Elastic logo
Elastic·Verified

Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Remote (region-restricted)Full-timeSenior€56K - €88KUTC+0–+1Portugal#elasticsearch#kubernetes#terraformHealthPTOParental leaveEquityCommissionBonus

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter.

What is The Role

Join the InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer, where you will play a key role in protecting Elastic's data and systems. This position offers the opportunity to work on projects that directly impact organizational security posture and collaborate with a skilled information security team.

You will ingest security telemetry across the entire security organization, ensuring reliable delivery into Elasticsearch and maintaining the underlying Elastic clusters. You own the pipeline end to end: from telemetry landing, through ingest pipelines, into detection indices, IR querying, and storage cluster operations.

What You Will Be Doing

  • Security Telemetry Ingestion: Build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint, and asset data). Integrate with third-party and cloud provider APIs to handle auth, pagination, rate limits, and schema changes via both Elastic integrations and custom pipelines.
  • Cluster Maintenance: Keep Elastic Cloud on Kubernetes (ECK) clusters healthy. Monitor and upgrade versions, manage capacity and shards, handle index lifecycle management (ILM), and enable cross-cluster search (CCS).
  • Infrastructure as Code: Use Terraform to manage cloud infrastructure and Elasticsearch resources (pipelines, index templates, and alerts). Use Kubernetes and Helm to deploy scheduled ingest jobs.
  • AI & Automation: Leverage AI automation and tooling to eliminate toil, including self-healing jobs, health checks, alerting, internal CLIs, and AI-assisted operational workflows.
  • Data Quality & Reliability: Monitor data flow, handle backfills, maintain schema and field consistency, and optimize infrastructure costs.

What You Bring

  • Proven experience operating Elasticsearch and Elastic clusters in production, including ingest pipelines, index templates, mappings, and queries.
  • Strong familiarity with ECK or running Elasticsearch on Kubernetes.
  • Demonstrated track record of leveraging AI tools to accelerate development, debugging, and operational tasks.
  • Kubernetes proficiency: deploying workloads (scheduled jobs, Helm charts, operators) and troubleshooting cluster pods/jobs.
  • Terraform expertise for provisioning cloud and Elasticsearch infrastructure as code.
  • REST API integration skills: handling authentication, pagination, rate limiting, concurrency, and errors.
  • Practical Python scripting skills to read, write, and maintain automation and ingestion scripts.
  • Eligibility to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.

Bonus Points

  • Hands-on experience with cloud providers (preferably GCP) working with audit and logging data.
  • Experience with GitHub, PR-based workflows, and GitHub Actions CI pipelines.
  • Familiarity with SOC operations, incident response workflows, and investigation telemetry.
  • Experience building and using dashboard and visualization tools.

Timezone overlap

UTC+0–+1

Open to

Portugal

Sign in to track applications and earn points.

More roles at Elastic

Similar remote roles