ELK Engineer
ELK Engineer – L2
Experience: 3–6 Years
Role Level: L2 / Mid-Level Engineer
Domain: ELK / SIEM / Log Management / Platform Engineering
Role Summary
We are looking for a hands-on ELK Engineer – L2 to manage, troubleshoot, optimize, and support Elasticsearch-based SIEM/log-management environments. The engineer will independently handle complex ELK issues, platform performance, log ingestion, cluster management, and production stability.
Key Responsibilities
- Install, configure, administer, upgrade, and troubleshoot Elasticsearch, Logstash and ProAct environments.
- Manage Elasticsearch clusters, nodes, indices, shards, replicas, mappings, templates and ILM policies.
- Monitor and optimize JVM/heap, CPU, memory, disk utilization, indexing and search performance.
- Troubleshoot cluster health, unassigned shards, disk watermark, indexing failures, mapping conflicts and performance degradation.
- Develop, enhance and troubleshoot Logstash pipelines, Grok/Dissect patterns and ECS mappings.
- Diagnose log loss, ingestion delays, parsing failures, pipeline-routing and data-quality issues.
- Support ingestion through Elastic Agent/Filebeat, Syslog, APIs, Kafka and Redis.
- Perform capacity planning and optimize storage, retention, shards, indices and pipeline throughput.
- Manage backup, snapshot, restore and DR/recovery readiness.
- Configure and troubleshoot Kibana dashboards, visualizations, data views and access-related issues.
- Perform RCA for P1/P2 and recurring platform issues and drive permanent corrective actions.
- Build scripts/automation for health checks, monitoring, deployment and repetitive operational activities.
- Maintain SOPs, KEDB, troubleshooting guides and technical documentation.
- Provide technical guidance and KT to L1 engineers and independently coordinate complex issues with Product/Engineering teams.
Required Technical Skills
Must Have: Elasticsearch, Logstash, Kibana, Linux, Grok/Regex, ECS, cluster management, shards/indices, ILM, JVM/heap, performance tuning and troubleshooting.
Good to Have: Elastic Agent/Filebeat, Kafka, Redis, Python/Shell scripting, REST APIs, Git, SQL, AWS/Azure/GCP, SIEM and cybersecurity fundamentals.
Expected L2 Competency
The candidate should independently manage and troubleshoot an end-to-end ELK environment, from log ingestion and parsing through Elasticsearch indexing, storage and visualization.
The engineer should be capable of handling production incidents, RCA, cluster optimization, capacity/performance issues and complex ingestion problems with minimal dependency on senior engineers.
Key Success Measures
- ELK platform availability and stability
- Reduced P1/P2 incidents and faster MTTR
- Cluster and storage optimization
- Minimal log loss and ingestion delay
- Improved indexing and search performance
- Reduction in recurring issues through RCA and automation
- Quality of SOP/KEDB and knowledge transfer
Job Details
Experience
Mid · 3–6 yrs