Skip to main content

Senior Information Security Infrastructure Engineer

Elastic
Hybrid - PortugalUpdated 11h ago
Base salary
€56k–€88k
Published base salary range
Location
Hybrid - Portugal
Remote eligibility
Employment
Full-time
Senior
Role family
Security
B2B SaaS
Apply on jobs.elastic.co
Job actionsApply now
Job actionsApply now

About the job

About the Role

Join the InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer, where you'll play a key role in protecting our organization's data and systems. You will own the security telemetry pipeline end to end: from new security data sources landing, through ingest pipelines, into the indices that detection, IR, and consulting teams query, plus the clusters that store it all.

Responsibilities

  • Build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint and asset data), integrating with third-party and cloud provider APIs (auth, pagination, rate limits, schema changes).
  • Keep Elastic Cloud on Kubernetes clusters healthy: monitor, upgrade versions, manage capacity and shards, handle index lifecycle management (ILM), enable cross-cluster search (CCS).
  • Use Terraform to manage cloud infrastructure and Elasticsearch resources, including pipelines, index templates, and alerts.
  • Utilize Kubernetes and Helm to deploy scheduled ingest jobs.
  • Use AI automation and tooling to reduce toil, including self-healing jobs, health checks, alerting, internal CLIs, and AI/agent-assisted workflows.
  • Own data quality and reliability: monitor backfills, ensure schema/field consistency, and keep an eye on costs.

Qualifications

  • Ability to operate Elastic and Elasticsearch in production, including ingest pipelines, index templates, mappings, and queries, while ensuring clusters are healthy and upgraded.
  • Experience with ECK or Elasticsearch on Kubernetes is strongly preferred.
  • Proven track record of using AI to accelerate development, debug complex systems, and accelerate operations, while owning final outcomes.
  • Kubernetes: deploying and operating workloads (scheduled jobs, Helm charts, operators); troubleshooting pods/jobs.
  • Terraform: managing cloud and Elasticsearch resources as code.
  • API integration: consuming REST APIs for data ingestion (authentication, pagination, rate limiting, concurrency, error handling).
  • Python scripting: able to read, write, and modify ingestion/automation scripts (scripting-level, not full software-engineering depth).

Bonus Points

  • Experience with cloud providers, preferably GCP, and working with audit and logging data.
  • Knowledge of GitHub, PR-based workflows, GitHub Actions, and CI.
  • Knowledge of SOC operations and incident response (IR) workflows.
  • Ability to develop and use dashboard/visualization tools.

Compensation & Benefits

Compensation is in the form of base salary; no variable component. Typical starting salary range: €55,800—€88,000 EUR. Benefits include health coverage for you and your family in many locations, flexible locations and schedules for many roles, generous vacation days, up to $2000 match for financial donations and service, up to 40 hours/year for volunteer projects, and minimum 16 weeks of parental leave.

Application Instructions

Apply via the provided job link. For accommodation requests, email candidate_accessibility@elastic.co.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.