远程工作雷达

咨询架构师 - 安全(欧洲、中东和非洲)

Consulting Architect - Security (EMEA)

开发工程限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡
公司Elastic
薪资未公开
工作地点Germany
地域资格限定地区(需当地身份)
时区要求日间重叠约 2 小时,需偶尔早起或晚睡
用工类型permanent
发布时间13 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 Germany 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:日间重叠约 2 小时,需偶尔早起或晚睡。

Elastic,搜索AI公司,让每个人都能实时使用所有数据找到所需答案,实现规模化——释放企业和个人的潜力。Elastic搜索AI平台被超过50%的财富500强企业使用,将搜索的精准性和AI的智能相结合,使每个人都能加速实现关键成果。通过利用所有结构化和非结构化数据——更有效地保障和保护隐私信息——Elastic基于云的完整搜索、安全和可观测性解决方案帮助组织实现AI的承诺。

### **职位职责**

Elastic Security是我们业务中增长最快的部门之一,我们的客户(包括政府和公共部门组织)依赖我们的安全解决方案来现代化他们的SOC、威胁检测和响应能力。

你将负责Elastic Security项目的实际交付(新部署、迁移和用例扩展),从发现到架构设计和构建。在此过程中,你会与高级利益相关者建立信任关系,并与我们的服务、工程和销售团队紧密合作。

Elastic是一家以远程办公为主的企业,但你将负责的许多项目可能需要现场支持,因此该职位在实践中是混合办公模式,根据项目不同而变化,最多可能有60%的出差时间。

由于涉及的一些项目方,也要求进行国家安全审查或许可;在你任职国家具备获得此类许可的资格是一个重要优势,Elastic将在需要时提供支持。

### **你将从事的工作**

#### **评估与设计**

- 分析客户目标、痛点、现有架构和威胁环境,将其转化为技术需求
- 设计Elastic Security解决方案架构(SIEM、端点、云安全),并与客户的整体安全生态系统集成
- 为客户提供安全策略建议,并负责Elastic方面的方案,通过定期与高级和关键利益相关者的会议对建议进行对齐

#### **实施与交付**

- 全程主导Elastic Security项目的实际交付,包括在关键任务环境中从传统SIEM/EDR平台的迁移和新建部署
- 部署并保护Elastic平台:集群架构、RBAC和角色映射、单点登录、私有连接(私有)

查看英文原文

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.

### **What is The Role**

Elastic Security is one of the fastest-growing parts of our business, and our customers (including government and public sector organisations) rely on our Security Solution to modernise their SOC, threat detection, and response capabilities.

You will lead the hands-on delivery of Elastic Security projects (new implementations, migrations, and use-case expansions) from discovery through architecture design and build. Along the way, you'll develop trusted relationships with senior stakeholders and work closely with our Services, Engineering and Sales teams.

Elastic is a remote-first company, but many of the projects you'll deliver might require onsite availability, making the role hybrid in practice, varying by project, with travel of up to 60%.

Some of these engagements, given the organisations involved, also require national security screening or clearance; eligibility to obtain one in your country of employment is a strong advantage, and Elastic will sponsor the process where required.

### **What You Will Be Doing**

#### **Assess and Design**

- Analyse customer goals, pain points, existing architecture, and threat landscape, translating them into technical requirements
- Design Elastic Security solution architectures (SIEM, endpoint, cloud security) that integrate with the customer's wider security ecosystem
- Advise on the customer's security strategy and own the Elastic side of it, aligning recommendations through regular sessions with senior and key stakeholders

#### **Implement and Deliver**

- Lead hands-on delivery of Elastic Security projects end-to-end, including greenfield deployments and migrations from legacy SIEM/EDR platforms in mission-critical environments
- Deploy and secure the Elastic platform: cluster architecture, RBAC and role mapping, single sign-on, private connectivity (private links, VPC peering), and hardening for enterprise and government environments
- Architect and build large-scale data ingestion with Elastic Agent, Beats, and Logstash, normalising data to ECS and integrating sources such as Kafka, Azure Event Hub, and AWS S3
- Develop security content aligned to the customer's threat landscape: detection rules, dashboards, and alerting workflows
- Drive security migrations from competing platforms, applying deep knowledge of Elastic's capabilities to translate each use case into its best form, whether through feature parity mapping or full redesign
- Establish detection-as-code practices for customers managing detections programmatically: developing, testing, versioning, and deploying detection content with Python, Git, and CI/CD pipelines
- Apply and enable Elastic's Agentic AI capabilities (AI Assistant, Attack Discovery, agent-driven workflows) to accelerate customers' detection and response

**Grow and Collaborate**

- Identify and deliver new security use cases as customers mature their cyber defence journey with Elastic
- Deliver engagements on time and within the agreed Statement of Work (SOW) scope, surfacing opportunities for follow-on work
- Communicate confidently with stakeholders from SOC engineers up to CISO / C-suite level
- Partner with Elastic Sales and pre-sales to assess technical risks and shape opportunities
- Feed field insight back to Elastic Engineering, Product Management, and Support to drive feature enhancements
- Mentor and share knowledge with fellow Elastic consultants across a highly distributed team
- Lead or assist with demos and proof-of-concepts that showcase the value of the Elastic Stack, and deliver enablement sessions and hands-on workshops that make customer teams self-sufficient

### **What You Bring Along**

- Minimum of 5 years' experience as a Consulting Architect, Senior Consultant, or in a senior IT technical leadership role, delivering and executing professional services engagements, ideally in the security domain
- Solid experience deploying Elastic Security or comparable SIEM platforms (e.g., Splunk, MS Sentinel, QRadar, ArcSight) and/or EDR platforms (e.g., CrowdStrike, MS Defender), or at least 2 years as a Security Analyst / Detection Engineer in a threat detection and response role
- An architect's view of the security ecosystem across varied customer environments: SOAR, vulnerability management, penetration testing, ticketing, and security policies, and how they connect in a SOC
- Scripting skills, ideally in Python, and exposure to modern delivery practices such as Infrastructure-as-Code and CI/CD are strongly preferred
- Hands-on experience with Linux and Windows operating systems, and on-prem and/or public cloud platforms (AWS, Azure, GCP)
- Strong customer advocacy, relationship-building, and communication skills, with the ability to pivot easily between delivery and strategic engagements
- Eligibility to obtain national security clearance in your country of employment (screening sponsored by Elastic where required)
- Willingness to travel and work onsite with customers (up to 60% of the time), combined with comfort working remotely in a highly distributed team
- Strong proficiency in both English (our company-wide operating language) and the local market language.

### **Bonus Points**

- Experience with advanced Elasticsearch operations: cluster architecture, shard management, data ingestion, and data tiering at scale
- Experience with detection-as-code: authoring, testing, and versioning detection content managed in Git
- Experience automating deployments and lifecycle management with Python, Terraform, and CI/CD tooling (e.g., GitLab pipelines)
- Experience deploying and operating containerised workloads on Kubernetes, cloud-managed or self-hosted (EKS, AKS, GKE, OpenShift)
- Experience with Agentic AI and LLM-based security workflows: AI assistants, automated triage, and agent-driven investigation
- Experience as a Tier-2/Tier-3 SOC Analyst, Threat Hunter, or DevSecOps Engineer
- Experience in large distributed environments or MSSPs, from architecture through deployment
- Experience delivering enablement sessions, technical workshops, or product training to technical audiences
- Elastic Certified Engineer certification, or security certifications such as GIAC or CISSP

#LI-PF1

### **Additional Information - We Take Care of Our People**

As a distributed company, diversity drives our identity. Whether you’re looking to launch a new career or grow an existing one, Elastic is the type of company where you can balance great work with great life. Your age is only a number. It doesn’t matter if you’re just out of college or your children are; we need you for what you can do.

We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.

- Competitive pay based on the work you do here and not your previous salary
- Health coverage for you and your family in many locations
- Ability to craft your calendar with flexible locations and schedules for many roles
- Generous number of vacation days each year
- Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
- Up to 40 hours each year to use toward volunteer projects you love
- Embracing parenthood with minimum of 16 weeks of parental leave

Different people approach problems differently. We need that. Elastic is an equal opportunity employer and is committed to creating an inclusive culture that celebrates different perspectives, experiences, and backgrounds. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.

We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email [candidate_accessibility@elastic.co](mailto:candidate_accessibility@elastic.co). We will reply to your request within 24 business hours of submission.

Applicants have rights under Federal Employment Laws, view posters linked below: [Family and Medical Leave Act (FMLA)](https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/fmlaen.pdf) Poster;[Pay Transparency Nondiscrimination Provision](https://www.dol.gov/sites/dolgov/files/ofccp/pdf/pay-transp_%20English_formattedESQA508c.pdf) Poster; [Employee Polygraph Protection Act (EPPA)](https://www.dol.gov/sites/dolgov/files/WHD/legacy/files/eppabw.pdf) Poster and [Know Your Rights](https://www.dol.gov/sites/dolgov/files/OFCCP/regs/compliance/posters/pdf/22-088_EEOC_KnowYourRights.pdf) (Poster)

Elasticsearch develops and distributes technology and information that is subject to U.S. and other countries’ export controls and licensing requirements for individuals who are located in or are nationals of the following sanctioned countries and regions: Belarus, Cuba, Iran, North Korea, Syria, or Russia, including the Ukrainian territories annexed by Russia (The Crimea region of Ukraine, The Donetsk People's Republic (DNR), The Luhansk People's Republic (LNR), Kherson or Zaporizhzhia). If you are located in or are a national of one of the listed countries or regions, an export license may be required as a condition of your employment in this role. Please note that national origin and/or nationality do not affect eligibility for employment with Elastic.

Please see [here](https://www.elastic.co/legal/applicant-privacy-statement) for our Privacy Statement.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级安全研究工程师,SONAR

ElasticSpain€67,000 - €106,000/年permanent5 天前
开发工程限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡

渠道代表

ElasticMexicopermanent6 天前
市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位