Skip to content

ELK Engineer

SISA Information Security Pvt LtdRemote (India)October 8, 2026
Remote
Full-time
SOC
Mid · 3–6 yrs

ELK Engineer – L2

Experience: 3–6 Years

Role Level: L2 / Mid-Level Engineer

Domain: ELK / SIEM / Log Management / Platform Engineering

Role Summary

We are looking for a hands-on ELK Engineer – L2 to manage, troubleshoot, optimize, and support Elasticsearch-based SIEM/log-management environments. The engineer will independently handle complex ELK issues, platform performance, log ingestion, cluster management, and production stability.

Key Responsibilities

  • Install, configure, administer, upgrade, and troubleshoot Elasticsearch, Logstash and ProAct environments.
  • Manage Elasticsearch clusters, nodes, indices, shards, replicas, mappings, templates and ILM policies.
  • Monitor and optimize JVM/heap, CPU, memory, disk utilization, indexing and search performance.
  • Troubleshoot cluster health, unassigned shards, disk watermark, indexing failures, mapping conflicts and performance degradation.
  • Develop, enhance and troubleshoot Logstash pipelines, Grok/Dissect patterns and ECS mappings.
  • Diagnose log loss, ingestion delays, parsing failures, pipeline-routing and data-quality issues.
  • Support ingestion through Elastic Agent/Filebeat, Syslog, APIs, Kafka and Redis.
  • Perform capacity planning and optimize storage, retention, shards, indices and pipeline throughput.
  • Manage backup, snapshot, restore and DR/recovery readiness.
  • Configure and troubleshoot Kibana dashboards, visualizations, data views and access-related issues.
  • Perform RCA for P1/P2 and recurring platform issues and drive permanent corrective actions.
  • Build scripts/automation for health checks, monitoring, deployment and repetitive operational activities.
  • Maintain SOPs, KEDB, troubleshooting guides and technical documentation.
  • Provide technical guidance and KT to L1 engineers and independently coordinate complex issues with Product/Engineering teams.

Required Technical Skills

Must Have: Elasticsearch, Logstash, Kibana, Linux, Grok/Regex, ECS, cluster management, shards/indices, ILM, JVM/heap, performance tuning and troubleshooting.

Good to Have: Elastic Agent/Filebeat, Kafka, Redis, Python/Shell scripting, REST APIs, Git, SQL, AWS/Azure/GCP, SIEM and cybersecurity fundamentals.

Expected L2 Competency

The candidate should independently manage and troubleshoot an end-to-end ELK environment, from log ingestion and parsing through Elasticsearch indexing, storage and visualization.

The engineer should be capable of handling production incidents, RCA, cluster optimization, capacity/performance issues and complex ingestion problems with minimal dependency on senior engineers.

Key Success Measures

  • ELK platform availability and stability
  • Reduced P1/P2 incidents and faster MTTR
  • Cluster and storage optimization
  • Minimal log loss and ingestion delay
  • Improved indexing and search performance
  • Reduction in recurring issues through RCA and automation
  • Quality of SOP/KEDB and knowledge transfer

Job Details

Experience

Mid · 3–6 yrs

Tools & Tech

AWS
Azure
Bash
ECS
Elasticsearch
GCP
Git
Kafka
Linux
Python
Redis
SQL