The
Senior Elastic Engineer is responsible for the administration, optimization, and governance of the full Elastic Stack and ensures its reliability and scalability
This role ensures platform reliability, security, scalability, and alignment with organizational workflows while driving user adoption and continuous improvement.
What You Will Do:- Architect and own the Elastic Stack (Elasticsearch, Logstash, Beats/Elastic Agent, Kibana) supporting high-volume security telemetry ingestion, detection, and search. Direct implementation experience with ECK is required.
- Design data models, index lifecycle management (ILM) strategies, sharding, and hot-warm-cold tiering for petabyte-scale, multi-tenant security data.
- Build and harden ingestion pipelines from EDR, network, cloud, and log sources into the Elastic Stack, in partnership with detection engineering.
- Tune cluster performance - query latency, indexing throughput, resource allocation - and drive capacity planning for growth.
- Own Elastic Stack security, upgrades, and reliability, including runbooks, monitoring, and incident response for the platform itself.
- Evaluate and roll out new Elastic capabilities (e.g., Elastic Security, ES|QL, machine learning jobs) that improve detection speed and analyst experience.
- Set technical direction for and mentor a small team of Elastic engineers, establishing standards, review practices, and on-call structure for the platform.
- Document architecture decisions, standards, and best practices, and represent the Elastic platform in cross-functional planning and vendor (Elastic) conversations.
What We Are Looking For:- 7+ years in search/data engineering or infrastructure roles, with 6+ years of hands-on Elasticsearch/Elastic Stack architecture experience.
- Deep expertise in Elasticsearch internals: sharding, replication, ILM, mapping/index design, query DSL and/or ES|QL, and cluster performance tuning at scale.
- Experience building ingestion pipelines with Logstash, Beats, or Elastic Agent, ideally with security/log data (SIEM, EDR, cloud logs).
- Comfort operating Elastic in private and public cloud environments (AWS/Azure) and with containerization (Docker/Kubernetes) and infrastructure-as-code.
- Working knowledge of security operations concepts (detections, alerting, SIEM workflows) is a strong plus
- Scripting/programming ability (Python, Go, or similar) for automation and tooling.
- Elastic Certified Engineer certification is a plus, not required.
Some Of What We Offer- Flexible Paid Time Off
- 401k with a company match
- Medical, Dental and Vision Coverage
- Voluntary Short Term and Long-Term Disability
- Employee Assistance Program with Mental Health Supplement
- Voluntary Basic, Accidental, and other ancillary life insurance
- Health Savings Account Contribution (with selection of a HDHP)
- 10 annual, paid holidays