Cyber Engineer - Elastic Security SIEM
Don't apply into the void.
Most applications for this BAE Systems USA role vanish into an ATS. With jobfinder-ai, your agent finds the actual hiring manager or founder behind this opening and sends a tailored email from your own inbox — so a real person reads your pitch and replies. We then follow up until you land on the calendar.
Reach the decision-maker — $5About the role
**Job Description**
BAE Systems is seeking a SIEM expert to design, implement, and operate our enterprise\-grade security monitoring and detection platform across a multi\-tenant environment. The ideal candidate will have deep hands\-on experience with the Elastic Stack (Elasticsearch, Logstash, Kibana, Beats, Elastic Agent), strong detection engineering skills, and a proven track record of building scalable, reliable SIEM solutions in a complex, high\-paced environment. You will bridge multi\-tenant, large‑scale data engineering with Security Operations, ensuring high‑volume log ingestion, strict schema enforcement, and the delivery of actionable alerts to our SOC teams. Ensure inter\-operability with other other Platforms and Systems in the environment and secure the SIEM Platform to DoD Risk Management standards. Core Responsibilities* Architecture \& Cluster Management – Design, deploy, and maintain high‑throughput, distributed Elasticsearch clusters on‑premise. Implement ILM policies, data streams, and hot/cold/frozen tier strategies to optimize performance and storage cost. * Data Engineering \& Ingestion – Build scalable pipelines with Elastic Agents, Fleet, and Logstash for continuous log collection. * Data Normalization \& Schemas – Map diverse security logs (network, identity, endpoint) to the Elastic Common Schema (ECS) and enforce strict normalization. * Detection Engineering – Partner with SOC analysts to create, tune, and test advanced detection rules using ES\|QL, EQL, and KQL, reducing false positives. * Dashboards \& Analytics – Develop sophisticated Kibana visualizations, Lens analytics, and operational dashboards to provide rapid situational awareness for incident responders.
This position is located in Chesapeake, VA. There is no relocation assistance available for this position. Applicants must be currently residing in or state willingness to relocate self to Chesapeake, VA or surrounding areas.
**Required Education, Experience, \& Skills**
* **Years of Experience:** 5‑10 years in cybersecurity engineering; minimum 3 years focused on large‑scale Elastic Stack/SIEM deployments. * **Education:** Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent professional experience. * **Preferred Certifications:** Elastic Certified Engineer, Elastic Certified SIEM Analyst, CISSP or comparable security certifications. * **Elastic Ecosystem**: Expert‑level mastery of Elasticsearch, Logstash, Kibana, and Fleet; deep knowledge of index templates, shard allocation, and mappings. * **Operating Systems:** Hands‑on administration and hardening of Red Hat Enterprise Linux (RHEL) environments. * **Storage Systems:** Experience configuring SANs to support high‑throughput, IOPS‑intensive log storage. * **Query Languages:** Proficiency with ES * **Automation \& IaC:** Deploy infrastructure with Ansible; containerise services using Docker and Kubernetes. * **Scripting:** Strong Python, Bash, or PowerShell skills for custom log parsing, API integration, and ETL processes. * **Security Context:** Solid understanding of corporate security logging architecture, network protocols (TCP/IP, DNS, Syslog), and the MITRE ATT\&CK framework.
**Preferred Education, Experience, \& Skills**
* **Linux Administration:** Expert‑level proficiency in Linux system administration * **Virtualization**: Hands\-on experience administering and configuring virtualized environments (e.g., VMware vSphere, ESXi, or KVM) to support, scale, and optimize SIEM cluster deployments. * Certifications: Red Hat or other Linux certifications * **DevSecOps:** Deep knowledge of DevSecOps practices and tooling. * **Private Cloud:** Experience with private‑cloud architectures and orchestration (OpenStack, VMware Cloud Foundation, etc.). * **Kubernetes:** Advanced competence in Kubernetes/container technologies for scalable SIEM services.
**Pay Information**
Full\-Time Salary Range: $107359 \- $182510
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well\-being. Regular employees scheduled to work 20\+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non\-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
**About BAE Systems Intelligence \& Security**
BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it’s what we do at BAE Systems. Working here means using your passion and ingenuity where it counts – defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team—making a big impact on a global scale. At BAE Systems, you’ll find a rewarding career that truly makes a difference.
Intelligence \& Security (I\&S), based in McLean, Virginia, designs and delivers advanced defense, intelligence, and security solutions that support the important missions of our customers. Our pride and dedication shows in everything we do—from intelligence analysis, cyber operations and IT expertise to systems development, systems integration, and operations and maintenance services. Knowing that our work enables the U.S. military and government to recognize, manage and defeat threats inspires us to push ourselves and our technologies to new levels.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
Ready to reach the decision-maker?
Set this role as a target and your agent does the sourcing, finds the verified email, writes the pitch, and follows up — on autopilot.
Start your hunt