Senior Security Engineer - Elastic SIEM and Detection Engineering
AcronisAbout the role
We’re looking for a Senior Security Engineer to lead our Elastic SIEM and Detection Engineering program. This is an engineering-first role focused on building scalable detection pipelines, improving telemetry quality, and developing high-confidence detections that help security teams move faster and respond more effectively.
You’ll own the evolution of our Elastic Security environment — from log ingestion and platform optimization to Detection-as-Code pipelines and detection coverage strategy. This role is ideal for someone who enjoys building systems, improving signal quality, automating workflows, and solving detection engineering problems at scale.
While the primary focus is engineering, you’ll also serve as a Tier 2 escalation point for complex security events, helping scope incidents, initiate containment when needed, and improve detections based on real-world activity.
This is a high-impact role with significant ownership and the opportunity to shape how detection engineering is implemented across the organization.
WHAT YOU'LL DO
Elastic SIEM & Platform Engineering:
Own and optimize the Elastic Security platform (Elasticsearch, Kibana, Fleet, Logstash, Elastic Agents)
Design and maintain ingestion pipelines for cloud, endpoint, network, and application telemetry
Improve telemetry quality, data retention, performance, and investigation workflows
Integrate SIEM workflows with SOAR and automation tooling
Detection Engineering & Detection-as-Code:
Build and maintain a Detection-as-Code pipeline using Git-based workflows and CI/CD automation
Develop, test, tune, and maintain high-fidelity detections using Elastic Security, EQL, and KQL
Reduce alert noise through tuning, enrichment, suppression, and exception handling
Map detections to MITRE ATT&CK and help drive detection coverage strategy
Track detection quality metrics including alert fidelity, false positive rates, and coverage gaps
Incident Response Support:
Assist with complex alert escalations and perform initial incident scoping
Execute initial containment actions when necessary (endpoint isolation, IP/domain blocking, account suspension)
Participate in a low-frequency on-call rotation for critical incidents
Translate incident learnings into improved detections and telemetry coverage
Collaboration & Automation:
Partner with infrastructure, DevSecOps, and cloud teams to improve logging and visibility
Build automation and tooling using Python and/or PowerShell
Support purple team exercises and adversary simulations
WHO WE'RE LOOKING FOR
5+ years of cybersecurity engineering experience
3+ years focused on SIEM engineering, detection engineering, or security analytics
Strong hands-on experience with Elastic Security and the Elastic Stack
Experience building or maintaining Detection-as-Code workflows using Git and CI/CD pipelines
Strong understanding of detection tuning, alert fidelity, and operational detection quality
Ability to independently investigate complex alerts and produce actionable findings
Technical Experience:
Elastic Security, Kibana, Fleet, Elastic Agents, EQL/KQL
Detection engineering and MITRE ATT&CK mapping
Jenkins, Bitbucket Pipelines, GitHub Actions, or similar CI/CD tooling
Python and/or PowerShell scripting
AWS CloudTrail, VPC Flow Logs, Azure Monitor, or similar telemetry sources
TCP/IP, DNS, HTTP/S, and common attack patterns
Threat intelligence enrichment and operationalization
Nice to Have:
SOAR playbook development and automated response workflows
Sigma rule development
Elastic detection-rules ecosystem familiarity
Terraform or Ansible experience
Previous SOC or Incident Response background
What Success Looks Like:
30 Days: Validate telemetry sources and establish initial detection coverage baseline
90 Days: Operational De
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s