Senior Security Engineer (Elastic SIEM)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Engineer (Elastic SIEM): Building and optimizing scalable detection pipelines and improving telemetry quality with an accent on Detection-as-Code and SIEM platform optimization. Focus on developing high-confidence detections, automating workflows with CI/CD, and mapping coverage to MITRE ATT&CK.
Location: Burlington, MA, USA
Salary: $123,000–$180,000
Company
A global leader in cyber protection providing an AI-powered integrated platform that unifies operations management, cybersecurity, and data protection.
What you will do
- Own and optimize the Elastic Security platform, including Elasticsearch, Kibana, Fleet, Logstash, and Elastic Agents.
- Design and maintain ingestion pipelines for cloud, endpoint, network, and application telemetry.
- Build and maintain a Detection-as-Code pipeline utilizing Git-based workflows and CI/CD automation.
- Develop and tune high-fidelity detections using EQL and KQL, mapping them to the MITRE ATT&CK framework.
- Serve as a Tier 2 escalation point for complex security events, performing initial scoping and containment.
- Collaborate with infrastructure and DevSecOps teams to enhance logging and overall visibility.
Requirements
- 5+ years of cybersecurity engineering experience.
- 3+ years of experience in SIEM engineering, detection engineering, or security analytics.
- Strong hands-on expertise with Elastic Security and the Elastic Stack.
- Experience implementing Detection-as-Code workflows via Git and CI/CD pipelines.
- Proficiency in Python and/or PowerShell scripting.
- Experience with AWS CloudTrail, VPC Flow Logs, and general TCP/IP and DNS attack patterns.
Nice to have
- SOAR playbook development and automated response workflows.
- Sigma rule development.
- Familiarity with the Elastic detection-rules ecosystem.
- Experience with Terraform or Ansible.
- Background in SOC or Incident Response.
Culture & Benefits
- Comprehensive medical, dental, and vision insurance.
- 401(k) retirement plan with company match.
- Flexible spending accounts (FSA).
- Disability and life insurance.
- Generous vacation policy.
- Innovative, high-growth environment focused on accountability and impact.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →