IT & Software

Elasticsearch Consultant

Xcede

London · England · United Kingdom

Elastic SIEM Engineer We are seeking an experienced Elastic SIEM Engineer to design, implement and maintain security monitoring solutions using the Elastic Stack. The successful candidate will be responsible for developing scalable log-management and threat-detection capabilities across complex cloud and containerised environments.

Key Responsibilities Design, deploy and support Elastic SIEM solutions using Elasticsearch, Logstash and Kibana. Build and maintain log-ingestion pipelines for infrastructure, applications, cloud platforms and security tools. Develop Kibana dashboards, alerts, detection rules and visualisations. Configure data parsing, enrichment, transformation and indexing within Logstash and Elasticsearch. Integrate Kafka to support reliable, high-volume event streaming and log ingestion. Deploy and operate Elastic components within Kubernetes environments. Automate infrastructure provisioning, configuration and deployment using Ansible and Argo CD. Build and maintain GitLab CI/CD pipelines. Develop scripts and automation tools to improve platform administration and operational efficiency. Monitor platform health, performance, availability and storage capacity. Troubleshoot ingestion failures, data-quality issues and performance bottlenecks. Implement security controls, access management, data-retention policies and platform hardening. Work closely with cybersecurity, infrastructure, cloud and DevOps teams. Produce technical documentation, operational procedures and support runbooks. Essential Skills and Experience Strong experience with the Elastic Stack:

Elasticsearch Logstash Kibana

Experience implementing or supporting Elastic Security/Elastic SIEM. Strong understanding of log management, security monitoring and SIEM principles. Experience creating dashboards, alerts and security detection rules. Knowledge of Elasticsearch clusters, indexing, mappings, lifecycle management and performance optimisation. Experience building and supporting Logstash pipelines. Hands-on experience with Ansible. Experience with Apache Kafka or similar event-streaming technologies. Strong Kubernetes knowledge, including deploying and troubleshooting containerised services. Experience with GitOps deployment practices using Argo CD. Experience creating and maintaining GitLab CI/CD pipelines. Scripting experience using Python, Bash or a comparable language. Good understanding of Linux environments, networking and security fundamentals. Strong troubleshooting, analytical and communication skills. Desirable Experience Elastic certifications or relevant cybersecurity qualifications. Experience with Elastic Agent, Fleet, Beats and endpoint integrations. Knowledge of security frameworks such as MITRE ATT&CK. Experience developing threat-detection use cases and tuning SIEM alerts. Familiarity with cloud platforms such as AWS, Azure or Google Cloud. Experience working in enterprise, regulated or high-availability environments. Knowledge of Infrastructure as Code and DevSecOps practices.

TPBN1_UKTJ

Reference: WJ-5375_5772797

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.