Senior Elastic Engineer

Remote from
USA flag
USA
Salary, yearly, USD
120,000 - 160,000
Employment type
Full Time,
Job posted
Apply before
22 Jun 2026
Experience level
Senior
Views / Applies
10 / 3

About ECS

Partnering with leading organizations to deliver powerful solutions for a complex world.

Actively Hiring
Verified job posting
This job post has been manually reviewed for authenticity and compliance.

AI Summary

This Senior Elastic Engineer role at Everforth ECS Federal supports the VA in modernizing enterprise observability and cybersecurity. The position requires deep expertise in the Elastic Stack, including cluster architecture, Logstash pipelines, and security compliance. Candidates need 7+ years of experience and the ability to obtain a Tier 5 background investigation. The role offers a salary range of $120,000-$160,000 and involves mentoring junior engineers.

Job Complexity

Easy Hard
AI Insight The role demands extensive experience (7+ years), specialized Elastic Stack skills, federal security compliance knowledge, and the ability to obtain a high-level clearance, making it challenging.

Salary Analysis

Median
USD140,000
US Market
USD120,000 – USD170,000
AI Insight The offered salary range of $120,000-$160,000 is competitive for a senior Elastic Engineer role, aligning with the US market median of $140,000. The high end is slightly below market max due to federal sector constraints, but benefits and stability often compensate.

Key Skills

Elastic Stack Elasticsearch Logstash Kibana SIEM Cybersecurity Cloud Architecture Log Aggregation Data Analytics Federal Compliance

Dear Hiring Manager,

I am writing to express my strong interest in the Senior Elastic Engineer position at Everforth ECS Federal. With over 7 years of experience in enterprise logging and SIEM platforms, including extensive hands-on work with the Elastic Stack, I am confident in my ability to support the VA's observability modernization initiatives.

In my previous role, I architected highly available Elasticsearch clusters and optimized ingestion pipelines for high-volume data, ensuring compliance with federal security standards. I hold relevant certifications and have a proven track record of mentoring junior engineers and obtaining ATOs.

I am eager to bring my technical expertise and dedication to cybersecurity to this critical role supporting the VA. Thank you for considering my application.

Sincerely,
[Your Name]

Describe your experience architecting highly available Elasticsearch clusters. What considerations did you make for scalability and performance?
I have architected multi-node Elasticsearch clusters with cross-cluster replication and shard allocation awareness. For scalability, I used index lifecycle management to roll over indices and optimize shard sizes. Performance tuning involved adjusting refresh intervals, using routing, and monitoring cluster health with Elastic's monitoring tools.
How do you ensure compliance with federal security standards like VA Handbook 6500 when implementing Elastic Security features?
I implement RBAC with fine-grained permissions, enable TLS encryption for data in transit, and configure audit logging. I also use Elastic's security features to mask sensitive data and ensure that all configurations align with NIST SP 800-53 controls. Regular security reviews and automated compliance checks are part of my workflow.
Can you walk me through a time you optimized Logstash pipelines for high-volume data? What challenges did you face?
I optimized pipelines by using persistent queues to handle backpressure and filter workers to parallelize processing. Challenges included memory consumption and ensuring data integrity. I used grok and dissect filters for parsing, and employed conditional logic to route data efficiently. Monitoring with Logstash monitoring APIs helped identify bottlenecks.
How do you approach mentoring junior engineers while managing your own technical responsibilities?
I allocate time for pair programming and code reviews, focusing on knowledge transfer. I create documentation and conduct brown-bag sessions on best practices. By setting clear expectations and using agile methodologies, I ensure that mentoring does not impact project deadlines.
What experience do you have with cloud environments (AWS/Azure) and how do you integrate Elastic Stack with cloud services?
I have deployed Elasticsearch on AWS using EC2 instances with auto-scaling groups and on Azure using VMs. I integrated with cloud services like S3 for snapshots and Azure Blob Storage for backups. I also used cloud-native tools like AWS Lambda for serverless ingestion and Azure Event Hubs for log streaming.

Everforth ECS Federal is seeking a Senior Elastic Engineer to support enterprise observability modernization and migration initiatives within a federal healthcare environment supporting the U.S. Department of Veterans Affairs.

The Senior Elastic Engineer serves as a subject matter expert for the design, implementation, and optimization of the Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) in support of Department of Veterans Affairs (VA) enterprise networks and cybersecurity operations. This role is critical for establishing robust log aggregation, data analytics, and real-time dashboarding to enhance situational awareness, threat hunting capabilities, and overall cybersecurity posture across VA information systems. 

Required Skills: 

  • Must be a US citizen with ability to obtain and maintain a Tier 5 (T5) background investigation (Public Trust Level 5) 
  • Minimum 7 years of experience supporting enterprise logging, SIEM, observability, or cybersecurity engineering platforms 
  • Minimum 5 years of hands-on Elastic Stack engineering experience 
  • Develop and maintain Logstash pipelines and Beats configurations to efficiently route and process high-volume network, security, and application data 
  • Monitor cluster health and optimize indices, shards, and queries for maximum performance and cost-effectiveness 
  • Implement and maintain Elastic Security features (e.g., Role-Based Access Control, TLS encryption) ensuring compliance with VA Handbook 6500 and federal security standards 
  • Analyze operational impacts associated with cybersecurity events, system changes, and platform performance issues with the ability to apply cybersecurity and privacy principles to organizational requirements 
  • Develop and optimize ingestion pipelines, parsers, enrichment workflows, and telemetry normalization strategies 
  • Architect, engineer, and deploy highly available and scalable Elasticsearch clusters across VA enclaves and cloud environments. 
  • Troubleshoot ingestion failures, performance bottlenecks, and observability platform issues 
  • Support Authority to Operate (ATO), Risk Management Framework (RMF), compliance validation, and continuous monitoring activities 
  • Develop technical documentation, operational procedures, and knowledge transfer materials 
  • Provide Tier 3 troubleshooting and act as a technical mentor for junior engineers 

Salary Range: $120,000-160,000

General Description of Benefits

Qualifications

  • 7+ years of experience with a Bachelor’s degree in Cybersecurity, Engineering or Computer Science, and/or 10+ years of equivalent experience 
  • One or more related certifications preferred: 
  • Elastic Certified Engineer or Elastic Certified Observability Engineer 
  • AWS Certified Security or Microsoft Azure Security Engineer 
  • Security+ or CSSIP 
  • Equivalent cybersecurity or cloud certificates 

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

How to apply

Did you apply? Let us know, and we’ll help you track your application.

See a few more

Similar Software Engineering remote jobs

Job Search Safety Tips

Here are some tips to help you search and apply for jobs safely:
Watch out for suspicious jobs Don't apply for jobs that offer high pay for little work or offer to hire you without an interview. Read more ›
Check the employer's profile Make sure you're applying for a trustworthy job by visiting the employer's profile and learning more about them. Read more ›
Protect your information Don't share personal details like your bank account or government-issued ID on suspicious websites or messengers. Read more ›
Report jobs that feel unsafe If you see a job that seems misleading, inappropriate or discriminatory, report it for going against our policies and we'll review it.

Share this job

Jobicy+ Subscription

Jobicy

614 professionals pay to access exclusive and experimental features on Jobicy

Free

USD $0/month

For people just getting started

  • • Unlimited applies and searches
  • • Access on web and mobile apps
  • • Weekly job alerts
  • • Access to additional tools like Bookmarks, Applications, and more

Plus

USD $8/month

Everything in Free, and:

  • • Ad-free experience
  • • Daily job alerts
  • • Personal career consultant
  • • AI-powered job advice
  • • Featured & Pinned Resume
  • • Custom Resume URL
Go to account ›