Skip to content

Consulting Architect

Elastic
mid-level
Location

United Kingdom

Work Type

Onsite

Seniority

mid-level

Posted

September 2, 2026


Total Compensation
€155,000
Yearly Savings (Comfortable)
€44,000
Want to apply for this job?

Subscribe to access the application link and 15,000+ more jobs

Job Description

Who you are

  • Minimum of 5 years' experience as a Consulting Architect, Senior Consultant, or in a senior IT technical leadership role, delivering and executing professional services engagements, ideally in the security domain
  • Solid experience deploying Elastic Security or comparable SIEM platforms (e.g., Splunk, MS Sentinel, QRadar, ArcSight) and/or EDR platforms (e.g., CrowdStrike, MS Defender), or at least 2 years as a Security Analyst / Detection Engineer in a threat detection and response role
  • An architect's view of the security ecosystem across varied customer environments: SOAR, vulnerability management, penetration testing, ticketing, and security policies, and how they connect in a SOC
  • Scripting skills, ideally in Python, and exposure to modern delivery practices such as Infrastructure-as-Code and CI/CD are strongly preferred
  • Hands-on experience with Linux and Windows operating systems, and on-prem and/or public cloud platforms (AWS, Azure, GCP)
  • Strong customer advocacy, relationship-building, and communication skills, with the ability to pivot easily between delivery and strategic engagements
  • Eligibility to obtain national security clearance in your country of employment (screening sponsored by Elastic where required)
  • Willingness to travel and work onsite with customers (up to 60% of the time), combined with comfort working remotely in a highly distributed team
  • Strong proficiency in both English (our company-wide operating language) and the local market language
  • Experience with advanced Elasticsearch operations: cluster architecture, shard management, data ingestion, and data tiering at scale
  • Experience with detection-as-code: authoring, testing, and versioning detection content managed in Git
  • Experience automating deployments and lifecycle management with Python, Terraform, and CI/CD tooling (e.g., GitLab pipelines)
  • Experience deploying and operating containerised workloads on Kubernetes, cloud-managed or self-hosted (EKS, AKS, GKE, OpenShift)
  • Experience with Agentic AI and LLM-based security workflows: AI assistants, automated triage, and agent-driven investigation
  • Experience as a Tier-2/Tier-3 SOC Analyst, Threat Hunter, or DevSecOps Engineer
  • Experience in large distributed environments or MSSPs, from architecture through deployment
  • Experience delivering enablement sessions, technical workshops, or product training to technical audiences
  • Elastic Certified Engineer certification, or security certifications such as GIAC or CISSP

What the job involves

  • Elastic Security is one of the fastest-growing parts of our business, and our customers (including government and public sector organisations) rely on our Security Solution to modernise their SOC, threat detection, and response capabilities
  • You will lead the hands-on delivery of Elastic Security projects (new implementations, migrations, and use-case expansions) from discovery through architecture design and build. Along the way, you'll develop trusted relationships with senior stakeholders and work closely with our Services, Engineering and Sales teams
  • Elastic is a remote-first company, but many of the projects you'll deliver might require onsite availability, making the role hybrid in practice, varying by project, with travel of up to 60%
  • Some of these engagements, given the organisations involved, also require national security screening or clearance; eligibility to obtain one in your country of employment is a strong advantage, and Elastic will sponsor the process where required
  • Analyse customer goals, pain points, existing architecture, and threat landscape, translating them into technical requirements
  • Design Elastic Security solution architectures (SIEM, endpoint, cloud security) that integrate with the customer's wider security ecosystem
  • Advise on the customer's security strategy and own the Elastic side of it, aligning recommendations through regular sessions with senior and key stakeholders
  • Lead hands-on delivery of Elastic Security projects end-to-end, including greenfield deployments and migrations from legacy SIEM/EDR platforms in mission-critical environments
  • Deploy and secure the Elastic platform: cluster architecture, RBAC and role mapping, single sign-on, private connectivity (private links, VPC peering), and hardening for enterprise and government environments
  • Architect and build large-scale data ingestion with Elastic Agent, Beats, and Logstash, normalising data to ECS and integrating sources such as Kafka, Azure Event Hub, and AWS S3
  • Develop security content aligned to the customer's threat landscape: detection rules, dashboards, and alerting workflows
  • Drive security migrations from competing platforms, applying deep knowledge of Elastic's capabilities to translate each use case into its best form, whether through feature parity mapping or full redesign
  • Establish detection-as-code practices for customers managing detections programmatically: developing, testing, versioning, and deploying detection content with Python, Git, and CI/CD pipelines
  • Apply and enable Elastic's Agentic AI capabilities (AI Assistant, Attack Discovery, agent-driven workflows) to accelerate customers' detection and response
  • Identify and deliver new security use cases as customers mature their cyber defence journey with Elastic
  • Deliver engagements on time and within the agreed Statement of Work (SOW) scope, surfacing opportunities for follow-on work
  • Communicate confidently with stakeholders from SOC engineers up to CISO / C-suite level
  • Partner with Elastic Sales and pre-sales to assess technical risks and shape opportunities
  • Feed field insight back to Elastic Engineering, Product Management, and Support to drive feature enhancements
  • Mentor and share knowledge with fellow Elastic consultants across a highly distributed team
  • Lead or assist with demos and proof-of-concepts that showcase the value of the Elastic Stack, and deliver enablement sessions and hands-on workshops that make customer teams self-sufficient

Benefits

  • Toast to your health: Fully paid health coverage for you and your family, in many locations.
  • Craft your calendar: Flexible location and schedule for most roles.
  • Create space for you: Distributed by design workforce, plus generous number of vacation days each year.
  • Embrace parenthood: Minimum of 16 weeks of parental leave, plus generous family formation benefits.
  • Give back your time: 40 hours each year to use toward volunteering with organizations and causes you’re passionate about.
  • Amplify your impact: Double your charitable giving — we match donations up to $1500 USD (or local currency equivalent).
More Jobs You Might Like
Principal Engineer, Hybrid Cloud Environment

Google

Zurich

Helpful Resources
Salary & Savings Calculator

Compare salaries across European cities and calculate your potential savings. Understand cost of living and take-home pay for tech jobs in Europe.

Career Guides

Expert advice on landing high-paying tech jobs in Europe. Tips on interviews, salary negotiation, and career growth from The European Engineer.

Access 15,000+ High-Paying Tech Jobs

Get unlimited access to our full database of 15,000+ jobs with advanced filters, salary comparisons, and exclusive career guides from The European Engineer.