Senior Elastic Platform Engineer (Secret Clearance)

Zachary Piper
Scott Air Force Base, United States of America
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 230K

Job location

Scott Air Force Base, United States of America

Tech stack

Amazon Web Services (AWS)
Computer Security
Data Integrity
Distributed Systems
Elasticsearch
Intrusion Detection and Prevention
Parsing
Performance Tuning
Logstash
Security Information and Event Management
Data Logging
Data Ingestion
SC Clearance
Kubernetes
Deployment Automation
Kibana
Splunk
Data Pipelines

Job description

Zachary Piper Solutions is seeking a to support an Air Force project at The team is seeking an experienced security engineer to lead the migration from splunk to Elastic for the agency. Expertise across the elastic stack and automated deployments is needed to be successful. Details below:

  • Lead the design, deployment, configuration, and administration of enterprise-scale Elastic environments supporting security monitoring and log analytics requirements.
  • Architect and implement the migration of security logging, monitoring, and SIEM capabilities from Splunk to Elastic, ensuring data integrity, performance, and operational continuity.
  • Build, manage, and optimize Elastic clusters, including Elasticsearch, Kibana, and associated components in highly available and secure environments.
  • Design, develop, and maintain custom data ingestion pipelines to collect, transform, enrich, and route security and operational log data from multiple sources into Elastic.
  • Deploy, configure, and support Elastic Cloud on Kubernetes (ECK) environments, leveraging Kubernetes operators to automate cluster lifecycle management and scaling.
  • Administer Kubernetes-based Elastic deployments, including cluster provisioning, upgrades, monitoring, troubleshooting, and performance tuning.
  • Create custom dashboards, visualizations, alerts, and reporting capabilities to support operational monitoring and security investigations.
  • Support testing, validation, and cutover activities associated with Splunk-to-Elastic migration efforts.
  • Mentor junior engineers and contribute to engineering best practices, standards, and continuous improvement initiatives.

Requirements

  • Bachelor's degree from an accredited university and 5+ years of experience supporting cyber security tooling, specifically elastic.
  • Extensive hands-on experience with Elasticsearch, Kibana, Logstash, Beats, and Elastic Agent.
  • Proven experience leading or supporting large-scale Splunk-to-Elastic migration projects.
  • Strong expertise in Kubernetes administration and containerized application deployments.
  • Experience deploying and supporting Elastic Cloud on Kubernetes (ECK) using Kubernetes Operators.
  • Deep understanding of security logging, SIEM architectures, threat detection, and security operations workflows.
  • Experience developing custom data ingestion, parsing, enrichment, and normalization solutions.
  • Strong troubleshooting and problem-solving skills in complex distributed system environments.
  • Experience supporting federal government, defense, or highly regulated environments is highly desirable.

Benefits & conditions

  • Total compensation based on experience level - $190,000-$230,000 + $5k relocation bonus based on experience level
  • Full Benefits: PTO, Paid Holidays, Medical, Dental, and Vision, 401k

#LI-MK1 #LI-Onsite

Keywords: Elastic Stack, Elasticsearch, Kibana, Logstash, secret, top secret, ts/sci, federal, W2, opentowork, hiring, Beats, Elastic Agent, Elastic Security, SIEM, Security Information and Event Management, Security Logging, Log Analytics, Threat Detection, Security Monitoring, Splunk Migration, Splunk to Elastic Migration, Data Migration, Elasticsearch Cluster Administration, Elastic Architecture, Distributed Systems, Index Lifecycle Management (ILM), Data Retention Policies, Index Management, Data Ingestion Pipelines, Custom Data Pipelines, ETL Development, Data Transformation, Data Enrichment, Log Parsing, Data Normalization, Log Aggregation, API Integration, Security Event Collection, Kubernetes, Elastic Cloud on Kubernetes (ECK), Kubernetes Operators, Container Orchestration, Containerized Deployments, Cloud-Native Architecture, Platform Engineering, Cluster Deployment, Cluster Management, Performance Tuning, Scalability, High Availability, Infrastructure Automation, DevOps, Site Reliability Engineering (SRE), Monitoring and Alerting, Root Cause Analysis, Troubleshooting, System Optimization, Linux Administration, Automation Scripting, CI/CD Pipelines, Security Operations (SOC), Cybersecurity, Role-Based Access Control (RBAC), Authentication and Authorization, Encryption, Audit Logging, Compliance, Incident Response, Threat Hunting, Security Analytics, Dashboard Development, Data Visualization, Technical Leadership, Solution Architecture, Systems Integration, Enterprise Logging, Government Contract Support, Federal Environments, Mission-Critical Systems, Requirements Analysis, Technical Documentation, Cross-Functional Collaboration, Agile Methodology, Engineering Best Practices, Enterprise Search, Operational Support, Infrastructure Engineering, Cloud Platforms, Custom Solution Development, Production Support, Platform Modernization.

Apply for this position