Senior Security Engineer – Elastic

5ironCyber

Franklin (TN)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Company-paid health, dental and vision insurance
Up to a 4% 401k company match
Generous paid time off
Paid time off to vote and volunteer
Paid time off on your birthday
Up to $100 per month for internet and cell phone

Job summary

A cybersecurity firm is seeking a hands-on Security Engineer specialized in the Elastic Stack. This role involves designing and maintaining security detections and analytics within Elastic, working closely with SOC operations. Ideal candidates will have over 4 years of experience, strong Elasticsearch skills, and a focus on developing detection strategies. The position provides opportunities for professional growth in technical leadership. Benefits include health insurance, 401k match, and generous PTO.

Qualifications

  • 4+ years of experience working with the Elastic Stack in a security, observability, or analytics context.
  • Strong experience with Elasticsearch query language (ES|QL and/or KQL) and Kibana.
  • Hands-on experience building security detections, alerts, or analytics.
  • Hands-on experience building security detections, alerts, or analytics in SIEM or log analytics platforms.
  • Experience with Elastic Security (SIEM, Endpoint, Detection Rules).
  • Familiarity with endpoint, cloud, and infrastructure telemetry (e.g., EDR logs, Windows events, Linux logs, cloud audit logs).
  • Understanding of adversary behavior and detection methodologies, including the MITRE ATT&CK framework.
  • Experience working in ticketing or incident management systems in an operational environment.
  • Strong communication skills and ability to collaborate with SOC analysts and engineers.

Responsibilities

  • Design, implement, and maintain multi-tenant Elastic environments.
  • Support ingestion, normalization, and enrichment of security telemetry.
  • Collaborate with SOC leadership and product stakeholders for actionable improvements.
  • Improve detection fidelity by reducing false positives and increasing actionable signal.
  • Support ingestion, normalization, and enrichment of security telemetry from endpoints, cloud platforms, and network sources to expand visibility and detection coverage.
  • Maintain and optimize Elastic Stack components (Elasticsearch, Kibana, Beats, Elastic Agent) in collaboration with platform teams to meet evolving MDR and product requirements.
  • Assist with scaling, performance tuning, and reliability of Elastic-based security monitoring environments as the MDR platform grows.
  • Support onboarding of new data sources and clients into the Elastic security platform, ensuring consistency and operational readiness.
  • Proactively identify opportunities to enhance the Elastic platform through idea generation, proof-of-concept development, and implementation of new capabilities, detections, and workflows.
  • Partner with SOC leadership and product stakeholders to translate operational gaps and customer needs into actionable platform improvements.
  • Collaborate with SOC leadership, MDR engineering, and threat intelligence teams to evolve detection strategy.
  • Contribute to documentation, standards, and detection engineering best practices to support consistency and scalability across the MDR program.
  • Actively expand technical knowledge by learning and supporting additional security platforms and technologies beyond Elastic, as MDR capabilities evolve.
  • Mentor junior engineers or analysts as needed, sharing platform knowledge and detection engineering best practices.
  • For interested candidates, opportunities may exist to take on technical leadership or people management responsibilities over time.

Skills

Elastic Stack
Elasticsearch query language (ES|QL and/or KQL)
Kibana
Building security detections
Communication skills
endpoint/cloud telemetry
MITRE ATT&CK
incident management
communication

Education

Relevant certifications or formal education in cybersecurity or related fields

Tools

SIEM or log analytics platforms
Ticketing systems
Beats
Elastic Agent

Job description

Role Overview

The Security Engineer – Elastic is a hands-on engineering role responsible for designing, building, and maintaining security detections, analytics, and data pipelines within the Elastic Stack. This role partners closely with SOC operations to improve visibility, detection quality, and response effectiveness across endpoint, cloud, and infrastructure telemetry.

This is an individual contributor role. However, for candidates interested in future leadership opportunities, this position offers a strong foundation for growth into technical leadership or people management as the team scales.

RESPONSIBILITIES:
Elastic Engineering & Detection Development
  • Design, implement, and maintain multi-tenant Elastic environments, security detections, alerts, and analytics within the Elastic Stack.
  • Develop and tune detection logic aligned to real-world threats and the MITRE ATT&CK framework.
  • Build and optimize Elasticsearch queries, dashboards, and visualizations to support SOC operations and investigations.
  • Improve detection fidelity by reducing false positives and increasing actionable signal.
Data & Platform Engineering
  • Support ingestion, normalization, and enrichment of security telemetry from endpoints, cloud platforms, and network sources to expand visibility and detection coverage.
  • Maintain and optimize Elastic Stack components (Elasticsearch, Kibana, Beats, Elastic Agent) in collaboration with platform teams to meet evolving MDR and product requirements.
  • Assist with scaling, performance tuning, and reliability of Elastic-based security monitoring environments as the MDR platform grows.
  • Support onboarding of new data sources and clients into the Elastic security platform, ensuring consistency and operational readiness.
  • Proactively identify opportunities to enhance the Elastic platform through idea generation, proof-of-concept development, and implementation of new capabilities, detections, and workflows.
  • Partner with SOC leadership and product stakeholders to translate operational gaps and customer needs into actionable platform improvements.
Collaboration & Growth
  • Collaborate with SOC leadership, MDR engineering, and threat intelligence teams to evolve detection strategy.
  • Contribute to documentation, standards, and detection engineering best practices to support consistency and scalability across the MDR program.
  • Actively expand technical knowledge by learning and supporting additional security platforms and technologies beyond Elastic, as MDR capabilities evolve.
  • Mentor junior engineers or analysts as needed, sharing platform knowledge and detection engineering best practices.
  • For interested candidates, opportunities may exist to take on technical leadership or people management responsibilities over time.
Qualifications:
  • 4+ years of experience working with the Elastic Stack in a security, observability, or analytics context.
  • Strong experience with Elasticsearch query language (ES|QL and/or KQL), Kibana, and Elastic data models.
  • Hands‑on experience building security detections, alerts, or analytics in SIEM or log analytics platforms.
  • Experience with Elastic Security (SIEM, Endpoint, Detection Rules).
  • Familiarity with endpoint, cloud, and infrastructure telemetry (e.g., EDR logs, Windows events, Linux logs, cloud audit logs).
  • Understanding of adversary behavior and detection methodologies, including the MITRE ATT&CK framework.
  • Experience working in ticketing or incident management systems in an operational environment.
  • Strong communication skills and ability to collaborate with SOC analysts and engineers.
Preferred (Not Required):
  • Understanding of adversary behavior and detection methodologies, including the MITRE ATT&CK framework.
  • Scripting or automation experience (Python, Bash, or similar).
  • Experience in an MDR, MSSP, or SOC environment.
  • Relevant certifications or formal education in cybersecurity or related fields.
BENEFITS:
  • Company‑paid health, dental and vision insurance plans for the employee.
  • Up to a 4% 401k company match that vests immediately, it’s yours to keep.
  • Generous paid time off and 10 holidays per year.
  • Paid time off to vote and volunteer.
  • Paid time off on your birthday because it’s your special day.
  • Up to $100 per month for your internet and cell phone service.
  • Team building events.
ADDITIONAL:
  • All candidates will be required to take an extensive background screen, credit screen, and drug screen prior to employment.
  • This is an on‑site position for candidates located in Franklin, TN.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Elastic Engineer
Senior Elastic Engineer

CyberMaxx, Inc. • Linthicum (MD)

On-site
USD 160,000 - 230,000
Flexible PTO
401k with company match
Medical, Dental and Vision insurance
+2
Senior Elastic Engineer
Senior Elastic Engineer

CyberMaxx • Linthicum (MD)

On-site
USD 140,000 - 190,000
401k with company match
Medical, Dental, and Vision coverage
Paid time off
+1
Senior Manager, Endpoint Protections
Senior Manager, Endpoint Protections

Elastic • United States

On-site
USD 180,000 - 240,000
Health coverage
Flexible locations & schedules
Generous vacation days
+2
Elasticsearch Lead Engineer - SIEM Platform
Elasticsearch Lead Engineer - SIEM Platform

Vanguard • Malvern

On-site
USD 170,000 - 230,000
Principal Product Manager - Identity Threat Detection and Response
Principal Product Manager - Identity Threat Detection and Response

Elastic • United States

On-site
USD 180,000 - 230,000
Health coverage
Flexible locations and schedules
Generous vacation days
+1
Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec
Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Elastic • Mountain View (CA)

Hybrid
USD 159,900 - 252,900
Health coverage
Flexible locations and schedules
Generous vacation
+5
Principal Threat Hunting and Emulation Engineer - InfoSec
Principal Threat Hunting and Emulation Engineer - InfoSec

Elasticsearch B.V. • United States

Hybrid
USD 160,000 - 253,000
Health coverage for you and family
Flexible locations and schedules
Generous vacation days
+1
Principal Threat Hunting and Emulation Engineer - InfoSec
Principal Threat Hunting and Emulation Engineer - InfoSec

Elastic • Mountain View (CA)

Hybrid
USD 160,000 - 253,000
Health coverage
Flexible locations & schedules
Vacation days
+4
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Washington

On-site
USD 237,000 - 297,000
Comprehensive health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Seattle (WA)

On-site
USD 237,000 - 297,000
Comprehensive health benefits
Retirement benefits
Learning and development stipend
+2