ELK Engineer

SISA Information Security Pvt LtdOn-siteFull-timeJunior, 1–2 yearsListed 2 hours ago

Apply now

About this role

# ELK Engineer – L2
Experience: 3–6 Years Role Level: L2 / Mid-Level Engineer Domain: ELK / SIEM / Log Management / Platform Engineering
### Role Summary
We are looking for a hands-on ELK Engineer – L2 to manage, troubleshoot, optimize, and support Elasticsearch-based SIEM/log-management environments. The engineer will independently handle complex ELK issues, platform performance, log ingestion, cluster management, and production stability.
### Key Responsibilities

- Install, configure, administer, upgrade, and troubleshoot Elasticsearch, Logstash and ProAct environments.
- Manage Elasticsearch clusters, nodes, indices, shards, replicas, mappings, templates and ILM policies .
- Monitor and optimize JVM/heap, CPU, memory, disk utilization, indexing and search performance .
- Troubleshoot cluster health, unassigned shards, disk watermark, indexing failures, mapping conflicts and performance degradation.
- Develop, enhance and troubleshoot Logstash pipelines, Grok/Dissect patterns and ECS mappings .
- Diagnose log loss, ingestion delays, parsing failures, pipeline-routing and data-quality issues .
- Support ingestion through Elastic Agent/Filebeat, Syslog, APIs, Kafka and Redis .
- Perform capacity planning and optimize storage, retention, shards, indices and pipeline throughput .
- Manage backup, snapshot, restore and DR/recovery readiness .
- Configure and troubleshoot Kibana dashboards, visualizations, data views and access-related issues.
- Perform RCA for P1/P2 and recurring platform issues and drive permanent corrective actions.
- Build scripts/automation for health checks, monitoring, deployment and repetitive operational activities.
- Maintain SOPs, KEDB, troubleshooting guides and technical documentation .
- Provide technical guidance and KT to L1 engineers and independently coordinate complex issues with Product/Engineering teams.

### Required Technical Skills
Must Have: Elasticsearch, Logstash, Kibana, Linux, Grok/Regex, ECS, cluster management, shards/indices, ILM, JVM/heap, performance tuning and troubleshooting. Good to Have: Elastic Agent/Filebeat, Kafka, Redis, Python/Shell scripting, REST APIs, Git, SQL, AWS/Azure/GCP, SIEM and cybersecurity fundamentals.
### Expected L2 Competency
The candidate should independently manage and troubleshoot an end-to-end ELK environment , from log ingestion and parsing through Elasticsearch indexing, storage and visualization. The engineer should be capable of handling production incidents, RCA, cluster optimization, capacity/performance issues and complex ingestion problems with minimal dependency on senior engineers.
### Key Success Measures

- ELK platform availability and stability
- Reduced P1/P2 incidents and faster MTTR
- Cluster and storage optimization
- Minimal log loss and ingestion delay
- Improved indexing and search performance
- Reduction in recurring issues through RCA and automation
- Quality of SOP/KEDB and knowledge transfer