Consulting Architect
Elastic
mid-level
Location
United Kingdom
Work Type
Onsite
Seniority
mid-level
Posted
September 2, 2026
Total Compensation
€155,000
Yearly Savings (Comfortable)
€44,000
Want to apply for this job?
Subscribe to access the application link and 15,000+ more jobs
Job Description
Who you are
- Minimum of 5 years' experience as a Consulting Architect, Senior Consultant, or in a senior IT technical leadership role, delivering and executing professional services engagements, ideally in the security domain
- Solid experience deploying Elastic Security or comparable SIEM platforms (e.g., Splunk, MS Sentinel, QRadar, ArcSight) and/or EDR platforms (e.g., CrowdStrike, MS Defender), or at least 2 years as a Security Analyst / Detection Engineer in a threat detection and response role
- An architect's view of the security ecosystem across varied customer environments: SOAR, vulnerability management, penetration testing, ticketing, and security policies, and how they connect in a SOC
- Scripting skills, ideally in Python, and exposure to modern delivery practices such as Infrastructure-as-Code and CI/CD are strongly preferred
- Hands-on experience with Linux and Windows operating systems, and on-prem and/or public cloud platforms (AWS, Azure, GCP)
- Strong customer advocacy, relationship-building, and communication skills, with the ability to pivot easily between delivery and strategic engagements
- Eligibility to obtain national security clearance in your country of employment (screening sponsored by Elastic where required)
- Willingness to travel and work onsite with customers (up to 60% of the time), combined with comfort working remotely in a highly distributed team
- Strong proficiency in both English (our company-wide operating language) and the local market language
- Experience with advanced Elasticsearch operations: cluster architecture, shard management, data ingestion, and data tiering at scale
- Experience with detection-as-code: authoring, testing, and versioning detection content managed in Git
- Experience automating deployments and lifecycle management with Python, Terraform, and CI/CD tooling (e.g., GitLab pipelines)
- Experience deploying and operating containerised workloads on Kubernetes, cloud-managed or self-hosted (EKS, AKS, GKE, OpenShift)
- Experience with Agentic AI and LLM-based security workflows: AI assistants, automated triage, and agent-driven investigation
- Experience as a Tier-2/Tier-3 SOC Analyst, Threat Hunter, or DevSecOps Engineer
- Experience in large distributed environments or MSSPs, from architecture through deployment
- Experience delivering enablement sessions, technical workshops, or product training to technical audiences
- Elastic Certified Engineer certification, or security certifications such as GIAC or CISSP
What the job involves
- Elastic Security is one of the fastest-growing parts of our business, and our customers (including government and public sector organisations) rely on our Security Solution to modernise their SOC, threat detection, and response capabilities
- You will lead the hands-on delivery of Elastic Security projects (new implementations, migrations, and use-case expansions) from discovery through architecture design and build. Along the way, you'll develop trusted relationships with senior stakeholders and work closely with our Services, Engineering and Sales teams
- Elastic is a remote-first company, but many of the projects you'll deliver might require onsite availability, making the role hybrid in practice, varying by project, with travel of up to 60%
- Some of these engagements, given the organisations involved, also require national security screening or clearance; eligibility to obtain one in your country of employment is a strong advantage, and Elastic will sponsor the process where required
- Analyse customer goals, pain points, existing architecture, and threat landscape, translating them into technical requirements
- Design Elastic Security solution architectures (SIEM, endpoint, cloud security) that integrate with the customer's wider security ecosystem
- Advise on the customer's security strategy and own the Elastic side of it, aligning recommendations through regular sessions with senior and key stakeholders
- Lead hands-on delivery of Elastic Security projects end-to-end, including greenfield deployments and migrations from legacy SIEM/EDR platforms in mission-critical environments
- Deploy and secure the Elastic platform: cluster architecture, RBAC and role mapping, single sign-on, private connectivity (private links, VPC peering), and hardening for enterprise and government environments
- Architect and build large-scale data ingestion with Elastic Agent, Beats, and Logstash, normalising data to ECS and integrating sources such as Kafka, Azure Event Hub, and AWS S3
- Develop security content aligned to the customer's threat landscape: detection rules, dashboards, and alerting workflows
- Drive security migrations from competing platforms, applying deep knowledge of Elastic's capabilities to translate each use case into its best form, whether through feature parity mapping or full redesign
- Establish detection-as-code practices for customers managing detections programmatically: developing, testing, versioning, and deploying detection content with Python, Git, and CI/CD pipelines
- Apply and enable Elastic's Agentic AI capabilities (AI Assistant, Attack Discovery, agent-driven workflows) to accelerate customers' detection and response
- Identify and deliver new security use cases as customers mature their cyber defence journey with Elastic
- Deliver engagements on time and within the agreed Statement of Work (SOW) scope, surfacing opportunities for follow-on work
- Communicate confidently with stakeholders from SOC engineers up to CISO / C-suite level
- Partner with Elastic Sales and pre-sales to assess technical risks and shape opportunities
- Feed field insight back to Elastic Engineering, Product Management, and Support to drive feature enhancements
- Mentor and share knowledge with fellow Elastic consultants across a highly distributed team
- Lead or assist with demos and proof-of-concepts that showcase the value of the Elastic Stack, and deliver enablement sessions and hands-on workshops that make customer teams self-sufficient
Benefits
- Toast to your health: Fully paid health coverage for you and your family, in many locations.
- Craft your calendar: Flexible location and schedule for most roles.
- Create space for you: Distributed by design workforce, plus generous number of vacation days each year.
- Embrace parenthood: Minimum of 16 weeks of parental leave, plus generous family formation benefits.
- Give back your time: 40 hours each year to use toward volunteering with organizations and causes you’re passionate about.
- Amplify your impact: Double your charitable giving — we match donations up to $1500 USD (or local currency equivalent).
More Jobs You Might Like
Helpful Resources
Salary & Savings Calculator
Compare salaries across European cities and calculate your potential savings. Understand cost of living and take-home pay for tech jobs in Europe.
Career Guides
Expert advice on landing high-paying tech jobs in Europe. Tips on interviews, salary negotiation, and career growth from The European Engineer.
Access 15,000+ High-Paying Tech Jobs
Get unlimited access to our full database of 15,000+ jobs with advanced filters, salary comparisons, and exclusive career guides from The European Engineer.