid understanding of cyber adversary tactics, techniques, and procedures to help customers use Elastic to detect sophisticated adversaries, triage alerts, and respond to potential incidents.
- Ability to demonstrate business value of technical solutions
- Excellent verbal and written communication skills, training and presentation skills
- Strong work-ethic and committed to quality
- Disciplined, organized and methodical in approach to projects and tasks
- Able to travel up to 50% of the time
- Great presentation skills with the ability to speak in front of audiences both large and small
- Exceptional Communication: Ability to articulate complex technical concepts clearly and concisely to diverse audiences. Skilled in listening to clients' needs and effectively conveying solutions.
- Relationship Building: Strong capacity to build and maintain professional relationships with clients, demonstrating understanding and respect for their unique needs and objectives.
- Consultative Mindset: Proven ability to provide insightful advice and guidance to clients, using technical knowledge to inform recommendations.
- Empathy and Patience: Exceptional ability to empathize with clients, understand their challenges, and handle their concerns with patience and professionalism.
- Negotiation and Persuasion: Ability to negotiate effectively, aligning the interests of multiple parties and persuading clients or stakeholders when necessary.
- Client Education: Strong capability for teaching clients about technical systems and solutions, helping them understand and make the most of the technology.
- Cultural Awareness: Understanding and respect for cultural differences and diversity within the client base, facilitating effective communication and relationship-building.
AFS Addem
Tier 1 Analyst duties and responsibilities:
- Alert monitoring and triage
- Monitor alerts from on boarded data sources in real-time
- Add exceptions to rules based upon confirmed FPs
- Perform initial alert investigation and triage to determine the validity of the alert and severity
- Follow established playbooks for common alert types. Examples are adding alerts to a case, initial timeline analysis, and visualization building in lens
- Initial Incident Response
- Document related or relevant events in timeline and cases
- Coordinate with Tier 2 and escalate when needed
- Threat Analysis
- On board threat intel sources
- Understand how Indicator Match rules work and when to use them/ limitations.
- Create indicator match rules for on boarded TI feeds
- Write and refine rules using KQL, EQL, ES|QL, and other query languages.
- Customize OOTB rules for customer environment
- Manage Elastic Defend installation
- Utilize machine learning models (ML) for security tuning.
- Understanding of the Protections (Malware protection, Memory Threat, Malicious Behavior, Ransomware) within Elastic Security
Tier 2 Analyst duties and responsibilities:
- Advanced Incident Investigation and Reporting
- Building and refining queries for threat hunts.
- Explaining hunt results using Elastic tools.
- Enable and support customer workflows, including:
- Alert triage
- Case management
- Timeline analysis
- Visualizations and integrations
- Create reports using tools like Canvas.
- SIEM and Data Management
- Understand pipeline requirements and assist engineers with data ingestion/onboarding.
- Implement Elastic Agent deployment strategies and best practices.
- Work with host-based logs (Windows/Unix) to identify anomalies or potential threats.
- Identify gaps in customer security posture and recommend improvements.
- Integrate and tune Elastic features to reduce false positives and highlight actionable insights.
- Understanding of the Protections (Malware protection, Memory Threat, Malicious Behavior, Ransomware) within Elastic Security
Join Elastic's Federal Consulting Team and help public sector organizations solve their most complex data challenges using the Elastic Stack. If you're passionate about cutting-edge technology, customer success, and working in mission-critical environments, we'd love to hear from you!
Compensation:
Compensation for this role is in the form of base salary. This role does not have a variable compensation component.
The typical starting salary range for new hires in this role is listed below. In select locations (including Seattle WA, Los Angeles CA, the San Francisco Bay Area CA, and the New York City Metro Area), an alternate range may apply as specified below.
These ranges represent the lowest to highest salary we reasonably and in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the ranges may be modified in the future.
An employee's position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs.
Elastic believes that employees should have the opportunity to share in the value that we create together for our shareholders. Therefore, in addition to cash compensation, this role is currently eligible to participate in Elastic's stock program. Our total rewards package also includes a company-matched 401k with dollar-for-dollar matching up to 6% of eligible earnings, along with a range of other benefits offered with a holistic emphasis on employee well-being.
The typical starting salary range for this role is:
$113,100 - $152,600 USD
Additional Information - We Take Care of Our People
As a distributed company, diversity drives our identity. Whether you're looking to launch a new career or grow an existing one, Endgame Systems is the type of company where you can balance great work with great life. Your age is only a number. It doesn't matter if you're just out of college or your children are; we need you for what you can do.
We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.
- Competitive pay based on the work you do here and not your previous salary
- Health coverage for you and your family
- Ability to craft your calendar with flexible locations and schedules for many roles
- Generous number of vacation days each year
- Double your charitable giving - We match up to $1500 (or local currency equivalent)
- Up to 40 hours each year to use toward volunteer projects you love
- Embracing parenthood with minimum of 16 weeks of parental leave
Different people approach problems differently. We need that. Endgame Systems is an equal opportunity/affirmative action employer committed to diversity, equity, and inclusion. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.
We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email candidate_accessibility@elastic.co We will reply to your request within 24 business hours of submission.
Applicants have rights under Federal Employment Laws, view posters linked below: Family and Medical Leave Act (FMLA) Poster; Pay Transparency Nondiscrimination Provision Poster; Employee Polygraph Protection Act (EPPA) Poster and Know Your Rights (Poster)
Please see here for our Privacy Statement.
group id: 10317748