Elasticsearch Lead Engineer - SIEM Platform

Vanguard

Malvern (Chester County)

On-site

USD 170,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vanguard is seeking an Elasticsearch Lead Engineer for the SIEM Platform in the United States. You will architect and maintain high-scale Elasticsearch clusters supporting security event ingestion and detection analytics.

You will map ECS across data sources, design ingestion pipelines, and integrate with AWS services like S3, Kinesis, Lambda, and CloudWatch. You will also enforce security controls and runbooks, and mentor junior engineers.

Qualifications

  • 6+ years Elasticsearch / Elastic Stack in production security or observability
  • Mapping logs to ECS across Windows, Linux, cloud and EDR
  • Scale: 10TB+/day ingest, 100+ node clusters
  • Hands-on with AWS services: S3, Kinesis, CloudWatch, IAM
  • Security controls: TLS, RBAC, audit logging
  • IaC tools: Terraform / Ansible / CDK

Responsibilities

  • Architect and maintain high-availability Elasticsearch clusters for large-scale security event ingestion
  • Define ECS field mappings across sources for consistent detection and analytics
  • Design data ingestion pipelines and integrate with AWS services for log collection
  • Manage AWS infrastructure using CloudFormation
  • Implement ILM policies and data lifecycle for S3-based data lakes
  • Collaborate with Detection Engineering and Threat Intelligence on index strategies
  • Establish cluster security controls: TLS, RBAC, audit logging, encryption at rest
  • Build resilient architectures with cross-cluster replication and DR runbooks
  • Monitor platform health and perform upgrades/patching
  • Troubleshoot production Elasticsearch cloud issues
  • Define and enforce SLOs for ingestion latency, queries, and availability
  • Mentor engineers and establish runbooks and standards

Skills

Elasticsearch expertise
Cloud security fundamentals
Leadership / mentoring
Production-grade systems

Education

Bachelor's degree in related field

Tools

AWS
Terraform
Ansible
CDK
Kubernetes

Job description

Elasticsearch Lead Engineer - SIEM Platform
  • Architect and maintain high-availability Elasticsearch clusters supporting large-scale security event ingestion
  • Define and enforce Elastic Common Schema (ECS) field mappings across all data sources, ensuring consistent normalization for detection rules and analytics
  • Design and develop custom data ingestion pipelines using Elasticsearch
  • Integrate with AWS services including S3, Kinesis Data Streams, Lambda, and CloudWatch for log collection
  • Manage AWS infrastructure: EC2, S3, IAM, and Secrets Manager - using AWS CloudFormation
  • Implement data lifecycle management - hot/warm/cold/frozen tier strategies, ILM policies, and snapshot/restore to S3-based data lakes
  • Partner with Detection Engineering and Threat Intelligence teams to optimize index strategies, queries, and dashboards in Kibana
  • Establish and maintain cluster security controls: TLS/mTLS, role-based access control (RBAC), audit logging, and encryption at rest
  • Build resilient, fault-tolerant architectures: cross-cluster replication, shard allocation awareness, and disaster recovery runbooks
  • Perform activities related platform health monitoring and upgrade / patching
  • Troubleshoot and manage production technical issues related to Elasticsearch cloud
  • Define and enforce SLOs for ingestion latency, query performance, and cluster availability
  • Mentor junior engineers and establish best practices, runbooks, and architectural standards
Qualifications
  • Minimum of six years related work experience.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • 6+ years of Elasticsearch / Elastic Stack (ELK) experience in a production security or observability environment
  • Deep understanding of Elastic Common Schema (ECS) and experience mapping diverse log sources (Windows, Linux, network, cloud, EDR) to ECS
  • Hands-on experience operating Elasticsearch at scale (10TB+/day ingest, 100+ node clusters)
  • Proficiency with AWS - Kinesis, S3, IAM, CloudTrail, and AWS‑native log sources
  • Experience with data streaming platforms - Apache Kafka, or Confluent Platform - for high‑throughput event ingestion
  • Experience integrating with data lake platforms - AWS S3 / Lake Formation, Data Lake, or Apache Iceberg for long‑term retention and threat hunting
  • Strong understanding of security principles: least privilege, network segmentation, secrets management, audit logging
  • Experience building resilient systems: replication topologies, capacity planning, chaos engineering mindset, and documented DR procedures
  • Proficiency with infrastructure‑as‑code tools (Terraform, Ansible, or CDK) (Optional)
Preferred Qualifications
  • Elastic Certified Engineer or Elastic Certified Analyst certification
  • Experience with Elastic Security / SIEM detection rules, ML jobs, and Timeline investigations
  • Familiarity with MITRE ATT&CK framework and how it informs index and detection design
  • Experience with container‑based deployments of Elastic (ECK / Kubernetes)
  • Knowledge of compliance frameworks: SOC 2, PCI‑DSS, HIPAA, or FedRAMP
Special Factors

Sponsorship: Vanguard is not offering visa sponsorship for this position.

Benefits

suite of benefits that includes comprehensive health and wellness care, work‑life balance, and an investment in your future at its core.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Elasticsearch Lead Engineer – SIEM Platform Architect
Elasticsearch Lead Engineer – SIEM Platform Architect

Vanguard • Malvern

On-site
USD 170,000 - 230,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Senior Elastic Engineer
Senior Elastic Engineer

CyberMaxx, Inc. • Linthicum (MD)

On-site
USD 160,000 - 230,000
Flexible PTO
401k with company match
Medical, Dental and Vision insurance
+2
Sr. Elastic Engineer
Sr. Elastic Engineer

ECS • Shiloh (IL)

On-site
USD 100,000 - 130,000
Senior Elastic Engineer
Senior Elastic Engineer

CyberMaxx • Linthicum (MD)

On-site
USD 140,000 - 190,000
401k with company match
Medical, Dental, and Vision coverage
Paid time off
+1
Elastic Engineer
Elastic Engineer

Phase2 Technology • Honolulu (HI)

On-site
USD 86,000 - 198,000
Senior Security Engineer – Elastic
Senior Security Engineer – Elastic

5ironCyber • Franklin (TN)

On-site
USD 110,000 - 140,000
Company-paid health, dental and vision insurance
Up to a 4% 401k company match
Generous paid time off
+3
Sr. Elastic Engineer
Sr. Elastic Engineer

ECS • Bedford (MA)

On-site
USD 180,000 - 210,000
Elasticsearch Engineer (TS/SCI Clearance)
Elasticsearch Engineer (TS/SCI Clearance)

ShorePoint • Herndon (VA)

On-site
USD 110,000 - 140,000
144 hours of PTO
85% of insurance premium covered
401k
+1
Principal Solutions Architect, Security Specialist
Principal Solutions Architect, Security Specialist

Elasticsearch B.V. • United States

On-site
USD 129,000 - 204,000
Competitive pay based on performance
Flexible locations and schedules
Health coverage for employees and families
+2