Jobs and Careers
EN

Elastic Security Analyst, Federal Public Sector

Endgame Systems, LLC
United States, United Statesfull_timeVerifiedPosted 7 May 2025
💰 $152,600/yr($113,100/yr$152,600/yr)

About the role

Endgame Systems, LLC provides consulting services related to Elastic technology to Government agencies with heightened security needs. Endgame Systems, LLC is a wholly-owned subsidiary of Elastic.  Elastic is a free and open search company that powers enterprise search, observability, and security solutions built on one technology stack that can be deployed anywhere. From finding documents to monitoring infrastructure to hunting for threats, Elastic makes data usable in real-time and at scale. Thousands of organizations worldwide, including Barclays, Cisco, eBay, Fairfax, ING, Goldman Sachs, Microsoft, The Mayo Clinic, NASA, The New York Times, Wikipedia, and Verizon, use Elastic to power mission-critical systems. Founded in 2012, Elastic is a distributed company with Elasticians around the globe. Learn more at elastic.co.  Endgame Systems, LLC, while a subsidiary of Elastic, is an independent entity focused on Government services.

Purpose

Elastic’s Security Analyst will leverage cyber hunt methodologies to drive customer success, product adoption, and renewals. This individual will deliver consulting to customers in the US PUBSEC market. This role will engage directly with customers to solve their most challenging cyber security challenges, leveraging Elastic.

Responsibilities

  • Deliver consulting aligned with up-to-date product strategies and general business needs
  • Possess a solid familiarity with the MITRE ATT&CK framework and advanced attacker techniques
  • Support, perform, and troubleshoot hardware and software installations independently
  • Recognize and analyze malware based on a combination of behavioral activity and signature-based tippers
  • Support the creation and maintenance of quality customer-facing documentation and self-help resources, including product implementation documentation and best practices.
  • Understand customer business needs and use cases, driving product improvements
  • Continually seek opportunities to increase customer satisfaction and deepen customer relationships, driving product adoption, expansion and renewals
  • Specific tasks may include but are not limited to:
    • Build visualizations/dashboards
    • GenAI LLM features (Attack Discovery and Security Assistant) 
    • Build reports (canvas)
    • Building rules
      • KQL
      • EQL
      • ES|QL
      • ML
      • Indicator Match
      • threshold 
  • Elastic integrations
    • Tuning rules
    • Apply an understanding of frequency analysis and how to tune out the most noisy false positives to give customers better visibility into lower frequency events that need to be investigated
  • Understand and enable customers on the following workflows:
    • Alert triage
    • Cases
    • Timeline
    • Visualizations
    • Integrations
    • Elastic Agent Deployment strategies/ best practices
    • Elastic Defend Installation
    • Elastic Defend response actions
  • Apply cybersecurity best practices
  • Translate how to achieve any action from a previous SIEM or security tool in Elastic
  • Understand latest threats and trends, and explain how Elastic helps secure customers form those threats
  • Familiarity with host-based logs (Windows | Unix)
  • Identify anomalous activity or potential threats in a customer environment
  • Assist customers with root cause analysis of identified threats
  • Identify gaps in customer security posture and make recommendations for improvement
  • Assist the customer with threat hunting activities, such as:
    • Building and tuning queries for threat hunts
    • Explaining threat hunt results as they appear in Elastic
  • Understand and describe pipeline requirements to assist engineers with data onboarding needs
  • Other duties as assigned

Requirements

  • Bachelor’s Degree in Computer Science or related field and 4+ years of security training, software implementation, consulting, customer support, SOC, IR, or related experience with demonstrated accomplishments in the role
  • Strong understanding of Windows, Mac, and Linux internals, administration, and troubleshooting as well as experience with large-scale, complex enterprise troubleshooting
  • Solid understanding of cyber adversary tactics, techniques, and procedures to help customers use Elastic to detect sophisticated adversaries, triage alerts, and respond to potential incidents.
  • Ability to demonstrate business value of technical solutions
  • Excellent verbal and written communication skills, training and presentation skills
  • Strong work-ethic and committed to quality
  • Disciplined,

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Endgame Systems, LLC

View company profile →