Elastic logo
Elastic·Verified

Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Elastic, the Search AI Company, enables organizations to find the answers they need in real time using all their data at scale. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together search precision and AI intelligence to accelerate critical business results.

About the Role

Join the InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer, playing a central role in protecting organizational data and systems. In this position, you will own the pipeline end to end: from a new security data source landing, through ingest pipelines, into the indices queried by detection, incident response, and consulting teams, as well as the underlying Elastic clusters.

What You Will Be Doing

  • Security telemetry ingestion: Build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint, and asset data). Integrate with third-party and cloud provider APIs (handling authentication, pagination, rate limits, schema changes) via both Elastic integrations and custom builds.
  • Cluster management: Maintain, monitor, and regularly upgrade Elastic Cloud on Kubernetes (ECK) clusters. Manage capacity, shards, Index Lifecycle Management (ILM), and cross-cluster search (CCS).
  • Infrastructure as Code: Use Terraform to manage cloud infrastructure and Elasticsearch resources (pipelines, index templates, alerts). Deploy scheduled ingest jobs using Kubernetes and Helm.
  • AI automation & tooling: Implement AI automation, self-healing jobs, alerting, internal CLIs, and agent-assisted workflows to reduce toil in operations and investigations.
  • Data quality & reliability: Ensure data flows correctly, monitor backfills, maintain consistent schemas and field mappings, and monitor operational costs.

What You Bring

  • Production experience operating Elastic and Elasticsearch, including ingest pipelines, index templates, mappings, queries, and cluster health/upgrades (ECK or Elasticsearch on Kubernetes strongly preferred).
  • Demonstrated experience leveraging AI tools to accelerate development, debugging, and operational tasks.
  • Hands-on Kubernetes proficiency: deploying workloads, scheduled jobs, Helm charts, operators, and troubleshooting pods/jobs.
  • Experience with Terraform for managing cloud and Elasticsearch resources as code.
  • Proven track record integrating REST APIs for data ingestion (auth, pagination, concurrency, error handling).
  • Python scripting skills for building and modifying automation and ingestion scripts.
  • Eligibility to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.

Bonus Points

  • Hands-on experience with cloud providers (preferably GCP) and working with audit/logging data.
  • Familiarity with GitHub, pull request workflows, GitHub Actions, and CI/CD pipelines.
  • Understanding of SOC operations and incident response (IR) workflows.
  • Experience developing dashboard and visualization tools.

Compensation & Benefits

  • Base Salary: €67.000—€106.000 EUR (no variable compensation component)
  • Comprehensive health coverage for you and your family
  • Flexible work schedules and remote-first culture
  • Generous vacation policy
  • Minimum 16 weeks of paid parental leave
  • Charitable donation and volunteer matching programs

Timezone overlap

UTC+0–+3

Open to

Europe

Sign in to track applications and earn points.

More roles at Elastic

Similar remote roles