Elastic Engineer - Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
We are seeking a Software Engineer, Cybersecurity with strong experience in Elastic Security and/or Elastic Observability to help design, implement, and optimize enterprise security monitoring and detection capabilities. This role will focus on building scalable security solutions, enhancing SIEM operations, developing detection content, and leveraging advanced analytics and machine learning to identify and respond to cyber threats.
The ideal candidate has a blend of software engineering, cloud security, and cybersecurity expertise, with hands-on experience deploying and managing Elastic-based security solutions. Responsibilities
- Design, develop, and maintain security monitoring solutions within the Elastic platform.
- Build and optimize data ingestion pipelines for logs, events, and telemetry from multiple sources.
- Develop dashboards, visualizations, and reporting capabilities to support security operations.
- Create, tune, and maintain detection rules, alerts, and automated response workflows.
- Implement and enhance machine learning and anomaly detection capabilities.
- Configure and manage Elastic Agents and Fleet deployments.
- Integrate security tools and third-party technologies using actions and outbound connectors.
- Leverage Elastic AI capabilities, including Attack Discovery and AI Assistants, to improve threat detection and investigations.
- Support Cross-Cluster Search implementations for enterprise-scale visibility.
- Collaborate with security operations, threat intelligence, and engineering teams to improve detection coverage.
- Align detection strategies with the MITRE ATT&CK framework.
- Contribute to automation and software engineering initiatives that enhance security operations.
Requirements
- 3-7+ years of software engineering experience.
- Hands-on experience with Elastic Security or Elastic Observability.
- Strong SIEM experience, preferably within Elastic environments.
- Experience with:
- Data source and log ingestion
- Dashboards and visualizations
- Detection rules and alerts
- Machine learning and anomaly detection
- Actions and outbound connectors
- Experience deploying and managing:
- Elastic Agent
- Fleet
- Cross-Cluster Search
- Experience with Elastic AI capabilities, especially Attack Discovery.
- Knowledge of cloud architectures and hyperscalers, particularly Microsoft Azure.
- Cybersecurity background including:
- Threat Intelligence
- XDR/EDR technologies
- MITRE ATT&CK framework
- Strong troubleshooting, problem-solving, and collaboration skills., * Elastic Certified Engineer, Elastic Certified Analyst, or other Elastic certifications.
- Security certifications such as Security+, CySA+, CISSP, GIAC, or equivalent.
- Experience with security automation and orchestration.
- Knowledge of scripting and programming languages such as Python, Java, Go, or PowerShell.
- Experience supporting large-scale enterprise security monitoring environments.
What You’ll Bring
- Passion for cybersecurity and threat detection.
- Strong engineering mindset with a focus on automation and scalability.
- Ability to work across security, cloud, and development teams.
- Excellent communication and stakeholder management skills.
- Continuous learning mindset focused on emerging threats and technologies.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Data Engineer Salary UK
Where To Find Software Engineering Jobs
The Most Popular IT Jobs on the Market
Dev Digest 121 - AI goes offline