Elasticsearch Consultant
Elasticsearch SIEM Engineer
Contract: Initial 6 months
Rate: Market rate - Inside IR35
Location: London – Hybrid
We are supporting a leading technology services organisation working with a major telecommunications client that is looking for an experienced Elasticsearch SIEM Engineer.
You will be responsible for designing, developing and supporting scalable Elastic Stack solutions, with a particular focus on security monitoring, log ingestion and SIEM capabilities.
Key responsibilities
- Design, deploy and maintain Elasticsearch, Logstash and Kibana environments
- Develop and optimise Logstash pipelines for security and operational data
- Onboard and enrich logs from cloud, infrastructure, network and security sources
- Create and tune Elastic SIEM detection rules, dashboards and alerts
- Improve cluster performance, resilience, scalability and data retention
- Automate deployments and configuration through Ansible and scripting
- Support containerised Elastic environments running on Kubernetes
- Manage streaming and ingestion workflows using Kafka
- Maintain CI/CD and GitOps processes through GitLab and Argo CD
- Collaborate with SOC, security, platform and infrastructure teams
Required experience
- Strong hands-on experience with Elasticsearch, Logstash and Kibana
- Experience implementing or supporting Elastic Security/Elastic SIEM
- Strong understanding of data ingestion, parsing, enrichment and alerting
- Experience with Ansible, Kafka and Kubernetes
- Experience using Argo CD and GitLab CI/CD
- Scripting experience with Python, Bash or similar
- Knowledge of Elasticsearch performance tuning, ILM, shards and cluster management
- Strong troubleshooting and stakeholder-management skills