1

Elastic Siem Jobs (NOW HIRING)

Elastic SIEM Engineer

Hanover, MD · Hybrid

$150K - $165K/yr

ASRC Federal is actively hiring an Elastic SIEM Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Hanover MD. Remote flexibility available! Telework ...

Elastic SIEM Engineer

Hanover, MD · Hybrid

$150K - $165K/yr

ASRC Federal is actively hiring an Elastic SIEM Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Hanover MD. Remote flexibility available! Telework ...

Elastic SIEM Engineer

Hanover, MD · On-site

$120K - $165K/yr

As an Elastic SIEM Engineer , your primary duty is to maintain enterprise-scale Elastic Stack security solutions that safeguard our national security systems. You will design and implement advanced ...

Sr Security Analyst

Scott Air Force Base, IL · On-site

$92K - $121K/yr

We are seeking a Security Analyst with strong Elastic SIEM experience and solid cybersecurity fundamentals who can investigate alerts, hunt threats, and help operationalize detection capabilities ...

Elastic Engineeer

Mesa, AZ · On-site

$65.35 - $87/hr

Specific experience with Elastic SIEM is a plus * Demonstrated experience with the full Elastic Stack - Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration

Sr. DevSecOps Engineer

San Diego, CA · On-site

$120K - $150K/yr

Elastic SIEM alert enrichment * Compliance notifications & ticketing * Integrate LLMs to: * Summarize alerts * Draft POA&M entries * Generate remediation guidance * Produce daily/weekly SOC and ...

Sr. DevSecOps Engineer

San Diego, CA · On-site

$120K - $150K/yr

Elastic SIEM alert enrichment * Compliance notifications & ticketing * Integrate LLMs to: * Summarize alerts * Draft POA&M entries * Generate remediation guidance * Produce daily/weekly SOC and ...

Description SAIC is seeking a SIEM Administrator / Engineer to support enterprise cybersecurity ... Support the organization's transition from Splunk to Elastic, including migration and validation of ...

next page

Showing results 1-20

Elastic Siem information

See salary details

$17

$44

$60

How much do elastic siem jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for elastic siem in the United States is $44.14, according to ZipRecruiter salary data. Most workers in this role earn between $34.62 and $54.57 per hour, depending on experience, location, and employer.

What is Elastic SIEM?

Elastic SIEM (Security Information and Event Management) is a security solution integrated into the Elastic Stack that helps organizations detect, investigate, and respond to security threats in real-time. It collects and analyzes security-related data from across your infrastructure, such as logs and events, to identify suspicious activities and potential threats. Elastic SIEM provides powerful visualization, automated alerting, and investigation tools to streamline threat detection and incident response workflows. It is popular for its scalability, flexibility, and open-source foundation, making it suitable for a wide range of security operations.

What are the key skills and qualifications needed to thrive as an Elastic SIEM specialist?

To thrive as an Elastic SIEM Specialist, you need expertise in cybersecurity concepts, log analysis, threat detection, and hands-on experience with the Elastic Stack (Elasticsearch, Logstash, Kibana), often backed by relevant IT or cybersecurity certifications. Familiarity with SIEM platforms, scripting languages (such as Python), and security frameworks is typically required for effective system integration and automation. Strong analytical thinking, attention to detail, and effective communication set top specialists apart when responding to threats and collaborating with teams. These skills are vital for proactively identifying security risks, optimizing incident response, and ensuring organizational data protection.

What are some common challenges faced by professionals working with Elastic SIEM, and how can they be addressed?

One common challenge in the Elastic SIEM role is managing and scaling the ingestion and analysis of large volumes of security data from various sources. Professionals often need to fine-tune data pipelines, optimize queries, and ensure proper mapping to maintain system performance. Collaboration with IT and security teams is crucial for customizing detection rules and responding to incidents effectively. Staying current with Elastic Stack updates and best practices can help overcome technical hurdles and enhance threat detection capabilities.

What is the difference between Elastic Siem vs SIEM Analyst?

AspectElastic SiemSIEM Analyst
CertificationsElastic Certified Engineer, Security certificationsCompTIA Security+, CISSP, GIAC
Work EnvironmentSecurity operations, data analysis, cloud environmentsSecurity monitoring, incident response, log analysis
Industry UsageIT security, cloud security, enterprise environmentsCybersecurity teams, security operations centers

Elastic Siem professionals focus on deploying and managing Elastic Stack for security monitoring, while SIEM Analysts analyze security data and respond to threats using various SIEM tools. Both roles require security knowledge, but Elastic Siem specialists often have more technical skills related to Elastic Stack deployment, whereas SIEM Analysts focus on threat detection and incident response.

Does Elastic SIEM pay well?

Elastic SIEM analysts and security engineers typically earn competitive salaries aligned with cybersecurity industry standards. Compensation varies based on experience, certifications, and location, with roles often offering benefits such as remote work and opportunities to work with advanced security tools. Overall, positions in Elastic SIEM tend to be well-paying within the cybersecurity field.
Infographic showing various Elastic Siem job openings in the United States as of September 2026, with employment types broken down into 93% Full Time, 2% Part Time, and 5% Contract. Highlights an 73% Physical, 10% Hybrid, and 17% Remote job distribution, with an average salary of $91,821 per year, or $44.1 per hour.

Elastic SIEM Engineer

Hanover, MD • Hybrid

$150K - $165K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 18 days ago


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

244th of 454 rated engineering


Job description

ASRC Federal is actively hiring an Elastic SIEM Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Hanover MD.

Remote flexibility available! Telework offered with a requirement to be onsite up to one (1) day a week at Hanover, MD.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefit packages. This position is offering a pay range of $150,000.00 - $165,450.00 depending on experience, seniority, geographic locations, and factors permitted by law. Benefits offered may include health care, dental, vision, life insurance; 401k; education assistance; paid time off including Paid Time Off, holidays and any other paid leave required by law.

Job Description:

As an Elastic SIEM Engineer, your primary duty is to maintain enterprise-scale Elastic Stack security solutions that safeguard our national security systems. You will design and implement advanced detection rules, correlation searches, and analytics pipelines using Elasticsearch, Logstash, Kibana, and Elastic Security to identify sophisticated threats and adversary activity. A key part of your role involves optimizing data ingestion pipelines from diverse sources including cloud platforms (AWS, Azure, GCP), network devices, endpoints, and security tools, ensuring high availability, performance, and scalability of the SIEM infrastructure. You will develop custom dashboards, visualizations, and threat hunting workbenches that empower SOC analysts to detect and respond to incidents effectively, while collaborating with security operations, engineering teams, and government stakeholders to enhance detection capabilities. Additionally, you will be responsible for tuning detection logic to reduce false positives, automating security workflows, integrating threat intelligence feeds, and ensuring all activities align with critical compliance standards like NIST 800-53 and RMF through comprehensive documentation and technical leadership.

Minimum Requirements: 

  • At least five (5) Years – Direct Elastic engineering/administration experience
  • Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Bachelor’s degree in information security or related field and/or equivalent combination of experience
  • Certifications:
    • Must meet DoD 8140/8570 IAM or IAT Level II certifications’ requirements at the time of hire by having one of the following certifications. (CCNA Security, CySA +, GICSP, GSEC, Security+, SSSP, CAP, CASP CE, CISM, CISSP (or Associate) or GSLC
  • Highly Desired:
    • Two (2) plus years of AWS experience

Basic Qualifications:

  • Experience in the support and maintenance of an Elastic infrastructure in a highly available configuration in an AWS Cloud environment
  • Proven experience as an Elastic Engineer or similar role
  • Strong understanding of Elastic architecture in a cloud environment, including data ingestion, indexing, search, and visualization
  • Prior experience customizing and configuring Elastic environments according to client needs, including developing scripts and apps as necessary
  • Proficiency in scripting languages such as Python or Bash for Elastic app and dashboard development
  • Experience with data transformation and normalization to ensure compatibility with Elastic
  • Troubleshoot Elastic indexers, search heads and forwarder problems
  • Familiarity with networking principles and protocols
  • Excellent problem-solving skills and the ability to work under pressure
  • Strong communication and interpersonal skills, with the ability to explain technical concepts to non-technical stakeholders
  • Experience analyzing log files from network traffic logs, firewall logs, IDS logs, DNS logs and ESS to ID possible security threats e.g., determine rogue systems, infected systems, unauthorized system changes and unauthorized hardware connections
  • Work Environment and Physical Demands
  • This is primarily a Telework position with a requirement to be onsite up to two (2) days a week at Fort Meade, MD
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to work flexible hours to support critical security incidents, maintenance windows, and emergency response activities as needed

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom