Summary
ECI is a global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations. The Security Platform Engineer will build, operate, and improve Elastic-based security platforms, telemetry pipelines, and operational controls, while ensuring reliable data ingestion, quality, and platform performance. The role also partners with Automation Engineering and applies AI-assisted practices to improve security platform delivery and reliability.
Responsibilities
- Build and maintain Elastic platform services, data pipelines, and operational standards across security environments
- Own Logstash and ingestion pipeline lifecycle including onboarding, parsing, normalization, enrichment, and schema governance
- Maintain platform reliability through performance tuning, capacity planning, retention management, and upgrade planning
- Define and enforce data quality standards to ensure telemetry is complete, consistent, and usable for detection and response workflows
- Troubleshoot and resolve ingestion, indexing, search performance, and pipeline stability issues in production environments
- Own platform-side client lifecycle readiness including onboarding standards, technical validation, and production go-live criteria
- Build and maintain platform observability using metrics, logging, health checks, and operational runbooks
- Partner with Automation Engineering to provide stable data contracts and platform interfaces for detection and workflow delivery
- Collaborate in architecture and operational review practices to raise engineering standards across the function
- Explore and apply AI-assisted engineering practices to improve platform reliability, telemetry quality, operational documentation, and delivery efficiency
Skills
- Degree in Computer Science, Cyber Security, Engineering, Information Technology, or equivalent practical experience
- 3+ years supporting or engineering production SIEM, observability, or large-scale data platform environments
- Strong understanding of telemetry ingestion, parsing, normalization, enrichment, and schema management
- Experience troubleshooting distributed platform issues across ingestion, indexing, search, and data lifecycle
- Practical experience with platform lifecycle operations including upgrades, patching, configuration management, and performance tuning
- Experience working with REST APIs and integration patterns in operational environments
- Working knowledge of Linux administration in engineering environments
- Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP
- Foundational understanding of detection and incident response concepts within security operations
- Experience administering enterprise SIEM or security analytics platforms in production, especially Elastic Security
- Hands-on experience with Elastic Stack platform operations, including Elasticsearch, Logstash, and Kibana
- Familiarity with data retention strategy, index lifecycle management, and storage optimization in high-volume environments
- Experience with infrastructure as code and configuration tooling such as Terraform or Ansible
- Exposure to containerized deployment patterns with Docker or Kubernetes
- Familiarity with MITRE ATT&CK and how telemetry quality supports detection coverage
- Experience supporting managed client onboarding and multi-tenant security platform operations
- Experience developing operational tooling or scripts to improve platform reliability and consistency
Qualifications
Must Haves
- Degree in Computer Science, Cyber Security, Engineering, Information Technology, or equivalent practical experience
- 3+ years supporting or engineering production SIEM, observability, or large-scale data platform environments
- Strong understanding of telemetry ingestion, parsing, normalization, enrichment, and schema management
- Experience troubleshooting distributed platform issues across ingestion, indexing, search, and data lifecycle
- Practical experience with platform lifecycle operations including upgrades, patching, configuration management, and performance tuning
- Experience working with REST APIs and integration patterns in operational environments
- Working knowledge of Linux administration in engineering environments
- Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP
- Foundational understanding of detection and incident response concepts within security operations
Nice to Haves
- Experience administering enterprise SIEM or security analytics platforms in production, especially Elastic Security
- Hands-on experience with Elastic Stack platform operations, including Elasticsearch, Logstash, and Kibana
- Familiarity with data retention strategy, index lifecycle management, and storage optimization in high-volume environments
- Experience with infrastructure as code and configuration tooling such as Terraform or Ansible
- Exposure to containerized deployment patterns with Docker or Kubernetes
- Familiarity with MITRE ATT&CK and how telemetry quality supports detection coverage
- Experience supporting managed client onboarding and multi-tenant security platform operations
- Experience developing operational tooling or scripts to improve platform reliability and consistency