Elasticsearch Consultant

Xcede Recruitment Solutions

Greater London

On-site

GBP 85,000 - 110,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Xcede Recruitment Solutions is seeking an Elastic SIEM Engineer to design, implement and maintain security monitoring across cloud and containerised environments using the Elastic Stack. You will build scalable log-management, threat-detection capabilities and dashboards, driving security outcomes with automation.

Responsibilities include deploying Elastic SIEM, developing pipelines, integrating Kafka and operating within Kubernetes, while automating with Ansible, Argo CD and GitLab CI/CD.

Qualifications

  • Strong experience with the Elastic Stack (Elasticsearch, Logstash, Kibana).
  • Experience implementing or supporting Elastic Security/Elastic SIEM.
  • Solid understanding of log management, security monitoring and SIEM principles.
  • Experience creating dashboards, alerts and security detection rules.
  • Knowledge of Elasticsearch clusters, indexing, mappings, lifecycle management and performance optimization.
  • Experience building and supporting Logstash pipelines.
  • Hands-on experience with Ansible.
  • Experience with Apache Kafka or similar event-streaming technologies.
  • Strong Kubernetes knowledge, including deploying and troubleshooting containerised services.
  • Experience with GitOps deployment practices using Argo CD.
  • Experience creating and maintaining GitLab CI/CD pipelines.
  • Scripting experience using Python, Bash or a comparable language.
  • Good understanding of Linux environments, networking and security fundamentals.
  • Strong troubleshooting, analytical and communication skills.

Responsibilities

  • Design, deploy and support Elastic SIEM solutions using Elasticsearch, Logstash and Kibana.
  • Build and maintain log-ingestion pipelines for infrastructure, applications, cloud platforms and security tools.
  • Develop Kibana dashboards, alerts and detection rules and visualisations.
  • Configure data parsing, enrichment, transformation and indexing within Logstash and Elasticsearch.
  • Integrate Kafka to support reliable, high-volume event streaming and log ingestion.
  • Deploy and operate Elastic components within Kubernetes environments.
  • Automate infrastructure provisioning, configuration and deployment using Ansible and Argo CD.
  • Build and maintain GitLab CI/CD pipelines.
  • Develop scripts and automation tools to improve platform administration and operational efficiency.
  • Monitor platform health, performance, availability and storage capacity.
  • Troubleshoot ingestion failures, data-quality issues and performance bottlenecks.
  • Implement security controls, access management, data-retention policies and platform hardening.
  • Work closely with cybersecurity, infrastructure, cloud and DevOps teams.
  • Produce technical documentation, operational procedures and support runbooks.

Skills

Elastic Stack
Elasticsearch
Logstash
Kibana
Elastic SIEM
Log ingestion pipelines
Ansible
Argo CD
GitLab CI/CD
Kafka
Kubernetes
Python/Bash
Linux fundamentals

Tools

Ansible
Argo CD
GitLab CI/CD
Kafka
Kubernetes

Job description

Elastic SIEM Engineer

We are seeking an experienced Elastic SIEM Engineer to design, implement and maintain security monitoring solutions using the Elastic Stack. The successful candidate will be responsible for developing scalable log-management and threat-detection capabilities across complex cloud and containerised environments.

Key Responsibilities
  • Design, deploy and support Elastic SIEM solutions using Elasticsearch, Logstash and Kibana.
  • Build and maintain log‑ingestion pipelines for infrastructure, applications, cloud platforms and security tools.
  • Develop Kibana dashboards, alerts, detection rules and visualisations.
  • Configure data parsing, enrichment, transformation and indexing within Logstash and Elasticsearch.
  • Integrate Kafka to support reliable, high‑volume event streaming and log ingestion.
  • Deploy and operate Elastic components within Kubernetes environments.
  • Automate infrastructure provisioning, configuration and deployment using Ansible and Argo CD.
  • Build and maintain GitLab CI/CD pipelines.
  • Develop scripts and automation tools to improve platform administration and operational efficiency.
  • Monitor platform health, performance, availability and storage capacity.
  • Troubleshoot ingestion failures, data‑quality issues and performance bottlenecks.
  • Implement security controls, access management, data‑retention policies and platform hardening.
  • Work closely with cybersecurity, infrastructure, cloud and DevOps teams.
  • Produce technical documentation, operational procedures and support runbooks.
Essential Skills and Experience
  • Strong experience with the Elastic Stack:
    • Elasticsearch
    • Logstash
    • Kibana
  • Experience implementing or supporting Elastic Security/Elastic SIEM.
  • Strong understanding of log management, security monitoring and SIEM principles.
  • Experience creating dashboards, alerts and security detection rules.
  • Knowledge of Elasticsearch clusters, indexing, mappings, lifecycle management and performance optimisation.
  • Experience building and supporting Logstash pipelines.
  • Hands‑on experience with Ansible.
  • Experience with Apache Kafka or similar event‑streaming technologies.
  • Strong Kubernetes knowledge, including deploying and troubleshooting containerised services.
  • Experience with GitOps deployment practices using Argo CD.
  • Experience creating and maintaining GitLab CI/CD pipelines.
  • Scripting experience using Python, Bash or a comparable language.
  • Good understanding of Linux environments, networking and security fundamentals.
  • Strong troubleshooting, analytical and communication skills.
Desirable Experience
  • Elastic certifications or relevant cybersecurity qualifications.
  • Experience with Elastic Agent, Fleet, Beats and endpoint integrations.
  • Knowledge of security frameworks such as MITRE ATT&CK.
  • Experience developing threat‑detection use cases and tuning SIEM alerts.
  • Familiarity with cloud platforms such as AWS, Azure or Google Cloud.
  • Experience working in enterprise, regulated or high‑availability environments.
  • Knowledge of Infrastructure as Code and DevSecOps practices.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Elasticsearch Consultant
Elasticsearch Consultant

Consult • Greater London

Hybrid
GBP 60,000 - 80,000
SIEM Engineer (Elastic)
SIEM Engineer (Elastic)

Searchability • Hemel Hempstead

Hybrid
GBP 81,000 - 99,000
Salary up to £90,000 DOE
£5,400 car allowance
25 days holiday + bank holidays and in
+4
Security Engineer
Security Engineer

TRIA • Manchester

On-site
GBP 60,000 - 90,000
SIEM Engineer (Elastic)
SIEM Engineer (Elastic)

Searchability NS&D • Hemel Hempstead

Hybrid
GBP 81,000 - 99,000
25 days holiday + bank holidays and my
birthday off
Matched contributory pension up to 6%
+2
Elastic SIEM Engineer: Threat Detection & Cloud Monitoring
Elastic SIEM Engineer: Threat Detection & Cloud Monitoring

Xcede Recruitment Solutions • Greater London

On-site
GBP 85,000 - 110,000
Elasticsearch Consultant or Architect (Observability OR Security (SIEM) or Search (Data)
Elasticsearch Consultant or Architect (Observability OR Security (SIEM) or Search (Data)

GIOS Technology • United Kingdom

On-site
GBP 55,000 - 75,000
Senior Elasticsearch SIEM Engineer
Senior Elasticsearch SIEM Engineer

Consult • Greater London

Hybrid
GBP 60,000 - 80,000
Cyber Security Engineer SoC/SIEM (Contract)
Cyber Security Engineer SoC/SIEM (Contract)

Methods • Malvern

On-site
GBP 50,000 - 70,000
Elastic Stack SIEM Architect – On-Prem Security Expert
Elastic Stack SIEM Architect – On-Prem Security Expert

Searchability NS&D • Hemel Hempstead

Hybrid
GBP 81,000 - 99,000
25 days holiday + bank holidays and my
birthday off
Matched contributory pension up to 6%
+2
Data Engineer
Data Engineer

GIOS Technology • United Kingdom

On-site
GBP 70,000 - 100,000