Back to jobs

Elastic Security Analyst, Federal Public Sector

United States

Endgame Systems, LLC provides consulting services related to Elastic technology to Government agencies with heightened security needs. Endgame Systems, LLC is a wholly-owned subsidiary of Elastic.  Elastic is a free and open search company that powers enterprise search, observability, and security solutions built on one technology stack that can be deployed anywhere. From finding documents to monitoring infrastructure to hunting for threats, Elastic makes data usable in real-time and at scale. Thousands of organizations worldwide, including Barclays, Cisco, eBay, Fairfax, ING, Goldman Sachs, Microsoft, The Mayo Clinic, NASA, The New York Times, Wikipedia, and Verizon, use Elastic to power mission-critical systems. Founded in 2012, Elastic is a distributed company with Elasticians around the globe. Learn more at elastic.co.  Endgame Systems, LLC, while a subsidiary of Elastic, is an independent entity focused on Government services.

Purpose

Elastic’s Security Analyst will leverage cyber hunt methodologies to drive customer success, product adoption, and renewals. This individual will deliver consulting to customers in the US PUBSEC market. This role will engage directly with customers to solve their most challenging cyber security challenges, leveraging Elastic.

Responsibilities

  • Deliver consulting aligned with up-to-date product strategies and general business needs
  • Possess a solid familiarity with the MITRE ATT&CK framework and advanced attacker techniques
  • Support, perform, and troubleshoot hardware and software installations independently
  • Recognize and analyze malware based on a combination of behavioral activity and signature-based tippers
  • Support the creation and maintenance of quality customer-facing documentation and self-help resources, including product implementation documentation and best practices.
  • Understand customer business needs and use cases, driving product improvements
  • Continually seek opportunities to increase customer satisfaction and deepen customer relationships, driving product adoption, expansion and renewals
  • Specific tasks may include but are not limited to:
    • Build visualizations/dashboards
    • GenAI LLM features (Attack Discovery and Security Assistant) 
    • Build reports (canvas)
    • Building rules
      • KQL
      • EQL
      • ES|QL
      • ML
      • Indicator Match
      • threshold 
  • Elastic integrations
    • Tuning rules
    • Apply an understanding of frequency analysis and how to tune out the most noisy false positives to give customers better visibility into lower frequency events that need to be investigated
  • Understand and enable customers on the following workflows:
    • Alert triage
    • Cases
    • Timeline
    • Visualizations
    • Integrations
    • Elastic Agent Deployment strategies/ best practices
    • Elastic Defend Installation
    • Elastic Defend response actions
  • Apply cybersecurity best practices
  • Translate how to achieve any action from a previous SIEM or security tool in Elastic
  • Understand latest threats and trends, and explain how Elastic helps secure customers form those threats
  • Familiarity with host-based logs (Windows | Unix)
  • Identify anomalous activity or potential threats in a customer environment
  • Assist customers with root cause analysis of identified threats
  • Identify gaps in customer security posture and make recommendations for improvement
  • Assist the customer with threat hunting activities, such as:
    • Building and tuning queries for threat hunts
    • Explaining threat hunt results as they appear in Elastic
  • Understand and describe pipeline requirements to assist engineers with data onboarding needs
  • Other duties as assigned

Requirements

  • Bachelor’s Degree in Computer Science or related field and 4+ years of security training, software implementation, consulting, customer support, SOC, IR, or related experience with demonstrated accomplishments in the role
  • Strong understanding of Windows, Mac, and Linux internals, administration, and troubleshooting as well as experience with large-scale, complex enterprise troubleshooting
  • Solid understanding of cyber adversary tactics, techniques, and procedures to help customers use Elastic to detect sophisticated adversaries, triage alerts, and respond to potential incidents.
  • Ability to demonstrate business value of technical solutions
  • Excellent verbal and written communication skills, training and presentation skills
  • Strong work-ethic and committed to quality
  • Disciplined, organized and methodical in approach to projects and tasks
  • Able to travel up to 50% of the time
  • Great presentation skills with the ability to speak in front of audiences both large and small
  • Exceptional Communication: Ability to articulate complex technical concepts clearly and concisely to diverse audiences. Skilled in listening to clients' needs and effectively conveying solutions.
  • Relationship Building: Strong capacity to build and maintain professional relationships with clients, demonstrating understanding and respect for their unique needs and objectives.
  • Consultative Mindset: Proven ability to provide insightful advice and guidance to clients, using technical knowledge to inform recommendations.
  • Empathy and Patience: Exceptional ability to empathize with clients, understand their challenges, and handle their concerns with patience and professionalism.
  • Negotiation and Persuasion: Ability to negotiate effectively, aligning the interests of multiple parties and persuading clients or stakeholders when necessary.
  • Client Education: Strong capability for teaching clients about technical systems and solutions, helping them understand and make the most of the technology.
  • Cultural Awareness: Understanding and respect for cultural differences and diversity within the client base, facilitating effective communication and relationship-building.

AFS Addem

Tier 1 Analyst duties and responsibilities:

  • Alert monitoring and triage 
    • Monitor alerts from on boarded data sources in real-time
    • Add exceptions to rules based upon confirmed FPs
    • Perform initial alert investigation and triage to determine the validity of the alert and severity 
    • Follow established playbooks for common alert types. Examples are adding alerts to a case, initial timeline analysis, and visualization building in lens 
  • Initial Incident Response 
    • Document related or relevant events in timeline and cases 
    • Coordinate with Tier 2 and escalate when needed 
  • Threat Analysis
    • On board threat intel sources 
    • Understand how Indicator Match rules work and when to use them/ limitations.
    • Create indicator match rules for on boarded TI feeds 
    • Write and refine rules using KQL, EQL, ES|QL, and other query languages.
      • Customize OOTB rules for customer environment
    • Manage Elastic Defend installation
    • Utilize machine learning models (ML) for security tuning.
    • Understanding of the Protections (Malware protection, Memory Threat, Malicious Behavior, Ransomware) within Elastic Security

Tier 2 Analyst duties and responsibilities:

  • Advanced Incident Investigation and Reporting
    • Building and refining queries for threat hunts.
    • Explaining hunt results using Elastic tools.
    • Enable and support customer workflows, including:
      • Alert triage
      • Case management
      • Timeline analysis
      • Visualizations and integrations
    • Create reports using tools like Canvas.
  • SIEM and Data Management
    • Understand pipeline requirements and assist engineers with data ingestion/onboarding.
    • Implement Elastic Agent deployment strategies and best practices.
    • Work with host-based logs (Windows/Unix) to identify anomalies or potential threats.
    • Identify gaps in customer security posture and recommend improvements.
    • Integrate and tune Elastic features to reduce false positives and highlight actionable insights.
    • Understanding of the Protections (Malware protection, Memory Threat, Malicious Behavior, Ransomware) within Elastic Security

Join Elastic’s Federal Consulting Team and help public sector organizations solve their most complex data challenges using the Elastic Stack. If you’re passionate about cutting-edge technology, customer success, and working in mission-critical environments, we’d love to hear from you!

Compensation:

Compensation for this role is in the form of base salary.  This role does not have a variable compensation component.  

The typical starting salary range for new hires in this role is listed below.  In select locations (including Seattle WA, Los Angeles CA, the San Francisco Bay Area CA, and the New York City Metro Area), an alternate range may apply as specified below. 

These ranges represent the lowest to highest salary we reasonably and in good faith believe we would pay for this role at the time of this posting.  We may ultimately pay more or less than the posted range, and the ranges may be modified in the future.  

An employee's position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs.

Elastic believes that employees should have the opportunity to share in the value that we create together for our shareholders. Therefore, in addition to cash compensation, this role is currently eligible to participate in Elastic's stock program.  Our total rewards package also includes a company-matched 401k with dollar-for-dollar matching up to 6% of eligible earnings, along with a range of other benefits offered with a holistic emphasis on employee well-being.

The typical starting salary range for this role is:

$113,100 - $152,600 USD

 

Additional Information - We Take Care of Our People

As a distributed company, diversity drives our identity. Whether you’re looking to launch a new career or grow an existing one, Endgame Systems is the type of company where you can balance great work with great life. Your age is only a number. It doesn’t matter if you’re just out of college or your children are; we need you for what you can do.

We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.

  • Competitive pay based on the work you do here and not your previous salary
  • Health coverage for you and your family 
  • Ability to craft your calendar with flexible locations and schedules for many roles
  • Generous number of vacation days each year
  • Double your charitable giving - We match up to $1500 (or local currency equivalent)
  • Up to 40 hours each year to use toward volunteer projects you love
  • Embracing parenthood with minimum of 16 weeks of parental leave

Different people approach problems differently. We need that. Endgame Systems is an equal opportunity/affirmative action employer committed to diversity, equity, and inclusion. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.

We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email candidate_accessibility@elastic.co We will reply to your request within 24 business hours of submission.

Applicants have rights under Federal Employment Laws, view posters linked below: Family and Medical Leave Act (FMLA) Poster; Pay Transparency Nondiscrimination Provision Poster; Employee Polygraph Protection Act (EPPA) Poster and Know Your Rights (Poster)

Please see here for our Privacy Statement.

 

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...
Select...
Select...

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Endgame Systems, LLC’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.