the company, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The the company Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — the company’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.
What is The Role
the company Security is one of the fastest-growing parts of our business, and our customers (including government and public sector organisations) rely on our Security Solution to modernise their SOC, threat detection, and response capabilities.
You will lead the hands-on delivery of the company Security projects (new implementations, migrations, and use-case expansions) from discovery through architecture design and build. Along the way, you'll develop trusted relationships with senior stakeholders and work closely with our Services, Engineering and Sales teams.
the company is a remote-first company, but many of the projects you'll deliver might require onsite availability, making the role hybrid in practice, varying by project, with travel of up to 60%.Some of these engagements, given the organisations involved, also require national security screening or clearance; eligibility to obtain one in your country of employment is a strong advantage, and the company will sponsor the process where required.
What You Will Be DoingAssess and Design
- Analyse customer goals, pain points, existing architecture, and threat landscape, translating them into technical requirements
- Design the company Security solution architectures (SIEM, endpoint, cloud security) that integrate with the customer's wider security ecosystem
- Advise on the customer's security strategy and own the the company side of it, aligning recommendations through regular sessions with senior and key stakeholders
Implement and Deliver
- Lead hands-on delivery of the company Security projects end-to-end, including greenfield deployments and migrations from legacy SIEM/EDR platforms in mission-critical environments
- Deploy and secure the the company platform: cluster architecture, RBAC and role mapping, single sign-on, private connectivity (private links, VPC peering), and hardening for enterprise and government environments
- Architect and build large-scale data ingestion with the company Agent, Beats, and Logstash, normalising data to ECS and integrating sources such as Kafka, Azure Event Hub, and AWS S3
- Develop security content aligned to the customer's threat landscape: detection rules, dashboards, and alerting workflows
- Drive security migrations from competing platforms, applying deep knowledge of the company's capabilities to translate each use case into its best form, whether through feature parity mapping or full redesign
- Establish detection-as-code practices for customers managing detections programmatically: developing, testing, versioning, and deploying detection content with Python, Git, and CI/CD pipelines
- Apply and enable the company's Agentic AI capabilities (AI Assistant, Attack Discovery, agent-driven workflows) to accelerate customers' detection and response
Grow and Collaborate
- Identify and deliver new security use cases as customers mature their cyber defence journey with the company
- Deliver engagements on time and within the agreed Statement of Work (SOW) scope, surfacing opportunities for follow-on work
- Communicate confidently with stakeholders from SOC engineers up to CISO / C-suite level
- Partner with the company Sales and pre-sales to assess technical risks and shape opportunities
- Feed field insight back to the company Engineering, Product Management, and Support to drive feature enhancements
- Mentor and share knowledge with fellow the company consultants across a highly distributed team
- Lead or assist with demos and proof-of-concepts that showcase the value of the the company Stack, and deliver enablement sessions and hands-on workshops that make customer teams self-sufficient
What You Bring Along
- Minimum of 5 years' experience as a Consulting Architect, Senior Consultant, or in a senior IT technical leadership role, delivering and executing professional services engagements, ideally in the security domain
- Solid experience deploying the company Security or comparable SIEM platforms (e.g., Splunk, MS Sentinel, QRadar, ArcSight) and/or EDR platforms (e.g., CrowdStrike, MS Defender), or at least 2 years as a Security Analyst / Detection Engineer in a threat detection and response role
- An architect's view of the security ecosystem across varied customer environments: SOAR, vulnerability management, penetration testing, ticketing, and security policies, and how they connect in a SOC
- Scripting skills, ideally in Python, and exposure to modern delivery practices such as Infrastructure-as-Code and CI/CD are strongly preferred
- Hands-on experience with Linux and Windows operating systems, and on-prem and/or public cloud platforms (AWS, Azure, GCP)
- Strong customer advocacy, relationship-building, and communication skills, with the ability to pivot easily between delivery and strategic engagements
- Eligibility to obtain national security clearance in your country of employment (screening sponsored by the company where required)
- Willingness to travel and work onsite with customers (up to 60% of the time), combined with comfort working remotely in a highly distributed team
- Strong proficiency in both English (our company-wide operating language) and the local market language.
Bonus Points
- Experience with advanced Elasticsearch operations: cluster architecture, shard management, data ingestion, and data tiering at scale
- Experience with detection-as-code: authoring, testing, and versioning detection content managed in Git
- Experience automating deployments and lifecycle management with Python, Terraform, and CI/CD tooling (e.g., GitLab pipelines)
- Experience deploying and operating containerised workloads on Kubernetes, cloud-managed or self-hosted (EKS, AKS, GKE, OpenShift)
- Experience with Agentic AI and LLM-based security workflows: AI assistants, automated triage, and agent-driven investigation
- Experience as a Tier-2/Tier-3 SOC Analyst, Threat Hunter, or DevSecOps Engineer
- Experience in large distributed environments or MSSPs, from architecture through deployment
- Experience delivering enablement sessions, technical workshops, or product training to technical audiences
- the company Certified Engineer certification, or security certifications such as GIAC or CISSP
#LI-PF1
Additional Information - We Take Care of Our People
As a distributed company, diversity drives our identity. Whether you’re looking to launch a new career or grow an existing one, the company is the type of company where you can balance great work with great life. Your age is only a number. It doesn’t matter if you’re just out of college or your children are; we need you for what you can do.
We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.