Elastic Security Education & Enablement Consultant
- ECS
- Virginia, United States
- $100,000 – $115,000
ECS is seeking a Elastic Security Education & Enablement Consultant to work remotely. Please Note: This position is contingent upon contract award.
As a leading managed cybersecurity services provider, ECS delivers highly tailored cybersecurity solutions aligned to each customer’s mission needs. The Professional Services Team partners with customers to understand their environment, strengthen security posture, and deliver measurable outcomes across detection, response, and continuous improvement.
We are seeking an Education & Training Consultant with Elastic Security expertise to lead customer enablement, training delivery, and knowledge transfer efforts while also serving as a Security Analyst supporting Elastic Security operations and use cases. This role requires strong instructional and communication skills, the ability to translate technical concepts for diverse audiences, and hands-on experience with Elastic Security to support customer training, investigations, and best practice adoption.
Key Responsibilities
- Customer Training & Enablement (Primary): Develop and deliver instructor-led and virtual training sessions focused on Elastic Security, SIEM operations, threat detection, investigation workflows, and cybersecurity best practices.
- Curriculum Development: Create and maintain training materials, presentations, hands-on labs, student guides, exercises, and knowledge transfer documentation tailored to customer requirements.
- Learning Assessment & Adoption: Evaluate learner progress, gather feedback, and recommend improvements to training programs to maximize operational readiness and adoption.
- Elastic Platform Instruction: Teach customers how to effectively use Elastic Security, Kibana dashboards, detections, case management, visualizations, and reporting capabilities.
- Workshop Facilitation: Lead technical workshops, demonstrations, tabletop exercises, and hands-on sessions for security analysts, administrators, and leadership stakeholders.
- Knowledge Transfer: Support customer transitions through structured knowledge-sharing sessions and operational handoff activities.
- SIEM Operations (Elastic Security): Use Elastic Security to analyze security events, investigate alerts, identify indicators of compromise, and support customer security operations.
- Threat Detection & Analysis: Correlate data across network, cloud, and endpoint telemetry to identify suspicious activity and recommend investigative actions.
- Content Development: Develop and tune detections, dashboards, visualizations, and security content aligned with customer operational objectives.
- Incident Response Support: Assist customers with alert triage, incident investigations, containment recommendations, and root cause analysis activities.
- Threat Research: Research emerging threats, vulnerabilities, and adversary techniques to improve customer awareness and detection capabilities.
- Operational Documentation: Develop and maintain runbooks, training documentation, standard operating procedures, and best practices.
Salary Range: $100,000-$115,000
General Description of Benefits
Qualifications
2+ years of experience delivering technical training, cybersecurity education, or customer enablement programs
Elastic Security proficiency including monitoring, detection, investigation, dashboards, and reporting capabilities
Strong presentation, facilitation, and instructional communication skills
Experience developing training materials, course content, lab exercises, or technical documentation
Strong cybersecurity fundamentals including network protocols, common attack techniques, and security operations concepts
Strong analytical skills for identifying patterns and anomalies across multiple data sources
Experience supporting security investigations, alert triage, or threat analysis activities
Strong written and verbal communication skills
Ability to engage with technical and non-technical audiences
Willingness to support domestic or international travel (short, planned engagements)
Must possess and maintain a U.S. Passport
Must have a Secret clearance, at minimum
Desired Skills
- Experience delivering commercial or government cybersecurity training programs
- Prior experience working in a Security Operations Center (SOC)
- Experience with Elastic Security, SIEM, EDR, SOAR, and ticketing platforms
- Experience building technical labs, workshops, or hands-on learning environments
- Familiarity with threat actor tactics, techniques, and procedures (TTPs)
- Familiarity with cloud environments (AWS, Azure, GCP) and related security telemetry
- Experience supporting Elastic observability data (logs, metrics, traces)
- Certifications such as Elastic Certified Analyst, Elastic Certified Engineer, CISSP, CEH, GCIH, or equivalent
- Training certifications such as CompTIA CTT+, ATD, military instructor certifications, or equivalent instructional experience
- Entry-level cybersecurity certifications (A+, Net+, Sec+, GSEC, etc.)
Skills
- Elastic Security
- SIEM operations
- Threat Detection
- Security Investigations
- Instructor-Led Training
- Curriculum Development
- Knowledge Transfer









