ECS Logo

ECS

Sr. Elastic Defend Analyst

Posted 13 Days Ago
Be an Early Applicant
In-Office
2 Locations
120K-165K Annually
Senior level
In-Office
2 Locations
120K-165K Annually
Senior level
The Sr. Elastic Defend Analyst will monitor endpoints, analyze alerts, conduct threat hunting, manage incident response, and enhance customer cybersecurity defenses using Elastic Security tools.
The summary above was generated by AI
Job Summary & Responsibilities

ECS is seeking a Sr. Elastic Defend Analyst to work in our Colorado Springs, CO office.  

 

As a leading managed cybersecurity services provider, ECS delivers highly tailored cybersecurity solutions to meet each customer’s mission needs. Our Professional Services Team partners closely with customers to understand their environment, assess their security posture, and implement end-to-end solutions that strengthen defense, reduce risk, and improve operational visibility.

 

As an Elastic Defend Analyst, you will apply your specialized expertise in Elastic Security—particularly Elastic Defend and Endpoint Security—to detect threats, investigate incidents, and enhance customer protection. You will work across technical, operational, and advisory domains and must be confident operating independently, leading technical conversations, and driving outcomes with minimal oversight.

This role blends deep hands-on Elastic Defend proficiency with cybersecurity fundamentals, threat analysis, and strong communication skills to ensure customers are protected from modern cyber threats.

 

Responsibilities

Endpoint Threat Detection & Response (Elastic Defend)

  • Deploy, configure, and tune Elastic Defend agents across customer endpoints.
  • Monitor, analyze, and respond to endpoint telemetry, alerts, and detections generated by Elastic Defend.
  • Create and refine endpoint detection rules, exceptions, and response workflows to minimize false positives and strengthen threat coverage.

Elastic SIEM / Security Analytics

  • Leverage Elastic SIEM to correlate events across logs, endpoints, cloud, and network sources.
  • Build dashboards, detection rules, visualizations, and analytics that provide actionable intelligence to customers.
  • Perform root-cause analysis on alerts and incidents, producing clear and detailed technical reports.

Threat Hunting & Research

  • Conduct proactive hunts within Elastic Security using endpoint data, process behavior, and threat intelligence.
  • Investigate emerging threats, vulnerabilities, and adversary TTPs to enhance detection capabilities.
  • Contribute to continuous improvement of customer defenses by identifying gaps and proposing enhancements.

Incident Response & Analysis

  • Support incident triage, containment, remediation, and recovery using Elastic Defend and SIEM capabilities.
  • Analyze malicious files, processes, persistence mechanisms, and attacker behavior on compromised endpoints.
  • Assist customers during large-scale or targeted breach investigations.

Content Development & Automation

  • Develop custom detections, machine learning jobs, ingest pipeline logic, and endpoint response actions.
  • Use scripting (Python, PowerShell, etc.) to automate repetitive tasks, enrich data, or streamline investigations.
  • Evaluate new Elastic Security features and contribute recommendations for customer adoption.

Cross-Functional Collaboration & Communication

  • Collaborate with threat intelligence, SOC, threat hunting, and engineering teams to improve customer protection.
  • Provide clear, actionable guidance to technical and non-technical stakeholders.
  • Share best practices on Elastic Defend configuration, tuning, and operational use.

Salary Range: $120,000 - $165,000

General Description of Benefits

Preferred Qualifications
  • 2+ years of cybersecurity experience, preferably in detection, incident response, or endpoint security.
  • Strong hands-on expertise with Elastic Defend for EDR/endpoint telemetry, detection rule creation, and agent management.
  • Proficiency with Elastic SIEM, Kibana dashboards, ingest pipelines, and related Elastic Security components.
  • Solid understanding of cybersecurity concepts (network protocols, malware behavior, encryption, threat actor TTPs).
  • Strong analytical skills for interpreting endpoint and log data to detect anomalies.
  • Scripting experience (Python, PowerShell, or similar) for automation and data manipulation.
  • Experience creating or tuning SIEM/EDR rules, dashboards, and security content.
  • Excellent written and verbal communication skills.
  • Ability to work in a fast-paced environment with strong problem-solving skills.
  • Able and willing to perform planned domestic or international travel.
  • Must possess and maintain a U.S. Passport.
  • Secret clearance required (minimum).

Top Skills

Elastic Defend
Elastic Security
Elastic Siem
Powershell
Python

ECS Colorado Springs, Colorado, USA Office

2310 Executive Circle, Colorado Springs, CO, United States, 80906

Similar Jobs

17 Hours Ago
Remote or Hybrid
CO, USA
139K-208K Annually
Senior level
139K-208K Annually
Senior level
Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
As a Lead Healthcare Solutions Architect, you'll design secure cloud solutions for healthcare organizations, ensuring compliance with regulations. You'll engage with clients, translating their needs into strategies and collaborating with various teams to improve healthcare IT outcomes.
Top Skills: AWSAzureCernerDaasEpicFhirGCPHl7NasPacsSanVdiVMware
17 Hours Ago
Remote or Hybrid
CO, USA
190K-280K Annually
Senior level
190K-280K Annually
Senior level
Information Technology • Insurance • Software
The Sr. Strategic Account Manager develops customer relationships, retains revenue, resolves concerns, engages with teams for solutions, and sells products into strategic accounts.
Top Skills: Salesforce
Yesterday
Remote or Hybrid
6 Locations
109K-203K Annually
Mid level
109K-203K Annually
Mid level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The role focuses on selling Identity Security solutions, exceeding revenue goals, engaging customers, and collaborating with partners and internal teams.
Top Skills: Salesforce

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account