Elastic Stack Engineer: Security Analytics & Ingestion

Jolera

United States

Remote

USD 140,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Competitive compensation package
Benefits package
Company events and recognitions

Job summary

Jolera is seeking a skilled Elastic Stack Engineer to design, deploy, and operate distributed Elastic environments for cybersecurity analytics and threat hunting.

You will own log ingestion pipelines, optimize performance, and translate complex data into clear insights for technical and non-technical stakeholders. The role emphasizes IaC, automation, and collaboration with a broader detection team.

Qualifications

  • Certified Elastic Engineer required.
  • Experience configuring and troubleshooting Elastic environments on-prem and Elastic Cloud.
  • Strong Elastic Stack architecture, design, deployment knowledge.
  • Deep understanding of Elasticsearch internals: indexing, search, data agg.
  • Experience managing large Elasticsearch clusters with high availability.
  • Proficiency in Elasticsearch Query DSL for complex queries and analytics.
  • Programming in Java, Python, or Ruby; scripting for automation beneficial.
  • Experience in cybersecurity and threat landscapes; defensive tech familiarity.
  • Knowledge of security measures in Elasticsearch: RBAC, encryption, index security, audit logs.
  • Experience handling logs/security events from various sources using ELK Stack.
  • Ability to craft complex queries, alerts, and visualizations for cybersecurity needs.
  • Data parsing using GROK/DISSECT, ingestion, ETL workflows.
  • Developing Elasticsearch Watchers.
  • Experience with Elastic Security, Detection Rules, ML & AI Assistant.
  • Develop Elasticsearch solutions for dashboards and ongoing monitoring.

Responsibilities

  • Design and operate distributed Elastic clusters with capacity planning and scaling.
  • Build and maintain ingestion pipelines aligned to ECS.
  • Manage large-scale Elastic Agent and Fleet deployments.
  • Serve as SME for log ingestion, parsing, normalization, and analysis.
  • Deliver Elastic infrastructure as code and automate deployments.
  • Develop and maintain Logstash pipelines (Syslog and others).
  • Integrate data sources into Elastic with clean, searchable data models.
  • Create automation/scripts to detect anomalies and improve workflows.
  • Build dashboards, visualizations, and investigation workflows in Kibana.
  • Continuously improve reliability by optimizing pipelines and architecture.
  • Support development of network intrusion analytics with the detection team.
  • Administer Linux systems for Elastic components and data pipelines.

Skills

Elastic Stack expertise
Cybersecurity experience
Log ingestion expertise
Java/Python/Ruby
ELK/WAF security

Education

Certified Elastic Engineer

Tools

Elasticsearch
Logstash
Kibana
Elastic Agent
Fleet

Job description

Jolera is seeking a skilled Elastic Stack Engineer to design, deploy, and operate distributed Elastic environments for cybersecurity analytics and threat hunting.

You will own log ingestion pipelines, optimize performance, and translate complex data into clear insights for technical and non-technical stakeholders. The role emphasizes IaC, automation, and collaboration with a broader detection team.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Elastic Engineer
Elastic Engineer

Jolera • United States

Remote
USD 140,000 - 180,000
Competitive compensation package
Benefits package
Company events and recognitions
Senior Elastic Stack SIEM Data Ingestion Architect
Senior Elastic Stack SIEM Data Ingestion Architect

Amentum company • Colorado Springs (CO)

On-site
USD 140,000 - 160,000
Health, dental, and vision insurance
Paid time off and holidays
401(k) matching
+6
Hybrid Elastic Data Engineer for Cyber Telemetry & SIEM
Hybrid Elastic Data Engineer for Cyber Telemetry & SIEM

Jcssolutions • Adelphi (MD)

Hybrid
USD 135,000 - 162,000
Health, dental, vision insurance
Life insurance
Disability insurance
+3
Elastic Platform Engineer - Logs & Threat Analytics
Elastic Platform Engineer - Logs & Threat Analytics

Booz Allen Hamilton • Fort Meade (MD)

On-site
USD 87,000 - 198,000
Elastic Stack Threat Analytics Engineer
Elastic Stack Threat Analytics Engineer

Booz Allen Hamilton • Scott Air Force Base (IL)

On-site
USD 87,000 - 198,000
Elastic Stack Engineer: ECS & Threat Visualization
Elastic Stack Engineer: ECS & Threat Visualization

Booz Allen Hamilton • Colorado Springs (CO)

On-site
USD 87,000 - 198,000
Elastic Stack Threat Analytics Engineer
Elastic Stack Threat Analytics Engineer

Booz Allen Hamilton • Columbus (OH)

On-site
USD 87,000 - 198,000
Elastic Stack Visualization & Security Engineer
Elastic Stack Visualization & Security Engineer

Booz Allen Hamilton • Pensacola (FL)

Hybrid
USD 87,000 - 198,000
Elastic Stack Engineer: Threat Hunting & Dashboards
Elastic Stack Engineer: Threat Hunting & Dashboards

Booz Allen Hamilton • San Antonio (TX)

On-site
USD 87,000 - 198,000
Elastic Stack Engineer: Threat Monitoring & Dashboards
Elastic Stack Engineer: Threat Monitoring & Dashboards

Booz Allen Hamilton • Oklahoma City (OK)

On-site
USD 87,000 - 198,000