E
ECI
Posted 29 days agoVerified live 11h ago

Security Platform Engineer (DevSecOps)

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
1 H-1B approvalsDept. of Labor
Elastic StackLogstashTelemetry IngestionData Parsing and NormalizationSchema ManagementDistributed Systems TroubleshootingREST APIsLinux AdministrationCloud Platforms and ServicesIdentity and Access Management (IAM)Infrastructure as CodeTerraformAnsibleDockerKubernetesMITRE ATT&CK

About the company

Founded in 1995, ECI is the market leader in end-to-end technology solutions for the financial industry.

Visa sponsorship history

1 year sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
1H-1B approved
100%approval rate
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20251

Job description

Summary

ECI is a global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations. The Security Platform Engineer will build, operate, and improve Elastic-based security platforms, telemetry pipelines, and operational controls, while ensuring reliable data ingestion, quality, and platform performance. The role also partners with Automation Engineering and applies AI-assisted practices to improve security platform delivery and reliability.

Responsibilities

  • Build and maintain Elastic platform services, data pipelines, and operational standards across security environments
  • Own Logstash and ingestion pipeline lifecycle including onboarding, parsing, normalization, enrichment, and schema governance
  • Maintain platform reliability through performance tuning, capacity planning, retention management, and upgrade planning
  • Define and enforce data quality standards to ensure telemetry is complete, consistent, and usable for detection and response workflows
  • Troubleshoot and resolve ingestion, indexing, search performance, and pipeline stability issues in production environments
  • Own platform-side client lifecycle readiness including onboarding standards, technical validation, and production go-live criteria
  • Build and maintain platform observability using metrics, logging, health checks, and operational runbooks
  • Partner with Automation Engineering to provide stable data contracts and platform interfaces for detection and workflow delivery
  • Collaborate in architecture and operational review practices to raise engineering standards across the function
  • Explore and apply AI-assisted engineering practices to improve platform reliability, telemetry quality, operational documentation, and delivery efficiency

Skills

  • Degree in Computer Science, Cyber Security, Engineering, Information Technology, or equivalent practical experience
  • 3+ years supporting or engineering production SIEM, observability, or large-scale data platform environments
  • Strong understanding of telemetry ingestion, parsing, normalization, enrichment, and schema management
  • Experience troubleshooting distributed platform issues across ingestion, indexing, search, and data lifecycle
  • Practical experience with platform lifecycle operations including upgrades, patching, configuration management, and performance tuning
  • Experience working with REST APIs and integration patterns in operational environments
  • Working knowledge of Linux administration in engineering environments
  • Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP
  • Foundational understanding of detection and incident response concepts within security operations
  • Experience administering enterprise SIEM or security analytics platforms in production, especially Elastic Security
  • Hands-on experience with Elastic Stack platform operations, including Elasticsearch, Logstash, and Kibana
  • Familiarity with data retention strategy, index lifecycle management, and storage optimization in high-volume environments
  • Experience with infrastructure as code and configuration tooling such as Terraform or Ansible
  • Exposure to containerized deployment patterns with Docker or Kubernetes
  • Familiarity with MITRE ATT&CK and how telemetry quality supports detection coverage
  • Experience supporting managed client onboarding and multi-tenant security platform operations
  • Experience developing operational tooling or scripts to improve platform reliability and consistency

Qualifications

Must Haves

  • Degree in Computer Science, Cyber Security, Engineering, Information Technology, or equivalent practical experience
  • 3+ years supporting or engineering production SIEM, observability, or large-scale data platform environments
  • Strong understanding of telemetry ingestion, parsing, normalization, enrichment, and schema management
  • Experience troubleshooting distributed platform issues across ingestion, indexing, search, and data lifecycle
  • Practical experience with platform lifecycle operations including upgrades, patching, configuration management, and performance tuning
  • Experience working with REST APIs and integration patterns in operational environments
  • Working knowledge of Linux administration in engineering environments
  • Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP
  • Foundational understanding of detection and incident response concepts within security operations

Nice to Haves

  • Experience administering enterprise SIEM or security analytics platforms in production, especially Elastic Security
  • Hands-on experience with Elastic Stack platform operations, including Elasticsearch, Logstash, and Kibana
  • Familiarity with data retention strategy, index lifecycle management, and storage optimization in high-volume environments
  • Experience with infrastructure as code and configuration tooling such as Terraform or Ansible
  • Exposure to containerized deployment patterns with Docker or Kubernetes
  • Familiarity with MITRE ATT&CK and how telemetry quality supports detection coverage
  • Experience supporting managed client onboarding and multi-tenant security platform operations
  • Experience developing operational tooling or scripts to improve platform reliability and consistency

More jobs like this