The opportunity
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the…
What you'll do
Analyse customer goals, pain points, existing architecture, and threat: landscape, translating them into technical requirements
Design Elastic Security solution architectures (SIEM, endpoint, cloud: security) that integrate with the customer's wider security ecosystem
Advise on the customer's security strategy and own the Elastic side of it,: aligning recommendations through regular sessions with senior and key stakeholders
Lead hands-on delivery of Elastic Security projects end-to-end, including: greenfield deployments and migrations from legacy SIEM/EDR platforms in mission-critical environments
Deploy and secure the Elastic platform: cluster architecture, RBAC and role mapping, single sign-on, private connectivity (private links, VPC peering), and hardening for enterprise and government environments
Architect and build large-scale data ingestion with Elastic Agent, Beats, and: Logstash, normalising data to ECS and integrating sources such as Kafka, Azure Event Hub, and AWS S3
What they're looking for
- Develop security content aligned to the customer's threat landscape: detection rules, dashboards, and alerting workflows
- Drive security migrations from competing platforms, applying deep knowledge: of Elastic's capabilities to translate each use case into its best form, whether through feature parity mapping or full redesign
- Establish detection-as-code practices for customers managing detections: programmatically: developing, testing, versioning, and deploying detection content with Python, Git, and CI/CD pipelines
- Apply and enable Elastic's Agentic AI capabilities (AI Assistant, Attack: Discovery, agent-driven workflows) to accelerate customers' detection and response