ELK/Data Engineer (4626) (TS/SCI) (Ft. Belvoir, VA)

Smx
Mount Vernon, VA


SMX is seeking a Data Analyst to design, develop, and implement data-driven solutions to enhance cybersecurity operations, leveraging data analytics, visualization, and observability techniques to improve threat detection, incident response, and security posture. This role requires designing and developing data pipelines and architectures to ingest, process, and analyze large datasets from various cybersecurity sources, as well as developing and implementing data visualization and dashboarding solutions to provide real-time insights and situational awareness to cybersecurity analysts and stakeholders.

The Data Analyst shall utilize the GISA Governance Board determined Security Information and Event Management (SIEM) solution, which as of January 2025 is transitioning from Splunk to a new architecture based on Elastic, Logstash, and Kibana (ELK), leveraging Cribl as a data broker to streamline and optimize data ingestion and processing. Additionally, the role involves implementing machine learning and anomaly detection models to identify potential security threats and improve incident response, developing and maintaining data quality and integrity, and collaborating with cybersecurity teams to integrate data-driven solutions with existing security tools and systems. The Data Analyst must stay up-to-date with emerging threats and trends in cybersecurity and data science, and apply this knowledge to improve the design and implementation of data-driven solutions, while ensuring compliance with relevant Department of Defense (DoD) and Intelligence Community (IC) standards, including the National Institute of Standards and Technology (NIST) Special Publication 800-53, DoD Instruction 8500.01, and Intelligence Community Directive (ICD) 503, as well as adherence to security regulations such as the Controlled Unclassified Information (CUI) program and other applicable laws, regulations, and policies governing the protection of national security information. The ultimate goal of this role is to provide data-driven insights and solutions that support the organization's cybersecurity mission, improve threat detection and incident response, and enhance overall cybersecurity posture in accordance with DoD and IC standards and regulations. This is a full-time onsite position.

Essential Duties & Responsibilities


  • Vulnerability Management and Reporting:

    • Generate detailed automated reports on identified vulnerabilities, outlining their severity, potential impact, and recommended remediation steps.

    • Assess vulnerability assessment results and prioritize vulnerabilities based on their criticality, potential impact, and ease of exploitation.

    • Maintain accurate records of vulnerability assessments, reports, and remediation efforts for audit and compliance purposes.


  • Remediation and Collaboration:

    • Work closely with IT teams to oversee the application of security patches and updates that address identified vulnerabilities.

    • Collaborate with incident response teams to address vulnerabilities that have been exploited or may be exploited during a security incident.

    • Collaborate with cross-functional teams, including regional support groups, to ensure the swift resolution of vulnerabilities.


  • Threat Intelligence and Awareness:

    • Stay updated on the latest threat intelligence, new vulnerabilities, and mitigation strategies, particularly in DoD, Army, and IC environments.

    • Participate in security awareness programs to educate employees on vulnerability reporting and the use of automated reporting tools.


  • Data Observability:

    • Design and develop data pipelines and architectures to ingest, process, and analyze large datasets from various cybersecurity sources, including network logs, system calls, and threat intelligence feeds.

    • Develop and implement data visualization and dashboarding solutions to provide real-time insights and situational awareness to cybersecurity analysts and stakeholders.

    • Collaborate with cybersecurity teams to integrate data-driven solutions with existing security tools and systems, including SIEMs, IDS/IPS, and threat intelligence platforms.


  • Compliance and Standards:

    • Ensure compliance with DoD, Army, and IC regulations, task orders, bulletins, and standards related to vulnerability management.

    • Clearly convey findings and recommendations to both technical and non-technical stakeholders, including management.


Required Skills, Experience & Education


  • Active Top Secret (TS) security clearance with eligibility for SCI and NATO read-on before starting work.

  • Meet DoD 8140 / 8570.01-M requirements for a privileged user on a TS/SCI information system before commencing work.

  • CISSP, CISM, or equivalent certification.

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field OR 10+ Years experience with Enterprise SIEM Data Observability and Reporting (Splunk/Elastic)

  • Technical Skills:

    • Thorough understanding of cybersecurity principles, best practices, and emerging threats.

    • Proficiency in vulnerability scanning and cybersecurity tools, including Tenable.

    • Security Information and Event Management (SIEM) systems: Splunk, Elastic, Logstash, Kibana (ELK)

    • Data broker technologies: Cribl, Confluent

    • Operating Systems Security Events: Windows, Linux

    • Networking protocols: TCP/IP, DNS, DHCP,

    • Cybersecurity tools and technologies: IDS/IPS, firewalls, host based security, threat intelligence platforms, vulnerability management tools


  • Technical Expertise: Advanced knowledge of Security Incident and Event Management (SIEM) tools, vulnerability management, compliance, and cybersecurity principles.

  • Analytical Thinking: Strong problem-solving skills to assess vulnerability risks and recommend effective remediation strategies.

  • Communication: Ability to convey technical findings clearly and succinctly to both technical and non-technical audiences.

  • Collaboration: Adept at collaborating with IT, security, and cross-functional teams to ensure timely and effective vulnerability remediation.

  • Attention to Detail: Meticulous in documenting and reporting vulnerabilities, ensuring compliance and audit readiness.

  • Regulatory Knowledge: Knowledge of DoD, Army, and IC regulations, standards, and compliance requirements.

  • Adaptability: Keeps current with evolving threats, vulnerabilities, and cybersecurity mitigation techniques.

Desired Skills/Experience


  • Advanced certifications such as Offensive Security Certified Professional (OSCP), GIAC Certified Incident Handler (GCIH), and GIAC Vulnerability Assessment Professional (GVAP).

  • Experience in a DoD, Army, or Intelligence Community environment with a focus on vulnerability management.

  • Familiarity with automation tools and scripting languages (such as Python and PowerShell) to improve vulnerability reporting processes.

Application Deadline: October 20, 2025

#CJPOST

#LI-onsite

The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.

The proposed salary for this position is:

$115,600—$192,700 USD

At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.

We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.

SMX is an Equal Opportunity employer including disabilities and veterans.

Selected applicant may be subject to a background investigation and/or education verification.

Posted 2025-09-11

Recommended Jobs

Senior Food Safety Manager, Food Safety Audit & Monitoring Team

Amazon.com Services LLC
Arlington, VA

DESCRIPTION The North American Food Safety A&M Team ensures that all Amazon Fulfillment sites meet Food Safety criteria and regulatory requirements. They collaborate with a diverse range of intern…

View Details
Posted 2025-10-24

Finance / Budget Analyst TS/SCI with CI poly

Tenica and Associates
Chantilly, Loudoun County, VA

TENICA is looking for a financial management specialist. Candidate must have a TOP SECRET/ SCI with CI poly clearance. Employee shall provide time-sensitive and accurate Financial Management su…

View Details
Posted 2025-08-06

Study Participant for Prime Opinions

Prime Opinion
Ashburn, VA

Register today and enjoy a complimentary bonus of up to $10! Prime Opinion is dedicated to empowering our members through an exceptional survey-taking journey. Explore a range of rewards available o…

View Details
Posted 2025-09-03

Residential Aide

Serenity Counseling Services of Vir
Richmond, VA

Job Description Job Description Residential Aide Responsibilities and Duties Will have direct contact with residents on a daily basis Provide assistance with activities Perform other dut…

View Details
Posted 2025-10-19

UKG Pro WFM - Senior Manager Save for Later Remove job

PwC
Richmond, VA

At PwC, our people in business application consulting specialise in consulting services for a variety of business applications, helping clients optimise operational efficiency. These individuals an…

View Details
Posted 2025-09-03

Tax Intern - Summer 2027 - Grant Thornton - Arlington, Virginia, United States

Grant Thornton
Arlington, VA

Description Tax Intern During your internship at Grant Thornton, you will be exposed to tax procedures including tax consulting and tax return preparation which will involve tax research, tax p…

View Details
Posted 2025-09-25

Enterprise Data Engineer

Accenture Federal Services
Chantilly, Loudoun County, VA

  At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared …

View Details
Posted 2025-09-12

Hybrid Java Backend Developer

Shuvel
Ashburn, VA

Position Summary: We are currently seeking a motivated, career and customer oriented Backend Developer to join our team to begin an exciting and challenging career. Job Responsibilities: …

View Details
Posted 2025-09-12

DevOps Engineer

Accenture Federal Services
Chantilly, Loudoun County, VA

  At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared …

View Details
Posted 2025-09-22