Senior Information Security Infrastructure Engineer
Elastic- Compensation
- up to $2k Published range
- Location
- Remote - United Kingdom Remote eligibility
- Employment
- Full-time Senior
About the job
About Elastic
Elastic, the Search AI Company, enables everyone to find answers in real time using all their data at scale. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together search and AI. Elastic's cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.
Role Overview
Join the InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer, where you'll play a key role in protecting the organization's data and systems. You will own the security telemetry pipeline end to end: from new data sources landing, through ingest pipelines, into indices that detection, IR, and consulting teams query, plus the clusters that store it all.
Responsibilities
- Build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint and asset data), integrating with third-party and cloud provider APIs (auth, pagination, rate limits, schema changes).
- Keep Elastic Cloud on Kubernetes clusters healthy, monitor and upgrade them regularly, manage capacity and shards, handle index lifecycle management (ILM), and enable cross-cluster search (CCS).
- Use Terraform to manage cloud infrastructure and Elasticsearch resources, including pipelines, index templates, and alerts.
- Utilize Kubernetes and Helm to deploy scheduled ingest jobs.
- Use AI automation and tooling to reduce toil, including self-healing jobs, health checks, alerting, internal CLIs, and AI/agent-assisted workflows.
- Own data quality and reliability: monitor backfills, ensure schema consistency, and keep an eye on costs.
Qualifications
- Ability to operate Elastic and Elasticsearch in production, including managing ingest pipelines, index templates, mappings, and queries, while ensuring clusters are healthy and upgraded.
- Experience with ECK or Elasticsearch on Kubernetes is strongly preferred.
- Proven track record of using AI to accelerate development, debug complex systems, and accelerate operations.
- Kubernetes: deploying and operating workloads (scheduled jobs, Helm charts, operators); troubleshooting pods/jobs.
- Terraform: managing cloud and Elasticsearch resources as code.
- API integration: consuming REST APIs for data ingestion (authentication, pagination, rate limiting, concurrency, error handling).
- Python scripting: able to read, write, and modify ingestion/automation scripts (scripting-level, not full software-engineering depth).
Bonus Points
- Experience with cloud providers, preferably GCP, and working with audit and logging data.
- Knowledge of GitHub, PR-based workflows, GitHub Actions, and CI.
- Knowledge of SOC operations and incident response workflows.
- Ability to develop and use dashboard/visualization tools.
Additional Information
Elastic is a distributed company with a focus on diversity and inclusion. They offer competitive pay, health coverage, flexible locations and schedules for many roles, generous vacation days, up to $2000 match for financial donations and service, up to 40 hours for volunteer projects, and a minimum of 16 weeks of parental leave. Elastic is an equal opportunity employer.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.