6+ years in systems engineering or infrastructure, including 2+ years of production Elastic Stack experience
Proficiency with at least one major cloud provider
Strong problem-solving skills and a self-starter mentality
Experience with federal security controls (TLS, SSO/SAML, PIV/CAC, STIG)
Ability to drive client relationships and identify expansion opportunities
Active TS/SCI Clearance required
Linux CLI fundamentals and basic networking knowledge
Responsibilities
Architect, deploy and tune Elastic Stack solutions across various environments
Execute legacy security platform migrations and modernize analyst workflows
Design and implement data ingestion pipelines using Elastic Agent and related tools
Harden deployments for federal compliance with security protocols
Build outcome-driven dashboards and advanced Kibana visualizations
Develop automation using Infrastructure-as-Code tools like Ansible or Terraform
Communicate technical decisions and trade-offs directly to client stakeholders
Contribute to internal intellectual property through reusable templates and architectures
Benefits
Opportunity to shape the growth and culture of a fast-growing company
Engagement with cutting-edge cybersecurity solutions
Direct interaction with clients and stakeholders
Access to advanced technologies and methodologies
Potential for career advancement in a specialized field
Full Job Description
Who we're looking for:
We are seeking an Elasticsearch Engineer (TS/SCI Clearance) with expertise in designing, deploying and optimizing Elastic Stack solutions in federal environments. This role supports the delivery of Elastic-based solutions across cloud, on-prem and hybrid infrastructures to enable security operations and data-driven outcomes. The Elasticsearch Engineer will lead technical implementations, support migrations and contribute to scalable architectures while engaging directly with client stakeholders. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.
What you'll be doing:
Architect, deploy and tune Elastic Stack solutions (Elastic Cloud Enterprise (ECE), Elastic Cloud on Kubernetes (ECK), Elastic Cloud) across cloud, on-prem and hybrid environments.
Execute legacy security platform migrations, including detection translation (e.g., Search Processing Language (SPL) 12 (ES|QL) Elasticsearch Query Language) and analyst workflow modernization.
Design and implement data ingestion pipelines using Elastic Agent, Fleet, Logstash and Beats.
Harden deployments for federal compliance, including Transport Layer Security (TLS), Personal Identity Verification/Common Access Card (PIV/CAC), Single Sign-On (SSO) / Security Assertion Markup Language (SSO/SAML), Security Technical Implementation Guide (STIG) and audit logging.
Build outcome-driven dashboards and advanced Kibana visualizations.
Develop automation using Infrastructure-as-Code (IaC) tools (Ansible, Terraform or equivalent).
Communicate technical decisions and trade-offs directly to client stakeholders.
Contribute to internal IP, including reusable templates, automation and reference architectures.
What you need to know:
Deep understanding of Elastic Stack capabilities and use cases across deployment, security and operations.
Knowledge of distributed cluster architecture at scale, including multi-tenant and CCS environments.
Must have's:
6+ years in systems engineering or infrastructure, including 2+ years of production Elastic Stack experience.
Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
Strong problem-solving skills and a self-starter mentality.
Solid written and verbal communication skills.
Linux Command-Line Interface (CLI) fundamentals and basic networking knowledge.
Hands-on experience with containerization and IaC tooling.
Proficiency with at least one major cloud provider.
Experience with federal security controls (TLS, SSO/SAML, PIV/CAC, STIG).
Proven track record leading engagements from scoping through delivery.
Deep knowledge of distributed cluster architecture at scale, including multi-tenant and CCS environments.
Ability to drive client relationships and identify expansion opportunities.
Applicants must hold and maintain an active TS/SCI Clearance (Full Scope polygraph preferred).
Beneficial to have:
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related field.
Elastic certifications (ECE or being on a defined certification track).
Elastic Security (SIEM, detection engineering, threat hunting and legacy migration).
Detection translation experience (SPL 12 ES|QL or equivalent).
Scripting proficiency (Python, Bash or PowerShell).
Exposure to AI-augmented search, RAG or semantic search use cases.
Prior professional services or consulting experience.
Where it's done:
Onsite (Herndon, VA).
About ShorePoint Inc.
ShorePoint Inc. is a cybersecurity and IT consulting firm that provides services to the federal government and commercial clients. The company's services include cybersecurity, cloud computing, data analytics, and software development. ShorePoint was founded in 2015 and is headquartered in Reston, Virginia. The company has additional offices in Washington, D.C. and Colorado Springs, Colorado.