
Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec
Elastic, the Search AI Company, enables organizations to find answers in real time using data at scale. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, unites search precision with AI intelligence across search, security, and observability solutions.
About the Role
Join the InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer to play a key role in protecting Elastic's data and systems. In this role, you will ingest the security telemetry that the entire security organization runs on, ensure it lands consistently in Elasticsearch, and maintain underlying Elastic clusters.
You will own the pipeline end-to-end: from onboarding new security data sources through ingest pipelines, to populating indices queried by detection, incident response, and consulting teams, as well as managing the clusters that store it all.
Key Responsibilities
- Security Telemetry Ingestion: Build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint, and asset data). Integrate with third-party and cloud provider APIs (authentication, pagination, rate limits, schema changes) using both built-in Elastic and custom integrations.
- Cluster Health & Maintenance: Keep Elastic Cloud on Kubernetes (ECK) clusters healthy with regular monitoring and upgrades. Manage capacity, shards, Index Lifecycle Management (ILM), and cross-cluster search (CCS).
- Infrastructure as Code: Use Terraform to manage cloud infrastructure and Elasticsearch resources (pipelines, index templates, alerts). Use Kubernetes and Helm to deploy scheduled ingest jobs.
- Automation & AI: Leverage AI tooling and automation to eliminate toil, including self-healing jobs, health checks, alerting, internal CLIs, and agent-assisted investigation workflows.
- Data Quality & Reliability: Monitor data flow, handle backfills, maintain schema consistency, and optimize infrastructure costs.
Qualifications
- Proven ability to operate Elastic and Elasticsearch in production (ingest pipelines, index templates, mappings, queries, and upgrades). Experience with ECK or Elasticsearch on Kubernetes is strongly preferred.
- Demonstrated track record of using AI tools to accelerate development, debugging, and operations while maintaining accountability for outcomes.
- Strong hands-on experience deploying and troubleshooting Kubernetes workloads (scheduled jobs, Helm charts, operators).
- Experience managing cloud and Elasticsearch infrastructure via Terraform.
- Proficient in consuming REST APIs for data ingestion (auth, pagination, rate limiting, error handling).
- Practical Python scripting skills for automation and data ingestion workflows.
- Eligibility to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.
Bonus Points
- Experience with cloud providers, especially Google Cloud Platform (GCP), handling audit and logging data.
- Familiarity with GitHub, PR-based workflows, GitHub Actions, and Continuous Integration (CI).
- Understanding of SOC operations, incident response (IR) workflows, and security telemetry analysis.
- Experience developing dashboards and data visualizations.
Compensation & Benefits
- Base salary range: €61.100—€97.000 EUR
- Parity-driven comprehensive health coverage for you and your family
- Flexible work schedule and remote location support
- Generous paid vacation days
- Minimum 16 weeks of paid parental leave
- Charitable donation and volunteer matching programs
Timezone overlap
UTC+0–+3
Benefits
Open to
Europe
Sign in to track applications and earn points.