Sr SIEM Engineer

Posted 11 Days Ago
Be an Early Applicant
Pune, Maharashtra
Senior level
Healthtech
The Role
Lead the design and implementation of Elastic SIEM, develop advanced detection logic, and support incident response initiatives. Optimize SIEM performance and collaborate with various teams.
Summary Generated by Built In

Your Future Evolves Here

Evolent Health has a bold mission to change the health of the nation by changing the way health care is delivered. Our pursuit of this mission is the driving force that brings us to work each day. We believe in embracing new ideas, challenging ourselves and failing forward. We respect and celebrate individual talents and team wins. We have fun while working hard and Evolenteers often make a difference working in everything from scrubs to jeans.

Are we growing? Absolutely and Globally. In 2021 we grew our teams by almost 50% and continue to grow even more in 2022. Are we recognized as a company you are supported by for your career and growth, and a great place to work? Definitely. Evolent Health International (Pune, India) has been certified as “Great Places to Work” in 2021. In 2020 and 2021 Evolent in the U.S. was both named Best Company for Women to Advance list by Parity.org and earned a perfect score on the Human Rights Campaign (HRC) Foundation’s Corporate Equality Index (CEI). This index is the nation's foremost benchmarking survey and report measuring corporate policies and practices related to LGBTQ+ workplace equality.

We recognize employees that live our values, give back to our communities each year, and are champions for bringing our whole selves to work each day. If you’re looking for a place where your work can be personally and professionally rewarding, don’t just join a company with a mission. Join a mission with a company behind it.

What You’ll Be Doing:

Position Summary:

We are seeking a highly skilled and experienced Senior SIEM Engineer with deep expertise in Elastic SIEM to join our cybersecurity team. This is a hands-on role responsible for architecting, deploying, administering, and developing security content and use cases in Elastic SIEM to support threat detection and incident response initiatives. The ideal candidate will have a solid foundation in cybersecurity operations, strong engineering skills, and a passion for developing advanced detection logic and correlation rules in Elastic Stack.

Key Responsibilities:

  • Lead the design, implementation, tuning, and administration of Elastic SIEM/Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) in enterprise environments.

  • Work on ECU and license optimization efforts to save costs.

  • Develop advanced correlation rules, detection logic, dashboards, and visualizations within Elastic SIEM.

  • Build and maintain custom parsers, log ingestion pipelines, and data enrichment mechanisms using Logstash, Beats, and Elastic Agent.

  • Engineer and maintain log collection from diverse data sources: firewalls, endpoints, servers, cloud platforms, applications, and network devices.

  • Integrate Elastic SIEM with threat intelligence feeds and develop use cases for TTP detection aligned with MITRE ATT&CK framework.

  • Continuously optimize performance, scalability, and availability of the SIEM platform.

  • Collaborate with SOC, Incident Response, and Threat Intel teams to understand requirements and transform them into actionable use cases.

  • Troubleshoot and resolve ingestion, parsing, and indexing issues.

  • Support compliance reporting, data retention, and audit requirements (HIPAA, PCI-DSS, SOX, NIST, etc.).

  • Document configurations, use cases, operational runbooks, and architectural changes.

  • Partner with peers in Elastic SIEM concepts, query development, and best practices.
     

Required Qualifications:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field. Master’s preferred.

  • 5+ years of experience in cybersecurity, with at least 2 years focused on Elastic SIEM/ELK Stack in a hands-on engineering role.

  • Proficient in EQL, Linux, Logstash filter syntax, YAML, and JSON.

  • Hands-on experience with Beats (Filebeat, Metricbeat, etc.), Elastic Agent, and Logstash pipelines.

  • Strong knowledge of information security concepts, attack vectors, and incident response workflows.

  • Experience in Elastic SIEM integration with SOAR, ticketing tools, cloud platforms (AWS, Azure), and security controls.

  • Some scripting experience in Python, Bash, or PowerShell for automation and data manipulation.

  • Excellent problem-solving skills and the ability to work independently or as part of a team.
     

Preferred Qualifications:

  • Elastic Certified Engineer or related certification.

  • Experience with Elastic Security App, Fleet, and Endpoint Integration.

  • Prior experience in building and tuning SIEM solutions in hybrid environments (on-prem and cloud).

Mandatory Requirements:

Employees must have a high-speed broadband internet connection with a minimum speed of 50 Mbps and the ability to set up a wired connection to their home network to ensure effective remote work. These requirements may be updated as needed by the business.

Evolent Health is an equal opportunity employer and considers all qualified applicants equally without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, or disability status.

Top Skills

AWS
Azure
Bash
Beats
Elastic Siem
Elasticsearch
Eql
JSON
Kibana
Linux
Logstash
Powershell
Python
Yaml
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Arlington, VA
2,581 Employees
On-site Workplace
Year Founded: 2011

What We Do

Evolent Health delivers proven clinical and administrative solutions that improve whole person health while making health care simpler and more affordable. Our three solutions—Evolent Care Partners, New Century Health and Evolent Health Services—encompass total cost of care management, specialty care management and administrative simplification. Evolent serves a national base of leading payers and providers, is the first company to receive the National Committee for Quality Assurance's Population Health Program Accreditation, and is consistently recognized as a top place to work in health care nationally.

OUR PEOPLE
We were named one of “Becker’s 150 Great Places to Work in Healthcare” in 2016, 2017, 2018 and 2019 and are proud to be recognized as a leader in driving diversity, equity, and inclusion (DE&I) efforts. Evolent achieved a 100% score on the 2020 Human Rights Campaign's Corporate Equality Index, making us one of the best places to work for LGBTQ+ employees. We were also named on the Best Companies for Women to Advance List 2020 and 2021 by Parity.org.

OUR CULTURE
Our accessible leadership team cultivates an open-door environment. We don’t like approval chains; we love ideas and people with the courage and conviction to bring novel solutions forward. We win as a team and always ask how we can do better. We respect and encourage commitments outside of work.

OUR COMPENSATION & BENEFITS
We recognize and reward our most valuable asset—our team—with competitive pay and annual performance-based bonuses. Evolent also offers comprehensive health benefits, a company-matched 401(k) and flexible spending accounts. Every salaried Evolent employee receives unlimited Personal Time Off and is eligible for a month-long sabbatical after working five years with Evolent.

This account is monitored closely by our company. Please message us at [email protected] with any questions or concerns.

Similar Jobs

ZS Logo ZS

Information Security Project Specialist - Cloud & InfoSec PMO

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
Pune, Maharashtra, IND
13000 Employees

ZS Logo ZS

Technical Support Associate

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
Pune, Maharashtra, IND
13000 Employees

ZS Logo ZS

Senior Cloud Administrator

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
Pune, Maharashtra, IND
13000 Employees

ZS Logo ZS

Identity & Access Management Specialist

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
Pune, Maharashtra, IND
13000 Employees
60K-90K

Similar Companies Hiring

Mochi Health Thumbnail
Telehealth • Healthtech
San Francisco, CA
70 Employees
Cencora Thumbnail
Pharmaceutical • Logistics • Healthtech
Conshohocken, PA
46000 Employees
Stepful Thumbnail
Software • Healthtech • Edtech • Artificial Intelligence
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account