Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec
On this page
TechJobs.ie Job Insights
Technologies & skills
Primary technologies
Cloud & infrastructure
Other technical skills
What you'll be doing
Join Elastic's InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer. You'll own end-to-end security telemetry ingestion, maintain Elastic Cloud on Kubernetes clusters, manage infrastructure as code, and use AI automation to enhance security data reliability and operations.
- Build and maintain ingestion of security-relevant data into Elasticsearch
- Integrate with third-party and cloud provider APIs for telemetry ingestion
- Monitor and upgrade Elastic Cloud on Kubernetes clusters
- Manage capacity, shards, and index lifecycle management
- Use Terraform to manage cloud infrastructure and Elasticsearch resources
- Deploy scheduled ingest jobs using Kubernetes and Helm
- Implement AI automation and tooling for operational efficiency
- Monitor data quality, reliability, and costs
Key requirements
Must-have
- Experience operating Elastic and Elasticsearch in production
- Experience with ECK or Elasticsearch on Kubernetes
- Proven use of AI to accelerate development and operations
- Kubernetes deployment and troubleshooting experience
- Terraform for managing resources as code
- API integration for data ingestion
- Python scripting skills
- Eligibility to work in DoD Impact Level 4 or above cloud environments
Nice-to-have
- Experience with cloud providers, preferably GCP
- Experience with audit and logging data
- Knowledge of GitHub, PR-based workflows, and GitHub Actions
- Knowledge of SOC operations and incident response workflows
- Ability to develop and use dashboard/visualization tools
Role signals
- Technical focus
- security infrastructure, data ingestion, automation
- Architecture / system design
- Indicated in the listing
- Hands-on vs management
- Hands-on
Similar jobs
Full job description
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.
What is The Role :
Join the InfoSec - Security Architecture team as a Senior Information Security Infrastructure Engineer, where you'll have the chance to play a key role in protecting our organization's data and systems. This position offers the opportunity to work on meaningful projects that directly impact our security posture and collaborate with a skilled team passionate about information security.
In more details: We ingest the security telemetry that the whole security org runs on. In this role you'll get that telemetry into Elasticsearch consistently and keep the underlying Elastic clusters healthy. You own the pipeline end to end: from a new security data source landing, through ingest pipelines, into the indices detection, IR, and consulting teams query, plus the clusters that store it all.
What You Will Be Doing :
-
Security telemetry ingestion - build and maintain ingestion of security-relevant data into Elasticsearch (cloud provider audit logs, identity/SaaS activity, endpoint and asset data). This means integrating with third-party and cloud provider APIs to pull telemetry:
-
auth, pagination, rate limits, and handling schema changes.
-
Both
-
Elastic integrations and one-off custom integrations.
-
Keep the Elastic Cloud on Kubernetes clusters healthy. Monitor and upgrade them regularly. This involves updating versions and builds. Manage capacity and shards. Handle index lifecycle management (ILM). Enable cross-cluster search (CCS).
-
Use Terraform to manage cloud infrastructure and Elasticsearch resources. This includes managing pipelines, index templates, and alerts. Utilize Kubernetes and Helm to deploy scheduled ingest jobs.
-
Use AI automation and tooling to reduce toil. This includes self-healing jobs and health checks. It also involves alerting, internal CLIs, and AI or agent-assisted workflows for investigation and operations.
-
Data quality & reliability - Own the "is the security data actually flowing correctly?" question. Monitor backfills. Ensure that schemas and fields are consistent. Keep an eye on costs.
What You Bring :
-
Ability to operate Elastic and Elasticsearch in production. This includes managing ingest pipelines, index templates, mappings, and queries, while ensuring that clusters are healthy and upgraded. Experience with ECK or Elasticsearch on Kubernetes is strongly preferred.
-
Proven track record of using AI to accelerate development, debug complex systems, and accelerate operations, while still owning the final outcomes.
-
Kubernetes - deploying and operating workloads (scheduled jobs, Helm charts, operators); troubleshooting pods/jobs in a cluster.
-
Terraform - managing cloud and Elasticsearch resources as code.
-
API integration - consuming REST APIs for data ingestion: authentication, pagination, rate limiting concurrency, and error handling.
-
Python scripting - able to read, write, and modify ingestion/automation scripts. Scripting-level, not full software-engineering depth.
-
Eligibility to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.
Bonus Points :
-
Experience with cloud providers.
-
Hands-on experience with cloud providers, preferably GCP, and working with audit and logging data.
-
Knowledge of GitHub, PR-based workflows, GitHub Actions and Continuous Integration (CI).
-
Knowledge of SOC operations and incident response (IR) workflows, including the use of security telemetry during investigations.
-
Ability to develop and use dashboard/visualization tools.
Compensation for this role is in the form of base salary. This role does not have a variable compensation component.
At Elastic, our compensation philosophy aims to provide fair, competitive and transparent remuneration. Salary ranges are established based on a combination of external market benchmarks, internal pay equity considerations, and the responsibilities and complexity associated with each role. This approach helps ensure consistency across comparable roles while remaining competitive within the relevant labour markets.
The final compensation offered within the applicable range will be determined based on several objective factors, including relevant professional experience, level of skills and expertise, alignment with the role requirements, and the overall scope and complexity of the position.
The typical starting salary range for this role is:
€87.300—€138.000 EUR
Additional Information - We Take Care of Our People
As a distributed company, diversity drives our identity. Whether you’re looking to launch a new career or grow an existing one, Elastic is the type of company where you can balance great work with great life. Your age is only a number. It doesn’t matter if you’re just out of college or your children are; we need you for what you can do.
We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.
-
Competitive pay based on the work you do here and not your previous salary
-
Health coverage for you and your family in many locations
-
Ability to craft your calendar with flexible locations and schedules for many roles
-
Generous number of vacation days each year
-
Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
-
Up to 40 hours each year to use toward volunteer projects you love
-
Embracing parenthood with minimum of 16 weeks of parental leave
Different people approach problems differently. We need that. Elastic is an equal opportunity employer and is committed to creating an inclusive culture that celebrates different perspectives, experiences, and backgrounds. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.
We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email candidate_accessibility@elastic.co. We will reply to your request within 24 business hours of submission.
Applicants have rights under Federal Employment Laws, view posters linked below: Family and Medical Leave Act (FMLA) Poster; Pay Transparency Nondiscrimination Provision Poster; Employee Polygraph Protection Act (EPPA) Poster and Know Your Rights (Poster)
Elasticsearch develops and distributes technology and information that is subject to U.S. and other countries’ export controls and licensing requirements for individuals who are located in or are nationals of the following sanctioned countries and regions: Belarus, Cuba, Iran, North Korea, Syria, or Russia, including the Ukrainian territories annexed by Russia (The Crimea region of Ukraine, The Donetsk People's Republic (DNR), The Luhansk People's Republic (LNR), Kherson or Zaporizhzhia). If you are located in or are a national of one of the listed countries or regions, an export license may be required as a condition of your employment in this role. Please note that national origin and/or nationality do not affect eligibility for employment with Elastic.
Please see here for our Privacy Statement.
Interview prep pack
Grounded in this listing. Use it to prepare examples before you apply.
Your interview focus
Based on this listing, the Senior Information Security Infrastructure Engineer role at Elastic focuses on building and maintaining secure, reliable data ingestion pipelines into Elasticsearch, managing Elastic clusters on Kubernetes, and leveraging automation and AI to optimize security operations.
- Hands-on Elasticsearch and Kubernetes experience·High
- API integration and automation skills·High
- Infrastructure as code (Terraform)·High
- AI-driven operational improvements·Medium
Only have 30 minutes?
Follow a focused preparation plan based on this job.
Start 30-minute prep
Your 30-minute plan
Review Elasticsearch and ECK Operations
0–8 minRefresh your knowledge and prepare examples of managing Elasticsearch clusters on Kubernetes, including upgrades, monitoring, and troubleshooting.
Prepare API Integration and Data Ingestion Stories
8–15 minSelect and outline specific projects where you integrated security data sources via APIs, focusing on technical challenges and solutions.
Revisit Terraform and Infrastructure as Code Practices
15–20 minReview your Terraform modules and workflows for managing cloud and Elasticsearch resources, and be ready to discuss them.
Gather Python Automation Examples
20–25 minIdentify and summarize Python scripts you have written for automation or ingestion, emphasizing their impact.
Reflect on AI and Automation Initiatives
25–30 minPrepare to discuss how you have used AI or automation to improve security operations, including outcomes and lessons learned.
Talking points
, 6 itemsEnd-to-End Security Telemetry Ingestion
You will need to describe your experience integrating diverse security data sources into Elasticsearch, including handling API authentication, pagination, and schema changes.
Operating Elasticsearch on Kubernetes (ECK)
Demonstrating hands-on experience with Elastic Cloud on Kubernetes, including cluster health, upgrades, and troubleshooting, is central to this role.
Infrastructure as Code with Terraform
You should be able to discuss how you have managed cloud and Elasticsearch resources using Terraform, including pipelines, templates, and alerts.
Python Scripting for Automation
Prepare examples of how you have used Python to automate ingestion, monitoring, or operational tasks, as scripting is required for this position.
AI and Automation in Security Operations
Be ready to explain how you have used AI or automation tools to reduce manual toil, implement self-healing jobs, or improve operational efficiency.
Data Quality, Reliability, and Cost Monitoring
You will need to show how you ensure data flows correctly, monitor for backfills, maintain schema consistency, and keep an eye on operational costs.
What to research
, 5 itemsElastic and Elasticsearch Operations
Review your experience managing Elasticsearch clusters, especially on Kubernetes (ECK), including upgrades, monitoring, and troubleshooting.
API Integration for Security Telemetry
Prepare examples of integrating with third-party and cloud provider APIs for ingesting security data, focusing on authentication, pagination, and error handling.
Terraform and Infrastructure as Code
Refresh your knowledge of using Terraform to manage cloud and Elasticsearch resources, including pipelines, templates, and alerts.
Python Scripting for Automation
Be ready to discuss and demonstrate Python scripts you have written for automation or data ingestion tasks.
AI and Automation in Security Operations
Gather examples of how you have used AI or automation to improve operational efficiency or reduce manual work in security contexts.
Questions to ask
, 6 itemsWhat are the main challenges your team faces with security telemetry ingestion today?
Why ask this? To understand the team's pain points and where your skills can add value.
How does the InfoSec - Security Architecture team collaborate with other security and engineering teams at Elastic?
Why ask this? To clarify cross-team workflows and communication expectations.
What tools and processes are currently in place for monitoring data quality and reliability in your pipelines?
Why ask this? To assess the maturity of existing systems and where you might contribute improvements.
How is AI currently being used in your security operations, and what opportunities do you see for further automation?
Why ask this? To gauge the organization's openness to innovation and your potential impact.
What is the process for upgrading and maintaining Elastic clusters, and how are incidents typically handled?
Why ask this? To understand operational expectations and incident response protocols.
Are there opportunities to contribute to dashboarding or visualization tools for security data?
Why ask this? To explore ways to expand your impact and support data-driven decision-making.
Register now to upload your CV
Create a free account, save a PDF or Word CV, and quick apply on roles that take applications here.
