09 Oct
|
SISA Information Security
|
Bengaluru
09 Oct
SISA Information Security
Bengaluru
We are looking for a hands-on ELK Engineer - L2 to manage, troubleshoot, optimize, and support Elasticsearch-based SIEM/log-management environments. The engineer will independently handle complex ELK issues, platform performance, log ingestion, cluster management, and production stability.
Key Responsibilities
- Install, configure, administer, upgrade, and troubleshoot Elasticsearch, Logstash and ProAct environments.
- Manage Elasticsearch clusters, nodes, indices, shards, replicas, mappings, templates and ILM policies .
- Monitor and optimize JVM/heap, CPU, memory, disk utilization, indexing and search performance .
- Troubleshoot cluster health, unassigned shards, disk watermark, indexing failures, mapping conflicts and performance degradation.
- Develop, enhance and troubleshoot Logstash pipelines, Grok/Dissect patterns and ECS mappings .
- Diagnose log loss, ingestion delays, parsing failures, pipeline-routing and data-quality issues .
- Support ingestion through Elastic Agent/Filebeat, Syslog, APIs, Kafka and Redis .
- Perform capacity planning and optimize storage, retention, shards, indices and pipeline throughput .
- Manage backup, snapshot, restore and DR/recovery readiness .
- Configure and troubleshoot Kibana dashboards, visualizations, data views and access-related issues.
- Perform RCA for P1/P2 and recurring platform issues and drive permanent corrective actions.
- Build scripts/automation for health checks, monitoring, deployment and repetitive operational activities.
- Maintain SOPs, KEDB,
troubleshooting guides and technical documentation .
- Provide technical guidance and KT to L1 engineers and independently coordinate complex issues with Product/Engineering teams.
Required Technical Skills
Must Have: Elasticsearch, Logstash, Kibana, Linux, Grok/Regex, ECS, cluster management, shards/indices, ILM, JVM/heap, performance tuning and troubleshooting.
Good to Have: Elastic Agent/Filebeat, Kafka, Redis, Python/Shell scripting, REST APIs, Git, SQL, AWS/Azure/GCP, SIEM and cybersecurity fundamentals.
Expected L2 Competency
The candidate should independently manage and troubleshoot an end-to-end ELK setting , from log ingestion and parsing through Elasticsearch indexing, storage and visualization.
The engineer should be capable of handling production incidents, RCA, cluster optimization, capacity/performance issues and complex ingestion problems with minimal dependency on senior engineers.
Key Success Measures
- ELK platform availability and stability
- Reduced P1/P2 incidents and faster MTTR
- Cluster and storage optimization
- Minimal log loss and ingestion delay
- Improved indexing and search performance
- Reduction in recurring issues through RCA and automation
- Quality of SOP/KEDB and knowledge transfer
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 ELK Engineer (Bengaluru)
🏢 SISA Information Security
📍 Bengaluru