CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.
Position: Elastic SIEM / ECK Engineer
Location: Quantico VA
Duration: Period of Performance through November. Post November we will look to place the candidate on another project.
Clearance: Active TS
Salary: $180k-$230k
Job Description:
Design, deploy, and modernize the customer's Elastic platform on AWS by migrating from Elastic Cloud Enterprise (ECE) to Elastic Cloud on Kubernetes (ECK).
Build out production ready ECK clusters on AWS, including architecture, configuration, and baseline hardening.
Migrate an existing Splunk SIEM environment (approximately 6 TB/day of data) to Elastic SIEM.
Transition Splunk knowledge objects, including:
* 375 detection rules
* 470+ dashboards
* 7 SOAR automations
Configure and validate data ingestion pipelines, normalization, and Elastic Common Schema (ECS) field mappings.
Implement, tune, and validate detection rules to ensure parity and improved signal quality post migration.
Integrate SIEM workflows and automation to support security operations and response use cases.
Implement Elastic Observability for the DISS application, including:
* Application Performance Monitoring (APM)
* Distributed tracing and performance visibility
Execute production cutover from legacy platforms to Elastic, ensuring continuity of operations.
Perform end to end validation of data ingestion, detections, dashboards, workflows, automations, and observability telemetry.
Provide post cutover stabilization and validation support.