Elastic builds the infrastructure that ingests, indexes, and analyzes security telemetry at scale. The Elastic Stack - Elasticsearch, Kibana, Beats, and Logstash - is the backbone of Elastic Security, a platform that ties detection, investigation, and response into a single workflow. Over half of the Fortune 500 run Elastic for threat hunting, endpoint protection, SIEM, and cloud security, meaning the attack surface your code defends is measured in petabytes and real-time event streams, not lab conditions.
The security engineering work spans detection rules and machine learning models for anomaly detection, endpoint agent development, cloud posture management, and the core search engine that makes it all queryable. Tooling touches YARA, Endpoint Detection and Response (EDR), SIEM, and increasingly AI-driven analytics layered on top of Elasticsearch. Engineers ship against an open-source codebase - Elastic's roots are in open source, and contributions flow upstream across the stack.
The team is distributed across 30+ countries with a culture built on transparent, collaborative development. If the job is building detection pipelines that surface adversary behavior in federated log data or hardening an endpoint agent running on millions of machines, the threat model is enterprise-scale and the domain is search-powered security analytics.






