Elastic SIEM Administrator

peraton· Information Technology
Apply Now ↗
📍 Wiesbaden, DEFULL TIME

About this role

Responsibilities

Peraton is seeking a talented and experienced Elastic SIEM Administrator to join our team in support of the U.S. Army Europe Regional Cyber Center (RCC-E) in Wiesbaden, Germany.

 

Location: on-site, Wiesbaden, Germany

 

Role & Job Description:

  • As a SIEM Administrator, you are responsible for administering and supporting the Elastic Stack cluster, including all pipeline-related services, to ensure reliability, scalability, and continued capability development.
    • A key component of this role is documentation: you will develop and maintain comprehensive materials on system operations, pipeline architecture, and service delivery processes.Primary Responsibilities:
  • You will operate, monitor, and maintain multi-site Elastic clusters across multiple network enclaves.
  • Administer Confluent Kafka environments and associated Logstash pipeline services.
  • Build and manage configurations and filters for Elastic Beats and Elastic Agent collection architectures.
  • Develop, maintain, and update documentation for system architecture, pipeline designs, operational procedures, and service offerings.
  • Support Defensive Cyber Operations by assisting with analytic development and data pipeline optimization.
  • Contribute to the ongoing development and enhancement of Elastic Stack capabilities.

#RCC-E

Qualifications

Minimum requirements: 

  • Must meet Technical Expert Status Accreditation (TESA) and Peraton qualifications for the role, which can be achieved through one of the following pathways:
    • A bachelor’s degree in a STEM field or in Business Administration plus 5 years of relevant, specialized experience.
    • An associate degree plus 7 years of specialized experience. 
    • 11 years of relevant, specialized experience with HS Diploma/Equivalent
  • Certifications:
    • DoD 8140 521-Intermediate (one of: GMON, GRID, CEH, CISSP-ISSAP, CISSP-ISSEP, Cloud+, CySA+, GCIA, GICSP, GSEC, PenTest+, Security+, or SSCP)
    • One of the following residential requirements (one of Elastic Certification, Splunk Enterprise Certified Admin, Splunk Certified Architect, Microsoft Certified Cybersecurity Architect Expert, ArcSight ESM Advanced Administrator Certified, or GDSA)
  • Demonstrated experience with Elastic SIEM, including Elastic and Kibana.
  • Experience writing and troubleshooting complex regular expressions.
  • Experience developing and maintaining custom ingest pipelines and normalizing disparate data sets.
  • Experience administering the Linux operating system.
  • Experience building and maintaining Kafka topics and supporting technologies.
  • Strong understanding of data models and SIEM standardized compliance frameworks.
  • Experience organizing and orchestrating data set migrations with affected users.
  • Ability to provide advanced SIEM query language support to various content owners.
  • Experience creating and maintaining administrative dashboards.
  • U.S. citizenship required. 
  • Active Top Secret clearance with SCI eligibility. 

Preferred qualifications

  • Be an Elastic Certified Engineer or Elastic Certified Observability Engineer.
  • Demonstrate experience supporting multi-site architectures.
  • Demonstrate experience with Elastic Agent.
  • Demonstrate extensive knowledge of Lucene language.
  • Experience with Git, GitLab, Azure DevOps, GitHub, or other project configuration management.

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Frequently Asked Questions

Is the salary disclosed for the Elastic SIEM Administrator position at peraton?
The salary for this Elastic SIEM Administrator role at peraton is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Elastic SIEM Administrator position at peraton located?
This Elastic SIEM Administrator role at peraton is based in Wiesbaden, DE. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Elastic SIEM Administrator role at peraton full-time or part-time?
This is listed as a FULL TIME position. It is posted as a Elastic SIEM Administrator role in the Information Technology department at peraton.
Which team or department does the Elastic SIEM Administrator at peraton belong to?
This Elastic SIEM Administrator position is part of the Information Technology department at peraton. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Elastic SIEM Administrator position at peraton?
Click the "Apply Now" button on this page. You will be redirected to peraton's official application portal hosted on icims where you can submit your application directly.
When was the Elastic SIEM Administrator job at peraton posted?
This Elastic SIEM Administrator position at peraton was posted on Mar 23, 2026. Apply as soon as possible — early applications are often reviewed first.
Elastic SIEM Administrator
peraton
Apply for this role ↗

You'll be redirected to peraton's official application page on icims.