Experienced Security Data Platform Engineer
Job Description
[Up to c. £225k Comp Package | Office-Led Working - 3 Remote Days Per Month]
Role Overview
We’re representing a highly sophisticated quantitative research and technology organisation seeking a senior Security Data & Platform Engineer to become a technical authority for the data infrastructure underpinning its cyber-security function. The immediate focus is a major migration to Elastic Security, with responsibility for engineering and evolving the ingestion architecture, security telemetry and data pipelines supporting detection, investigation, threat hunting and incident response across a highly customised environment. This is not a conventional SIEM administration role: the successful engineer will combine deep Elastic and security-data expertise with broader platform engineering, working across technologies such as Kafka, Logstash and Beats while solving challenges around data quality, scale, reliability and performance. Longer term, the remit will expand into machine learning over security telemetry, PKI, digital-forensics tooling and other security platforms...
Key Responsibilities
- Act as a technical SME for Elastic Security and the wider security-data platform
- Engineer and maintain scalable ingestion pipelines across endpoint, network, cloud, SaaS and internally generated security telemetry
- Lead onboarding, normalisation, tuning and stabilisation of data feeds as the organisation migrates further onto Elastic Security
- Optimise Elasticsearch data models, indexing strategies, storage, query performance and overall platform reliability
- Build and operate data-pipeline capabilities using technologies such as Kafka, Logstash, Beats and related integration tooling
- Develop scripts, APIs and lightweight software capabilities to automate ingestion, validation, monitoring and platform operations
- Partner with SOC, CSIRT, Detection Engineering and infrastructure teams to ensure security telemetry remains accurate, usable and cost-effective
- Contribute to future initiatives across security-data machine learning, PKI, digital forensics and wider security-platform engineering
What You’ll Bring...
- Typically around 6-12 years of experience across security engineering, SIEM, logging platforms, data engineering or adjacent platform-engineering roles, including substantial ownership of complex production environments
- Deep hands-on expertise with Elasticsearch and the wider Elastic Stack, ideally including Elastic Security, Logstash, Beats or comparable security-data tooling
- Strong experience designing, operating and troubleshooting scalable log-ingestion or event-processing architectures, ideally involving Kafka or similar streaming technologies
- Strong understanding of data modelling, indexing, performance optimisation, data quality, retention and operational reliability within large-scale data platforms
- Experience working within complex, customised, hybrid or on-prem environments rather than exclusively standard SaaS or managed-cloud deployments
- Sufficient software-engineering and scripting ability, such as Python or Bash, to automate workflows, build integrations and work credibly alongside strong software engineers
- Experience owning Elastic Security, SIEM or security-telemetry platforms supporting Detection Engineering, CSIRT, SOC, threat hunting or digital-forensics teams
- (Preferred) Exposure to PKI, security-data machine learning, threat-intelligence platforms, digital-forensics tooling or wider security-platform engineering
...
Apply for this role
All fields marked with * are required.