

Elastic Stack Consultant – Security & Observability (SIEM/APM/Kibana/Beats)
⭐ - Featured Role | Apply direct with Data Freelance Hub
This role is for an Elastic Stack Consultant – Security & Observability, offering a hybrid position in Birmingham & London, UK. The contract length is unspecified, with a pay rate also not disclosed. Key requirements include 5+ years in Elastic Stack, cybersecurity, and performance monitoring expertise.
🌎 - Country
United Kingdom
💱 - Currency
£ GBP
-
💰 - Day rate
-
🗓️ - Date discovered
July 3, 2025
🕒 - Project duration
Unknown
-
🏝️ - Location type
Hybrid
-
📄 - Contract type
Unknown
-
🔒 - Security clearance
Unknown
-
📍 - Location detailed
London Area, United Kingdom
-
🧠 - Skills detailed
#Jira #Scripting #Prometheus #Observability #Security #Cybersecurity #DevOps #Bash #Deployment #Normalization #Elastic Stack #Docker #Python #Java #.Net #Logstash #Monitoring #Elasticsearch #Kubernetes #ML (Machine Learning)
Role description
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Job Title: Elastic Stack Consultant – Security & Observability
Location: Birmingham & London, UK (Hybrid)
🔍 Job Overview:
We are seeking a highly skilled Elastic Stack Consultant – Security & Observability to architect, implement, and optimize end-to-end Elastic Stack deployments. This hybrid role combines Elastic SIEM for security detection and Elastic APM for performance monitoring. You will work closely with SOC teams, SREs, DevOps engineers, and security stakeholders to design detection rules, dashboards, alerting mechanisms, and pipeline integrations using the Elastic ecosystem.
🎯 Key Responsibilities:
🔐 Security (SIEM & Detection Engineering)
• Design and tune detection rules using EQL, Rule DSL, and Sigma mappings.
• Configure Elastic Security integrations with endpoint agents, EDR, and threat intel feeds.
• Conduct threat hunting and investigative queries across log, network, and endpoint data.
• Automate alert triage and enrichment using Ingest Pipelines and ML anomaly jobs.
• Integrate with ITSM tools (e.g., Jira, ServiceNow) and manage alert workflows.
📈 Observability (APM & Monitoring)
• Deploy and configure Elastic APM agents (.NET, Java, Python, Node.js).
• Build dashboards, service maps, flame graphs, and transaction monitoring views.
• Configure Metricbeat, Heartbeat, and Filebeat for uptime and health monitoring.
• Optimize ILM policies, shard sizing, and index rollover for scale and cost-efficiency.
• Integrate with observability tools like OpenTelemetry and Prometheus.
🛠️ Key Skills & Technologies:
• Elastic Stack (Elasticsearch, Kibana, Logstash, Beats, Elastic Agent)
• Detection & Response: EQL, DSL, MITRE ATT&CK, IOC/IOA analysis
• Observability: Elastic APM, Metrics, Logs, Distributed Tracing
• Dashboards: Kibana, Canvas, Lens
• Ingest Pipelines: Grok, Dissect, Script, CSV, GeoIP
• Logstash & Beats (Filebeat, Metricbeat, Auditbeat, Winlogbeat)
• Security Integration: STIX/TAXII, SIEM connectors
• Scripting: Python, Shell, Bash, Painless
• Container Platforms: Docker, Kubernetes (Nice to have)
• Tools: ServiceNow, Jira, Slack, PagerDuty
🤝 Ideal Candidate Will Have:
• Minimum 5 years of experience in Elastic Stack deployment and optimization.
• Experience in both cybersecurity (SIEM) and performance monitoring (APM).
• Strong understanding of ECS-compliant event mapping and normalization.
• Ability to collaborate across DevOps, Security, and Engineering teams.