Cyber Engineer - Elastic Security SIEM

Posted Yesterday
Be an Early Applicant
Norfolk, VA, USA
Hybrid
107K-183K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Where purpose connects.
The Role
Design, deploy, and operate enterprise-grade Elastic Stack SIEM in a multi-tenant environment: manage Elasticsearch clusters, build ingestion pipelines, normalize logs to ECS, create and tune detections (ES|QL/EQL/KQL), and deliver Kibana dashboards and alerts to SOCs while meeting DoD risk-management security requirements.
Summary Generated by Built In
Job Description
BAE Systems is seeking a SIEM expert to design, implement, and operate our enterprise-grade security monitoring and detection platform across a multi-tenant environment. The ideal candidate will have deep hands-on experience with the Elastic Stack (Elasticsearch, Logstash, Kibana, Beats, Elastic Agent), strong detection engineering skills, and a proven track record of building scalable, reliable SIEM solutions in a complex, high-paced environment. You will bridge multi-tenant, large-scale data engineering with Security Operations, ensuring high-volume log ingestion, strict schema enforcement, and the delivery of actionable alerts to our SOC teams. Ensure inter-operability with other other Platforms and Systems in the environment and secure the SIEM Platform to DoD Risk Management standards.
Core Responsibilities
  • Architecture & Cluster Management - Design, deploy, and maintain high-throughput, distributed Elasticsearch clusters on-premise. Implement ILM policies, data streams, and hot/cold/frozen tier strategies to optimize performance and storage cost.
  • Data Engineering & Ingestion - Build scalable pipelines with Elastic Agents, Fleet, and Logstash for continuous log collection.
  • Data Normalization & Schemas - Map diverse security logs (network, identity, endpoint) to the Elastic Common Schema (ECS) and enforce strict normalization.
  • Detection Engineering - Partner with SOC analysts to create, tune, and test advanced detection rules using ES|QL, EQL, and KQL, reducing false positives.
  • Dashboards & Analytics - Develop sophisticated Kibana visualizations, Lens analytics, and operational dashboards to provide rapid situational awareness for incident responders.
This position is located in Chesapeake, VA. There is no relocation assistance available for this position. Applicants must be currently residing in or state willingness to relocate self to Chesapeake, VA or surrounding areas.
Required Education, Experience, & Skills
  • Years of Experience: 5-10 years in cybersecurity engineering; minimum 3 years focused on large-scale Elastic Stack/SIEM deployments.
  • Education: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent professional experience.
  • Preferred Certifications: Elastic Certified Engineer, Elastic Certified SIEM Analyst, CISSP or comparable security certifications.
  • Elastic Ecosystem: Expert-level mastery of Elasticsearch, Logstash, Kibana, and Fleet; deep knowledge of index templates, shard allocation, and mappings.
  • Operating Systems: Hands-on administration and hardening of Red Hat Enterprise Linux (RHEL) environments.
  • Storage Systems: Experience configuring SANs to support high-throughput, IOPS-intensive log storage.
  • Query Languages: Proficiency with ES
  • Automation & IaC: Deploy infrastructure with Ansible; containerise services using Docker and Kubernetes.
  • Scripting: Strong Python, Bash, or PowerShell skills for custom log parsing, API integration, and ETL processes.
  • Security Context: Solid understanding of corporate security logging architecture, network protocols (TCP/IP, DNS, Syslog), and the MITRE ATT&CK framework.

Preferred Education, Experience, & Skills
  • Linux Administration: Expert-level proficiency in Linux system administration
  • Virtualization: Hands-on experience administering and configuring virtualized environments (e.g., VMware vSphere, ESXi, or KVM) to support, scale, and optimize SIEM cluster deployments.
  • Certifications: Red Hat or other Linux certifications
  • DevSecOps: Deep knowledge of DevSecOps practices and tooling.
  • Private Cloud: Experience with private-cloud architectures and orchestration (OpenStack, VMware Cloud Foundation, etc.).
  • Kubernetes: Advanced competence in Kubernetes/container technologies for scalable SIEM services.

Pay Information
Full-Time Salary Range: $107359 - $182510
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
About BAE Systems Intelligence & Security
BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it's what we do at BAE Systems. Working here means using your passion and ingenuity where it counts - defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team-making a big impact on a global scale. At BAE Systems, you'll find a rewarding career that truly makes a difference.
Intelligence & Security (I&S), based in McLean, Virginia, designs and delivers advanced defense, intelligence, and security solutions that support the important missions of our customers. Our pride and dedication shows in everything we do-from intelligence analysis, cyber operations and IT expertise to systems development, systems integration, and operations and maintenance services. Knowing that our work enables the U.S. military and government to recognize, manage and defeat threats inspires us to push ourselves and our technologies to new levels.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.

Skills Required

  • 5-10 years in cybersecurity engineering; minimum 3 years focused on large-scale Elastic Stack/SIEM deployments.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent professional experience.
  • Expert-level mastery of Elasticsearch, Logstash, Kibana, Fleet, and Beats; deep knowledge of index templates, shard allocation, and mappings.
  • Hands-on administration and hardening of Red Hat Enterprise Linux (RHEL).
  • Experience configuring SANs to support high-throughput, IOPS-intensive log storage.
  • Proficiency with Elasticsearch query languages (ES|QL, EQL, KQL).
  • Deploy infrastructure with Ansible; containerize services using Docker and Kubernetes.
  • Strong scripting skills in Python, Bash, or PowerShell for custom log parsing, API integration, and ETL.
  • Solid understanding of corporate security logging architecture, network protocols (TCP/IP, DNS, Syslog), and the MITRE ATT&CK framework.
  • Elastic Certified Engineer, Elastic Certified SIEM Analyst, CISSP or comparable security certifications.
  • Expert-level Linux administration and Red Hat or other Linux certifications.
  • Hands-on experience administering and configuring virtualization platforms (VMware vSphere, ESXi, or KVM).
  • Experience with private-cloud architectures and orchestration (OpenStack, VMware Cloud Foundation).
  • Advanced competence in Kubernetes/container technologies and DevSecOps practices.

What the Team is Saying

Dave K.
Maddie M.
Michael Z.
David F.
Catherine B.
Mike P.
Lexie W.
Rachel P.
Howard K.
Amy M.
Dave D.
Jason P.
AJ B.
Tim P.
Ryan Y.
Jose A.
Richard B.
Nakia J.
Sara M.
Chris D.
Liz S.
Sam W.
Caitlin A.

BAE Systems, Inc. Compensation & Benefits Highlights

  • Healthcare Strength Benefits materials highlight multiple medical plan options with FSA/HSA eligibility, and a 2024 guide references company HSA contributions. Health coverage breadth is emphasized alongside additional wellbeing resources.
  • Retirement Support A 401(k) savings plan is available with employer contributions or match offered by some business units per plan supplements. Company‑paid basic life insurance at 2x base salary (up to $1M) provides added financial protection.
  • Parental & Family Support Paid parental leave can be used in addition to other leave programs, with adoption and surrogacy reimbursement available. Feedback suggests bonding leave is available for all parents with additional short‑term disability for birth recovery, though specifics vary by business unit and state.

BAE Systems, Inc. Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Falls Church, VA
40,000 Employees
Year Founded: 1999

What We Do

Improving the future and protecting lives is an ambitious mission, but it’s what we do. As a leading aerospace, defense, and security company, we work together to deliver a full range of products and services for air, land, space, and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. How we work is rooted in purpose – a purpose to protect those who protect us, to unite our community of colleagues and customers, and to drive forward the growth and development of our exceptional team members. It's where purpose connects.

Why Work With Us

We believe your career should be filled with innovation and discovery. And that's exactly what you'll find at BAE Systems. As you work to develop the latest technology and defend national security, you will continually hone your skills and expand knowledge. On a sharp and collaborative team, you will be challenged – and supported – at every turn.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

BAE Systems, Inc. Teams

Team
Space & Mission Systems
Team
Electronic Systems
Team
Intelligence & Security
Team
Platforms & Services
Team
What It’s Like Working on BAE Systems’ AI-Powered Military Tech
About our Teams

BAE Systems, Inc. Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

As the work place continues to evolve, so do we. Remote and hybrid opportunities are available at BAE Systems depending on the nature of the role. Check your job requisition to learn more.

Typical time on-site: Not Specified
Company Office Image
HQBAE Systems, Inc. headquarters
Annapolis Junction, MD
Company Office Image
Austin, TX
Boulder, CO
Company Office Image
Space & Mission Systems headquarters
Burlington, MA
Cedar Rapids, IA
Dallas, TX
Endicott, NY
Fort Wayne, IN
Greenlawn, NY
Huntsville, AL
Jacksonville, FL
Los Angeles, CA
Maple Grove, MN
Intelligence & Security headquarters
Company Office Image
Electronic Systems headquarters
Redmond, WA
San Diego, CA
San Jose, CA
Company Office Image
Sterling Heights, MI
Washington, DC
Wayne, NJ
Learn more

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Electronic Attack Futures: Senior Capture & Strategy Lead

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Arlington, VA, USA
40000 Employees
153K-261K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Senior Principal II Engineer - FPGA Design - $20K Sign On Bonus

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Chantilly, VA, USA
40000 Employees
150K-254K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Senior Principal ASIC Implementation Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Manassas, VA, USA
40000 Employees
133K-226K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Engineer Senior - Systems - Mission Performance

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Chantilly, VA, USA
40000 Employees
97K-165K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account