Elastic Cloud Security Engineer (R0248356)

Posted yesterday

seneca resourcesLexington (MA)

SENIORITY

Senior

Apply

About the role

The Opportunity: Designs, implements, integrates, and maintains systems and tools to automate complex cyber activities. Applies leading-edge principles, theories, and concepts. Contributes to the development of new principles and concepts. Works on unusually complex problems and provides highly innovative solutions. Operates with substantial latitude for unreviewed action or decision. Mentors or supervises employees in both company and technical competencies.
Qualifications: 5+ years of experience administering Elastic Stack, including Elasticsearch, Kibana, Logstash, Beats, or Fleet Experience managing Elasticsearch index lifecycle policies, index templates, and data streams at scale, and building Kibana dashboards, visualizations, and lens-based analytics for security operations Experience with Elastic Security detection rules, alerts, and case management workflows Experience with log ingestion pipeline design, including parsing, enrichment, and normalization across heterogeneous log sources such as network, endpoint, identity, and cloud Experience with Elastic Common Schema (ECS) and mapping non-standard log sources into ECS-compliant fields Experience working in government cybersecurity environments such as SOC, SIEM operations, or defensive cyber Experience optimizing log collections from AWS platform, endpoints, and network devices Knowledge of AI/ML concepts as applied to security analytics such as anomaly detection, behavioral baselining, or threat scoring Ability to obtain a Secret clearance Bachelor’s degree Nice to Have SkillsExperience working in an agile working environment Experience working with DoD clients Experience with Elastic's ML jobs, including for User and Entity Behavior Analytics (UEBA), rare process detection, or anomalous login patterns Experience with Elastic AI Assistant or integration of LLMs into Elastic Security workflows such as natural language querying and alert triage assistance Experience building or fine-tuning ML models outside Elastic, including Python, scikit-learn, and PyTorch, for security use cases such as threat detection or lateral movement scoring Experience with Elastic Agent fleet management at scale, including custom integrations and policy management Experience with cross-domain data flows and working in multi-classification environments such as IL4, IL5, or IL6 Experience with ES|QL or EQL for advanced threat hunting and detection-as-code workflows Kubernetes Certification such as Kubernetes and Cloud Native Certification or Kubernetes Application Developer Certification

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this