Data Engineer
Listed on 2026-09-14
-
IT/Tech
Data Engineering, Cybersecurity, Information Security & Data Protection
We are hiring for Elastic Data Engineer – SIEM / Data Onboarding
Location:
Multiple locations across the United Kingdom (UK)
We are looking for a hands-on Senior Elastic Data Engineer with strong Data Engineering skills, particularly in onboarding raw, unstructured and semi-structured log data into Elastic Security / SIEM.
This is primarily a data onboarding and pipeline engineering role we need someone who is comfortable taking an unfamiliar raw log source, understanding its structure, building the required parsing and transformation logic, mapping it to ECS, and taking the data feed through to production.
Key skills we’re looking for:- Strong experience onboarding unstructured, semi-structured and structured logs from security, network, infrastructure and application platforms
- Hands-on development of Logstash pipelines for raw log ingestion and transformation
- Strong experience with Elasticsearch ingest pipelines
- Ability to parse complex and inconsistent log formats using Dissect, Grok, KV, JSON, CSV, scripting and native processors
- Experience handling syslog (RFC 3164 / RFC 5424) and multiple event formats within the same data source
- Strong understanding of Elastic Common Schema (ECS) and security data normalisation
- Experience designing data streams, mappings, component templates, index templates and ILM policies
- Hands-on experience with Elastic Agent, Fleet and integrations, including Custom Logs and Custom TCP/UDP
- Experience with Kafka → Logstash → Elasticsearch ingestion architectures
- Strong pipeline testing and troubleshooting skills, including malformed events, parsing failures and mapping conflicts
- Ability to own the complete data onboarding lifecycle — discovery, source-to-target mapping, development, testing, QA, deployment, validation and handover
We are looking for someone with genuine data engineering and log onboarding experience, not just Elastic administration, Kibana dashboarding or SIEM rule configuration.
You should be comfortable being given a raw/unfamiliar log sample and independently working out how to parse, normalise, enrich and onboard it into Elastic in a scalable and maintainable way.
Desirable certifications:Elastic Certified Engineer
Elastic Certified Analyst
If you have strong Elastic + Data Engineering + raw log onboarding experience, we’d be interested in speaking with you.
#Hiring #Elastic #Elasticsearch #Data Engineering #SIEM #Elastic Security #Logstash #Cyber Security #Data Onboarding #Kafka #ECS
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).