Security Platform Engineer (DevSecOps)
Position Summary
The Security Platform Engineer is part of ECI's Security Engineering team and focuses on building, operating, and improving the platform layer that powers security services at scale. This is a hands-on engineering role with strong emphasis on Elastic platform operations, telemetry pipeline reliability, and lifecycle management. You will design and maintain data ingestion patterns, platform standards, and operational controls that ensure security data is reliable, performant, and ready for detection and response use. As part of our modern engineering approach, this role uses AI-assisted workflows to improve delivery quality, reduce repetitive operational effort, and accelerate security outcomes across detection, response, and platform services.
You will work within the Platform function, where your focus is owning Elastic, Logstash, and core data pipeline operations across client environments. You will partner closely with Automation Engineering, which is accountable for detection-as-code workflows, SOAR orchestration, and automation delivery that runs on top of the platform. In practice, this means Platform owns data ingestion, parsing standards, schema quality, retention, and platform reliability, while Automation owns how workflows and detection logic are engineered, tested, deployed, and maintained.
Responsibilities
- Build and maintain Elastic platform services, data pipelines, and operational standards across security environments.
- Own Logstash and ingestion pipeline lifecycle including onboarding, parsing, normalization, enrichment, and schema governance.
- Maintain platform reliability through performance tuning, capacity planning, retention management, and upgrade planning.
- Define and enforce data quality standards to ensure telemetry is complete, consistent, and usable for detection and response workflows.
- Troubleshoot and resolve ingestion, indexing, search performance, and pipeline stability issues in production environments.
- Own platform-side client lifecycle readiness including onboarding standards, technical validation, and production go-live criteria.
- Build and maintain platform observability using metrics, logging, health checks, and operational runbooks.
- Partner with Automation Engineering to provide stable data contracts and platform interfaces for detection and workflow delivery.
- Collaborate in architecture and operational review practices to raise engineering standards across the function.
- Explore and apply AI-assisted engineering practices to improve platform reliability, telemetry quality, operational documentation, and delivery efficiency.
Requirements
- Degree in Computer Science, Cyber Security, Engineering, Information Technology, or equivalent practical experience.
- 3+ years supporting or engineering production SIEM, observability, or large-scale data platform environments.
- Strong understanding of telemetry ingestion, parsing, normalization, enrichment, and schema management.
- Experience troubleshooting distributed platform issues across ingestion, indexing, search, and data lifecycle.
- Practical experience with platform lifecycle operations including upgrades, patching, configuration management, and performance tuning.
- Experience working with REST APIs and integration patterns in operational environments.
- Working knowledge of Linux administration in engineering environments.
- Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP.
- Foundational understanding of detection and incident response concepts within security operations.
Preferred
- Experience administering enterprise SIEM or security analytics platforms in production, especially Elastic Security.
- Hands-on experience with Elastic Stack platform operations, including Elasticsearch, Logstash, and Kibana.
- Familiarity with data retention strategy, index lifecycle management, and storage optimization in high-volume environments.
- Experience with infrastructure as code and configuration tooling such as Terraform or Ansible.
- Exposure to containerized deployment patterns with Docker or Kubernetes.
- Familiarity with MITRE ATT&CK and how telemetry quality supports detection coverage.
- Experience supporting managed client onboarding and multi-tenant security platform operations.
- Experience developing operational tooling or scripts to improve platform reliability and consistency.
What Good Looks Like
- You keep the platform stable, performant, and dependable under real operational load.
- Data onboarding and pipeline changes are delivered consistently with clear validation and minimal production disruption.
- Telemetry quality is high, with clear standards and measurable improvements over time.
- Platform services are observable and maintainable through strong runbooks, metrics, and operational discipline.
- You raise team engineering standards through thoughtful design, documentation, and collaborative reviews.
- You use AI-assisted workflows in practical, controlled ways that improve platform reliability, operational consistency, and delivery speed.