Elasticsearch Consultant
Location:
London, Greater London, South East, England
Salary:
Competitive
Job Type:
Contract
Date Posted:
3 minutes ago
Expiry Date:
05/11/2026
Job Ref:
BH-128992
Start Date:
21/09/2026
Contact:
Shakir Muhammad
Contact Email:
shakir.muhammad@xcede.com
Specialism:
DevOps
Elastic SIEM Engineer
We are seeking an experienced Elastic SIEM Engineer to design, implement and maintain security monitoring solutions using the Elastic Stack. The successful candidate will be responsible for developing scalable log-management and threat-detection capabilities across complex cloud and containerised environments.
Key Responsibilities
We are seeking an experienced Elastic SIEM Engineer to design, implement and maintain security monitoring solutions using the Elastic Stack. The successful candidate will be responsible for developing scalable log-management and threat-detection capabilities across complex cloud and containerised environments.
Key Responsibilities
- Design, deploy and support Elastic SIEM solutions using Elasticsearch, Logstash and Kibana.
- Build and maintain log-ingestion pipelines for infrastructure, applications, cloud platforms and security tools.
- Develop Kibana dashboards, alerts, detection rules and visualisations.
- Configure data parsing, enrichment, transformation and indexing within Logstash and Elasticsearch.
- Integrate Kafka to support reliable, high-volume event streaming and log ingestion.
- Deploy and operate Elastic components within Kubernetes environments.
- Automate infrastructure provisioning, configuration and deployment using Ansible and Argo CD.
- Build and maintain GitLab CI/CD pipelines.
- Develop scripts and automation tools to improve platform administration and operational efficiency.
- Monitor platform health, performance, availability and storage capacity.
- Troubleshoot ingestion failures, data-quality issues and performance bottlenecks.
- Implement security controls, access management, data-retention policies and platform hardening.
- Work closely with cybersecurity, infrastructure, cloud and DevOps teams.
- Produce technical documentation, operational procedures and support runbooks.
- Strong experience with the Elastic Stack:
- Elasticsearch
- Logstash
- Kibana
- Experience implementing or supporting Elastic Security/Elastic SIEM.
- Strong understanding of log management, security monitoring and SIEM principles.
- Experience creating dashboards, alerts and security detection rules.
- Knowledge of Elasticsearch clusters, indexing, mappings, lifecycle management and performance optimisation.
- Experience building and supporting Logstash pipelines.
- Hands-on experience with Ansible.
- Experience with Apache Kafka or similar event-streaming technologies.
- Strong Kubernetes knowledge, including deploying and troubleshooting containerised services.
- Experience with GitOps deployment practices using Argo CD.
- Experience creating and maintaining GitLab CI/CD pipelines.
- Scripting experience using Python, Bash or a comparable language.
- Good understanding of Linux environments, networking and security fundamentals.
- Strong troubleshooting, analytical and communication skills.
- Elastic certifications or relevant cybersecurity qualifications.
- Experience with Elastic Agent, Fleet, Beats and endpoint integrations.
- Knowledge of security frameworks such as MITRE ATT&CK.
- Experience developing threat-detection use cases and tuning SIEM alerts.
- Familiarity with cloud platforms such as AWS, Azure or Google Cloud.
- Experience working in enterprise, regulated or high-availability environments.
- Knowledge of Infrastructure as Code and DevSecOps practices.
APPLY FOR THIS JOB
For your job application, please fill in the form below.
Shakir Muhammad
Specialisms: Cloud, Cyber, Network Security & Operations, Networks