Senior Information Security Engineer - Security Architecture - Infosec

Elastic Elastic · Enterprise · United States · InfoSec

This role focuses on building and maintaining the ingestion pipelines for security telemetry into Elasticsearch, ensuring the health and performance of Elastic clusters. It involves integrating with various APIs, managing cloud infrastructure with Terraform and Kubernetes, and utilizing AI automation to reduce operational toil and improve workflows.

What you'd actually do

  1. Security telemetry ingestion - build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint and asset data). This means integrating with third-party and cloud provider APIs to pull telemetry: auth, pagination, rate limits, and handling schema changes. Both Elastic integrations and one-off custom integrations.
  2. Keep the Elastic Cloud on Kubernetes clusters healthy. Monitor and upgrade them regularly. This involves updating versions and builds. Manage capacity and shards. Handle index lifecycle management (ILM). Enable cross-cluster search (CCS).
  3. Use Terraform to manage cloud infrastructure and Elasticsearch resources. This includes managing pipelines, index templates, and alerts. Utilize Kubernetes and Helm to deploy scheduled ingest jobs.
  4. Use AI automation and tooling to reduce toil. This includes self-healing jobs and health checks. It also involves alerting, internal CLIs, and AI or agent-assisted workflows for investigation and operations.
  5. Data quality & reliability - Own the "is the security data actually flowing correctly?" question. Monitor backfills. Ensure that schemas and fields are consistent. Keep an eye on costs.

Skills

Required

  • Ability to operate Elastic and Elasticsearch in production
  • Kubernetes - deploying and operating workloads
  • Terraform - managing cloud and Elasticsearch resources as code
  • API integration - consuming REST APIs for data ingestion
  • Python scripting

Nice to have

  • Experience with ECK or Elasticsearch on Kubernetes
  • Experience with cloud providers
  • Knowledge of GitHub, PR-based workflows, GitHub Actions and Continuous Integration (CI)
  • Knowledge of SOC operations and incident response (IR) workflows
  • Ability to develop and use dashboard/visualization tools

What the JD emphasized

  • Eligibility to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments