Elasticsearch Lead Engineer - SIEM Platform
Core
Architect and maintain high-availability Elasticsearch clusters supporting large-scale security event ingestion for a global SIEM platform.
Role type
Senior IC Elasticsearch Lead Engineer (SIEM Platform)
Builds
High-availability Elasticsearch clusters, custom data ingestion pipelines, and resilient fault-tolerant architectures for security event processing.
Domain
Cybersecurity / SIEM / Cloud Infrastructure
Deliverable
production ML models | infrastructure
Required skills
Elasticsearch cluster architecture, Elastic Common Schema (ECS) mapping, AWS services (S3, Kinesis, Lambda, CloudWatch), data lifecycle management (ILM), security controls (TLS/mTLS, RBAC), infrastructure-as-code (Terraform/Ansible/CDK), SLO definition, mentorship
Preferred skills
Elastic Security/SIEM detection rules, MITRE ATT&CK framework, container-based deployments (ECK/Kubernetes), compliance frameworks (SOC 2, PCI-DSS, HIPAA)
Technologies
Elasticsearch, Kibana, AWS (EC2, S3, IAM, Secrets Manager, CloudFormation), Apache Kafka, Confluent Platform, AWS S3/Lake Formation, Apache Iceberg, Terraform, Ansible, CDK
Responsibilities
Architect and maintain high-availability Elasticsearch clusters; Define and enforce ECS field mappings; Design and develop custom data ingestion pipelines; Integrate with AWS services for log collection; Manage AWS infrastructure; Implement data lifecycle management strategies; Partner with Detection Engineering teams to optimize index strategies; Establish and maintain cluster security controls; Build resilient, fault-tolerant architectures; Perform platform health monitoring and upgrades; Troubleshoot production technical issues; Define and enforce SLOs; Mentor junior engineers
Seniority
Senior, hands-on IC with mentorship responsibilities