Skip to content
← Back to job listings

Consulting Architect (Security. EMEA / Public Sector Eligible)

Elastic · Berlin, Germany

RemoteImported listingfull-time6 days ago

About The Role

Join Elastic, a remote-first company, as a Consulting Architect specializing in security. In this role, you will lead the hands-on delivery of Elastic Security projects, develop trusted relationships with senior stakeholders, and work closely with our Services, Engineering, and Sales teams. You will analyze customer goals and pain points, design Elastic Security solution architectures, advise on the customer's security strategy, and lead the end-to-end delivery of Elastic Security projects. This position requires travel of up to 60% and eligibility for national security clearance.

  • Lead the hands-on delivery of Elastic Security projects, including new implementations, migrations, and use-case expansions.
  • Design Elastic Security solution architectures that integrate with the customer's wider security ecosystem and advise on the customer's security strategy.
  • Establish detection-as-code practices for customers managing detections programmatically and drive security migrations from competing platforms.
  • Scripting skills, ideally in Python, and exposure to modern delivery practices such as Infrastructure-as-Code and CI/CD are strongly preferred
  • Willingness to travel and work onsite with customers (up to 60% of the time), combined with comfort working remotely in a highly distributed team
  • Strong customer advocacy, relationship-building, and communication skills, with the ability to pivot easily between delivery and strategic engagements
  • Eligibility to obtain national security clearance in your country of employment (screening sponsored by Elastic where required)
  • An architect's view of the security ecosystem across varied customer environments: SOAR, vulnerability management, penetration testing, ticketing, and security policies, and how they connect in a SOC
  • Hands-on experience with Linux and Windows operating systems, and on-prem and/or public cloud platforms (AWS, Azure, GCP)
  • Minimum of 5 years' experience as a Consulting Architect, Senior Consultant, or in a senior IT technical leadership role, delivering and executing professional services engagements, ideally in the security domain
  • Solid experience deploying Elastic Security or comparable SIEM platforms (e.g., Splunk, MS Sentinel, QRadar, ArcSight) and/or EDR platforms (e.g., CrowdStrike, MS Defender), or at least 2 years as a Security Analyst / Detection Engineer in a threat detection and response role
  • Strong proficiency in both English (our company-wide operating language) and the local market language
  • Experience with advanced Elasticsearch operations: cluster architecture, shard management, data ingestion, and data tiering at scale
  • Experience with detection-as-code: authoring, testing, and versioning detection content managed in Git
  • Experience automating deployments and lifecycle management with Python, Terraform, and CI/CD tooling (e.g., GitLab pipelines)
  • Experience deploying and operating containerised workloads on Kubernetes, cloud-managed or self-hosted (EKS, AKS, GKE, OpenShift)
  • Experience as a Tier-2/Tier-3 SOC Analyst, Threat Hunter, or DevSecOps Engineer
  • Experience with Agentic AI and LLM-based security workflows: AI assistants, automated triage, and agent-driven investigation
  • Experience in large distributed environments or MSSPs, from architecture through deployment
  • Elastic Certified Engineer certification, or security certifications such as GIAC or CISSP
  • Experience delivering enablement sessions, technical workshops, or product training to technical audiences

This is an external listing. JobSpring does not represent or verify the employer. Report this listing