
Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec
Elastic is seeking a Senior Information Security Infrastructure Engineer to join the InfoSec - Security Architecture team. In this role, you will own the end-to-end security telemetry pipeline, from ingestion of new data sources into Elasticsearch to keeping underlying clusters healthy and performant for incident response, detection, and consulting teams.
What You Will Be Doing
- Security Telemetry Ingestion: Build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint, and asset data). Integrate with third-party and cloud provider APIs handling authentication, pagination, rate limits, and schema changes via Elastic integrations and custom workflows.
- Elasticsearch & ECK Operations: Maintain the health of Elastic Cloud on Kubernetes (ECK) clusters. Manage upgrades, capacity, shard allocations, Index Lifecycle Management (ILM), and Cross-Cluster Search (CCS).
- Infrastructure as Code: Utilize Terraform to manage cloud infrastructure and Elasticsearch resources (pipelines, index templates, alerts). Deploy scheduled ingest jobs using Kubernetes and Helm.
- Automation & Tooling: Leverage AI automation and tooling to reduce operational toil, including self-healing jobs, automated health checks, alerting, internal CLIs, and agent-assisted investigation workflows.
- Data Quality & Reliability: Ensure data integrity across all security pipelines. Monitor backfills, maintain schema and field consistency, and optimize infrastructure costs.
What You Bring
- Strong experience operating Elasticsearch in production: managing ingest pipelines, index templates, mappings, queries, and cluster lifecycle management. Experience with ECK (Elastic Cloud on Kubernetes) is strongly preferred.
- Demonstrated track record of leveraging AI to accelerate development, operational tasks, and debugging.
- Hands-on expertise with Kubernetes: deploying workloads, scheduled jobs, Helm charts, operators, and cluster-level troubleshooting.
- Infrastructure as Code proficiency using Terraform to manage cloud and Elasticsearch resources.
- Solid experience consuming REST APIs for data ingestion, handling auth, pagination, rate limits, concurrency, and errors.
- Scripting proficiency in Python for automation and data ingestion tasks.
- Eligibility to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.
Bonus Points
- Hands-on experience with cloud providers (preferably GCP) and handling audit/logging data.
- Familiarity with GitHub, PR-based workflows, GitHub Actions, and CI/CD pipelines.
- Knowledge of Security Operations Center (SOC) operations, incident response workflows, and telemetry usage during investigations.
- Experience designing and building visualization and dashboard tools.
Timezone overlap
UTC+1–+2
Benefits
Open to
Europe
Sign in to track applications and earn points.