CyberMaxx prevents, detects, and responds to cyberattacks so organizations can have peace of mind.
Senior Elastic Engineer
Location
Maryland
Posted
5 days ago
Salary
0
Seniority
Senior
Job Description
Senior Elastic Engineer
CyberMaxx
• Architect and own the Elastic Stack (Elasticsearch, Logstash, Beats/Elastic Agent, Kibana) supporting high-volume security telemetry ingestion, detection, and search. • Direct implementation experience with ECK is required. • Design data models, index lifecycle management (ILM) strategies, sharding, and hot-warm-cold tiering for petabyte-scale, multi-tenant security data. • Build and harden ingestion pipelines from EDR, network, cloud, and log sources into the Elastic Stack, in partnership with detection engineering. • Tune cluster performance — query latency, indexing throughput, resource allocation — and drive capacity planning for growth. • Own Elastic Stack security, upgrades, and reliability, including runbooks, monitoring, and incident response for the platform itself. • Evaluate and roll out new Elastic capabilities (e.g., Elastic Security, ES|QL, machine learning jobs) that improve detection speed and analyst experience. • Set technical direction for and mentor a small team of Elastic engineers, establishing standards, review practices, and on-call structure for the platform. • Document architecture decisions, standards, and best practices, and represent the Elastic platform in cross-functional planning and vendor (Elastic) conversations.
Job Requirements
- 7+ years in search/data engineering or infrastructure roles, with 6+ years of hands-on Elasticsearch/Elastic Stack architecture experience.
- Deep expertise in Elasticsearch internals: sharding, replication, ILM, mapping/index design, query DSL and/or ES|QL, and cluster performance tuning at scale.
- Experience building ingestion pipelines with Logstash, Beats, or Elastic Agent, ideally with security/log data (SIEM, EDR, cloud logs).
- Comfort operating Elastic in private and public cloud environments (AWS/Azure) and with containerization (Docker/Kubernetes) and infrastructure-as-code.
- Working knowledge of security operations concepts (detections, alerting, SIEM workflows) is a strong plus
- Scripting/programming ability (Python, Go, or similar) for automation and tooling.
- Elastic Certified Engineer certification is a plus, not required.
Benefits
- Flexible Paid Time Off
- 401k with a company match
- Medical, Dental and Vision Coverage
- Voluntary Short Term and Long-Term Disability
- Employee Assistance Program with Mental Health Supplement
- Voluntary Basic, Accidental, and other ancillary life insurance
- Health Savings Account Contribution (with selection of a HDHP)
- 10 annual, paid holidays
Related Guides
Related Job Pages
More Full-stack Engineer Jobs
• Own features end-to-end across the complete software development lifecycle including AI, spanning requirements gathering, technical design, implementation, testing, automation, deployment, and ongoing operational ownership in production • Translate customer and business needs into clear technical solutions, making thoughtful trade-offs that balance speed, quality, and reliability • Design, build, and maintain highly scalable, distributed systems that handle large volumes of data • Identify and resolve pre-production bottlenecks and production issues, improving system resilience and performance • Participate in design and code reviews, contributing to shared engineering standards and long-term system health • Partner closely with product managers, SREs, and multi-functional teams to deliver meaningful customer outcomes • Participate in a rotating on-call schedule, diagnosing and resolving production issues to ensure reliability and customer trust
Senior Purple Team Engineer
KOHOA quickly scaling Fintech that helps Canadians gain control over their money with a no-fee spending and savings account.
• Own and lead incident response readiness across KOHO. • Plan and execute adversarial simulations: scope engagements, operate within defined rules of engagement, conduct offensive operations, and deliver findings that drive measurable security improvements. • Expand incident response readiness across KOHO and build response playbooks for marketing, data, legal, people & culture, risk, etc. • Conduct table top exercises with c-level to test risk acceptance and limitations. • Document lessons learned, operational improvements, and playbook updates. Execute all improvements. • Lead incident response/DFIR during a cybersecurity incident. • Conduct post incident documentation to determine contributing factors and lessons learned. • Design and deploy internal deception assets to detect lateral movement, insider threats, and unauthorized access across KOHO's environment. • Build external-facing deception capabilities, including fake credentials, canary tokens embedded in customer-facing surfaces, and decoy infrastructure seeded in breach databases and other attacker-accessible surfaces. • Instrument deception assets to generate actionable threat intelligence and feed findings back into detection logic, playbooks, and the broader threat model. • Build the triage and response workflow for deception-triggered alerts into existing SOC operations, from signal to investigation to lessons learned.
Software Developer
TuesdayTuesday, a SaaS technology platform, is democratizing philanthropy to fuel nonprofit capacity.
• Build Blazor WASM components with clean, reusable patterns and accessibility in mind • Implement Minimal API endpoints in .NET with OpenAPI, validation, and performance in focus • Contribute to our MAUI mobile app, including shared component libraries • Work with EF Core and SQL (Postgres); define/maintain database relationships and manage code-first EF Core migrations • Support real time UI behavior using SignalR where needed • Leverage Claude Enterprise to generate, refactor, and maintain test scripts efficiently, and help define best practices for AI-assisted testing on the team • Integrate authentication/authorization via Microsoft Entra ID (OIDC/OAuth2, MSAL, roles/scopes) • Ship via Azure DevOps (repos, pipelines, environments), following branch policies and PR reviews • Improve code quality through SonarCloud rules aligned with our standards • Generate and consume API clients from OpenAPI/Swagger for typesafe integration • Instrument services with distributed tracing and logging using Azure Application Insights • Help monitor service health, failure rates, and performance; participate in alert triage for staging/production • Work in three-week sprints with Product to refine user stories and acceptance criteria
Role Description Wir suchen einen echten Fullstack Entwickler (m/w/d), der sowohl im Backend als auch im Frontend zu Hause ist und unsere E-Commerce-Plattform technisch weiterentwickelt. Bei uns arbeitest du nicht nur „ein bisschen Frontend“ oder „nur API“, sondern entwickelst Features End-to-End – vom Datenmodell über die Geschäftslogik bis zur Angular-Komponente im Shop. Qualifications - Mindestens 3 Jahre Erfahrung in der Entwicklung von Web- oder E-Commerce-Anwendungen - Du fühlst dich sowohl im Backend als auch im Frontend wohl und kannst ein Feature eigenständig technisch durchdenken und umsetzen - Sehr gute Kenntnisse in Java (Spring Boot, Hibernate) - Kenntnisse in C# / .NET (z. B. ASP.NET Core, Entity Framework Core) von Vorteil - Erfahrung mit Angular (aktuelle Version), TypeScript, HTML und CSS (Less) - Sicherer Umgang mit SQL, Datenbankstrukturen und Datenmodellierung - Erfahrung mit GraphQL oder REST-Schnittstellen - Verständnis für Authentifizierungs- und Autorisierungskonzepte (z. B. OIDC, Keycloak) - Erfahrung in agilen Arbeitsweisen (z. B. Kanban mit Scrum-Elementen) - Erfahrung in der Zusammenarbeit mit verschiedenen Stakeholdern/Abteilungen - Deutschkenntnisse auf mindestens C1-Niveau Requirements - Nice to have Kenntnisse im Bereich CI/CD (Jenkins) - Erfahrung mit Docker und Kubernetes - Erfahrung mit Selenium (UI-/Webtests) - Erfahrung im E-Commerce-Umfeld Benefits - 30 Tage Urlaub - Urlaubs- und Weihnachtsgeld - Vermögenswirksame Leistungen - Betriebliche Altersvorsorge und Berufsunfähigkeitsvorsorge - Jobrad - EGYM-Wellpass: Firmenfitness mit Arbeitgeberzuschuss - FINN-Jobauto - Gleitzeitkonto - Möglichkeit zur persönlichen und fachlichen Weiterentwicklung - Sicherer Arbeitsplatz in einem zukunftsorientierten Unternehmen - Full Remote (wenn gewünscht)



