Senior Security Engineer - Elastic SIEM and Detection Engineering
Listed on 2026-06-06
-
Engineering
Systems Engineer, Cybersecurity
Senior Security Engineer - Elastic SIEM and Detection Engineering
We’re looking for a Senior Security Engineer to lead our Elastic SIEM and Detection Engineering program. This engineering‑first role focuses on building scalable detection pipelines, improving telemetry quality, and developing high‑confidence detections that help security teams move faster and respond more effectively.
You’ll own the evolution of our Elastic Security environment – from log ingestion and platform optimization to Detection‑as‑Code pipelines and detection coverage strategy. The role is ideal for someone who enjoys building systems, improving signal quality, automating workflows, and solving detection engineering problems will also serve as a Tier 2 escalation point for complex security events, helping scope incidents, initiate containment, and improve detections based on real‑world activity.
This high‑impact role gives significant ownership and the opportunity to shape detection engineering across the organization.
What you’ll do- Own and optimize the Elastic Security platform (Elasticsearch, Kibana, Fleet, Logstash, Elastic Agents).
- Design and maintain ingestion pipelines for cloud, endpoint, network, and application telemetry.
- Improve telemetry quality, data retention, performance, and investigation workflows.
- Integrate SIEM workflows with SOAR and automation tooling.
- Build and maintain a Detection‑as‑Code pipeline using Git‑based workflows and CI/CD automation.
- Develop, test, tune, and maintain high‑fidelity detections using Elastic Security, EQL, and KQL.
- Reduce alert noise through tuning, enrichment, suppression, and exception handling.
- Map detections to MITRE ATT&CK and help drive detection coverage strategy.
- Track detection quality metrics including alert fidelity, false positive rates, and coverage gaps.
- Assist with complex alert escalations and perform initial incident scoping.
- Execute initial containment actions when necessary (endpoint isolation, IP/domain blocking, account suspension).
- Participate in a low‑frequency on‑call rotation for critical incidents.
- Translate incident learnings into improved detections and telemetry coverage.
- Partner with infrastructure, Dev Sec Ops , and cloud teams to improve logging and visibility.
- Build automation and tooling using Python and/or Power Shell.
- Support purple team exercises and adversary simulations.
- 5+ years of cybersecurity engineering experience.
- 3+ years focused on SIEM engineering, detection engineering, or security analytics.
- Strong hands‑on experience with Elastic Security and the Elastic Stack.
- Experience building or maintaining Detection‑as‑Code workflows using Git and CI/CD pipelines.
- Strong understanding of detection tuning, alert fidelity, and operational detection quality.
- Ability to independently investigate complex alerts and produce actionable findings.
- Elastic Security, Kibana, Fleet, Elastic Agents, EQL/KQL.
- Detection engineering and MITRE ATT&CK mapping.
- Jenkins, Bitbucket Pipelines, Git Hub Actions, or similar CI/CD tooling.
- Python and/or Power Shell scripting.
- AWS Cloud Trail, VPC Flow Logs, Azure Monitor, or similar telemetry sources.
- TCP/IP, DNS, HTTP/S, and common attack patterns.
- Threat intelligence enrichment and operationalization.
- SOAR playbook development and automated response workflows.
- Sigma rule development.
- Elastic detection‑rules ecosystem familiarity.
- Terraform or Ansible experience.
- Previous SOC or Incident Response background.
- 30 days:
Validate telemetry sources and establish initial detection coverage baseline. - 90 days:
Operational Detection‑as‑Code pipeline with initial custom detections deployed. - 180 days:
Reduced alert noise, improved coverage visibility, and stabilized SIEM operations.
- US pay range $123,000–$180,000 (based on experience, skills, and location).
- Comprehensive benefits package: medical, dental, vision coverage, FSA, disability, life insurance.
- 401(k) retirement plan with company match.
- Generous vacation policy.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).