Elastic logo
Elastic·Verified

Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale. The Elastic Search AI Platform brings together search precision and AI intelligence to help organizations deliver on the promise of AI.

What is the Role

Join the InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer, where you will play a key role in protecting our organization's data and systems. In this role, you will ingest the security telemetry that the entire security organization relies on into Elasticsearch consistently and keep the underlying Elastic clusters healthy.

You own the pipeline end to end: from a new security data source landing, through ingest pipelines, into the indices queried by detection, incident response (IR), and consulting teams, along with the clusters that store it all.

What You Will Be Doing

  • Security Telemetry Ingestion: Build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint, and asset data). Integrate with third-party and cloud provider APIs handling authentication, pagination, rate limits, and schema changes via both Elastic integrations and custom pipelines.
  • Cluster Operations: Maintain Elastic Cloud on Kubernetes clusters. Monitor, upgrade versions/builds, manage capacity and shards, handle Index Lifecycle Management (ILM), and enable Cross-Cluster Search (CCS).
  • Infrastructure as Code: Use Terraform to manage cloud infrastructure and Elasticsearch resources (pipelines, index templates, and alerts). Deploy scheduled ingest jobs using Kubernetes and Helm.
  • Automation & Tooling: Use AI automation and tooling to reduce toil, including self-healing jobs, health checks, alerting, internal CLIs, and AI-assisted workflows for operations and investigations.
  • Data Quality & Reliability: Ensure security data flows accurately. Monitor backfills, verify field/schema consistency, and track infrastructure costs.

What You Bring

  • Strong experience operating Elastic and Elasticsearch in production (ingest pipelines, index templates, mappings, queries, and cluster health/upgrades). Experience with ECK (Elasticsearch on Kubernetes) is strongly preferred.
  • Proven track record of leveraging AI to accelerate development, debug complex systems, and streamline operations.
  • Solid Kubernetes skills: deploying and running workloads (scheduled jobs, Helm charts, operators) and troubleshooting pods/jobs.
  • Experience with Terraform for managing cloud and Elasticsearch resources as code.
  • Hands-on API integration experience: consuming REST APIs for data ingestion with robust authentication, pagination, rate limiting, and error handling.
  • Python scripting proficiency to write and modify ingestion and automation workflows.
  • Eligibility to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.

Bonus Points

  • Hands-on experience with cloud providers (preferably GCP) and working with audit/logging data.
  • Knowledge of GitHub, PR-based workflows, GitHub Actions, and Continuous Integration (CI).
  • Knowledge of SOC operations, incident response workflows, and the use of telemetry during investigations.
  • Ability to develop and maintain dashboard and visualization tools.

Timezone overlap

UTC+0–+1

Open to

Europe

Sign in to track applications and earn points.

More roles at Elastic

Similar remote roles