The Senior Elastic Stack Data Integration Engineer will serve as the primary technical authority for designing, building, and maintaining data ingestion pipelines supporting Elastic SIEM. This role focuses on creating scalable, resilient Logstash architectures; developing advanced pipeline logic; normalizing, enriching, and transforming security telemetry; and ensuring reliable delivery of high-fidelity data to Elasticsearch. The successful candidate will have deep command of Logstash architecture, patterns, and performance optimization, mastery of parsing, enrichment, normalization, and ECS alignment, and strong understanding of network protocols, logging patterns, and telemetry generation from enterprise systems. Advanced troubleshooting skills across data ingestion, pipeline logic, and Elastic Stack processing layers are essential. The candidate must be capable of designing scalable, HA ingestion workflows with clear operational boundaries, and able to conduct data modeling, schema design, and transformation mapping. They should be effective at interfacing with multiple teams, gathering requirements, and aligning pipeline designs with SIEM analytics needs, with a focus on reliability, maintainability, and observability across all pipeline components. Strong attention to detail and a disciplined approach to documentation, versioning, and configuration management are required. The candidate must demonstrate the ability to work independently, drive pipeline architecture decisions, and mentor junior engineers. Strong documentation, workflow diagramming, and communication skills are also necessary.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed