Job name: Consulting Architect - Security (EMEA / Public Sector eligible )

Company: Elastic

Location: Germany    

Job description:
Elastic, the Search AI Company, enables
everyone to find the answers they need
in real time, using all their data, at
scale — unleashing the potential of
businesses and people. The Elastic
Search AI Platform, used by more than
50% of the Fortune 500, brings together
the precision of search and the
intelligence of AI to enable everyone to
accelerate the results that matter. By
taking advantage of all structured and
unstructured data — securing and
protecting private information more
effectively — Elastic’s complete,
cloud-based solutions for search,
security, and observability help
organizations deliver on the promise of
AI.What is The Role
Elastic Security is one of the
fastest-growing parts of our business,
and our customers (including government
and public sector organisations) rely on
our Security Solution to modernise their
SOC, threat detection, and response
capabilities.
You will lead the hands-on delivery of
Elastic Security projects (new
implementations, migrations, and
use-case expansions) from discovery
through architecture design and build.
Along the way, you'll develop
trusted relationships with senior
stakeholders and work closely with our
Services, Engineering and Sales teams.
Elastic is a remote-first company, but
many of the projects you'll deliver
might require onsite availability,
making the role hybrid in practice,
varying by project, with travel of up to
60%.Some of these engagements, given the
organisations involved, also require
national security screening or
clearance; eligibility to obtain one in
your country of employment is a strong
advantage, and Elastic will sponsor the
process where required.
What You Will Be Doing
Assess and Design

Analyse customer goals, pain points,
existing architecture, and threat
landscape, translating them into
technical requirements
Design Elastic Security solution
architectures (SIEM, endpoint, cloud
security) that integrate with the
customer's wider security ecosystem
Advise on the customer's security
strategy and own the Elastic side of it,
aligning recommendations through regular
sessions with senior and key
stakeholders

Implement and Deliver

Lead hands-on delivery of Elastic
Security projects end-to-end, including
greenfield deployments and migrations
from legacy SIEM/EDR platforms in
mission-critical environments
Deploy and secure the Elastic platform:
cluster architecture, RBAC and role
mapping, single sign-on, private
connectivity (private links, VPC
peering), and hardening for enterprise
and government environments
Architect and build large-scale data
ingestion with Elastic Agent, Beats, and
Logstash, normalising data to ECS and
integrating sources such as Kafka, Azure
Event Hub, and AWS S3
Develop security content aligned to the
customer's threat landscape:
detection rules, dashboards, and
alerting workflows
Drive security migrations from competing
platforms, applying deep knowledge of
Elastic's capabilities to translate
each use case into its best form,
whether through feature parity mapping
or full redesign
Establish detection-as-code practices
for customers managing detections
programmatically: developing, testing,
versioning, and deploying detection
content with Python, Git, and CI/CD
pipelines
Apply and enable Elastic's Agentic
AI capabilities (AI Assistant, Attack
Discovery, agent-driven workflows) to
accelerate customers' detection and
response

Grow and Collaborate

Identify and deliver new security use
cases as customers mature their cyber
defence journey with Elastic
Deliver engagements on time and within
the agreed Statement of Work (SOW)
scope, surfacing opportunities for
follow-on work
Communicate confidently with
stakeholders from SOC engineers up to
CISO / C-suite level
Partner with Elastic Sales and pre-sales
to assess technical risks and shape
opportunities
Feed field insight back to Elastic
Engineering, Product Management, and
Support to drive feature enhancements
Mentor and share knowledge with fellow
Elastic consultants across a highly
distributed team
Lead or assist with demos and
proof-of-concepts that showcase the
value of the Elastic Stack, and deliver
enablement sessions and hands-on
workshops that make customer teams
self-sufficient

What You Bring Along

Minimum of 5 years' experience as a
Consulting Architect, Senior Consultant,
or in a senior IT technical leadership
role, delivering and executing
professional services engagements,
ideally in the security domain
Solid experience deploying Elastic
Security or comparable SIEM platforms
(e.g., Splunk, MS Sentinel, QRadar,
ArcSight) and/or EDR platforms (e.g.,
CrowdStrike, MS Defender), or at least 2
years as a Security Analyst / Detection
Engineer in a threat detection and
response role
An architect's view of the security
ecosystem across varied customer
environments: SOAR, vulnerability
management, penetration testing,
ticketing, and security policies, and
how they connect in a SOC
Scripting skills, ideally in Python, and
exposure to modern delivery practices
such as Infrastructure-as-Code and CI/CD
are strongly preferred
Hands-on experience with Linux and
Windows operating systems, and on-prem
and/or public cloud platforms (AWS,
Azure, GCP)
Strong customer advocacy,
relationship-building, and communication
skills, with the ability to pivot easily
between delivery and strategic
engagements
Eligibility to obtain national security
clearance in your country of employment
(screening sponsored by Elastic where
required)
Willingness to travel and work onsite
with customers (up to 60% of the time),
combined with comfort working remotely
in a highly distributed team
Strong proficiency in both English (our
company-wide operating language) and the
local market language.

Bonus Points

Experience with advanced Elasticsearch
operations: cluster architecture, shard
management, data ingestion, and data
tiering at scale
Experience with detection-as-code:
authoring, testing, and versioning
detection content managed in Git
Experience automating deployments and
lifecycle management with Python,
Terraform, and CI/CD tooling (e.g.,
GitLab pipelines)
Experience deploying and operating
containerised workloads on Kubernetes,
cloud-managed or self-hosted (EKS, AKS,
GKE, OpenShift)
Experience with Agentic AI and LLM-based
security workflows: AI assistants,
automated triage, and agent-driven
investigation
Experience as a Tier-2/Tier-3 SOC
Analyst, Threat Hunter, or DevSecOps
Engineer
Experience in large distributed
environments or MSSPs, from architecture
through deployment
Experience delivering enablement
sessions, technical workshops, or
product training to technical audiences
Elastic Certified Engineer
certification, or security
certifications such as GIAC or CISSP

#LI-PF1Additional Information - We Take
Care of Our People
As a distributed company, diversity
drives our identity. Whether you’re
looking to launch a new career or grow
an existing one, Elastic is the type of
company where you can balance great work
with great life. Your age is only a
number. It doesn’t matter if you’re
just out of college or your children
are; we need you for what you can do.
We strive to have parity of benefits
across regions and while regulations
differ from place to place, we believe
taking care of our people is the right
thing to do.

Competitive pay based on the work you do
here and not your previous salary
Health coverage for you and your family
in many locations
Ability to craft your calendar with
flexible locations and schedules for
many roles
Generous number of vacation days each
year
Increase your impact - We match up to
$2000 (or local currency equivalent) for
financial donations and service
Up to 40 hours each year to use toward
volunteer projects you love
Embracing parenthood with minimum of 16
weeks of parental leave

Different people approach problems
differently. We need that. Elastic is an
equal opportunity employer and is
committed to creating an inclusive
culture that celebrates different
perspectives, experiences, and
backgrounds. Qualified applicants will
receive consideration for employment
without regard to race, ethnicity,
color, religion, sex, pregnancy, sexual
orientation, gender perception or
identity, national origin, age, marital
status, protected veteran status,
disability status, or any other basis
protected by federal, state or local
law, ordinance or regulation.
We welcome individuals with disabilities
and strive to create an accessible and
inclusive experience for all
individuals. To request an accommodation
during the application or the recruiting
process, please email
[email protected]. We
will reply to your request within 24
business hours of submission.
Applicants have rights under Federal
Employment Laws, view posters linked
below: Family and Medical Leave Act
(FMLA) Poster; Pay Transparency
Nondiscrimination Provision Poster;
Employee Polygraph Protection Act (EPPA)
Poster and Know Your Rights (Poster)
Elasticsearch develops and distributes
technology and information that is
subject to U.S. and other countries’
export controls and licensing
requirements for individuals who are
located in or are nationals of the
following sanctioned countries and
regions: Belarus, Cuba, Iran, North
Korea, Syria, or Russia, including the
Ukrainian territories annexed by Russia
(The Crimea region of Ukraine, The
Donetsk People's Republic (DNR), The
Luhansk People's Republic (LNR),
Kherson or Zaporizhzhia). If you are
located in or are a national of one of
the listed countries or regions, an
export license may be required as a
condition of your employment in this
role. Please note that national origin
and/or nationality do not affect
eligibility for employment with Elastic.
Please see here for our
Privacy Statement.



View Job & Apply
  Next =>
   


Horizon Career CopyRight Site Map Online Advertising Discussion Forum Press Release Recruiting and Executive Search Classified Ads Job Fairs Networking Advice and Resource Employers and Recruiters' Accounts Post Jobs Search Resumes Horizoncareer