
Consulting Architect - Security (EMEA / Public Sector eligible)
Elastic
Consulting Architect - Security (EMEA / Public Sector eligible)
Elastic is seeking a Consulting Architect - Security to lead hands-on delivery of Elastic Security projects across EMEA, including public sector clients. The role involves designing and implementing SIEM, endpoint, and cloud security solutions, with up to 60% travel and remote-first work. Requires 5+ years in consulting or senior IT technical leadership, ideally in security, and eligibility for national security clearance.
Consulting Architect - Security (EMEA / Public Sector eligible)
Elastic is seeking a Consulting Architect - Security to lead hands-on delivery of Elastic Security projects across EMEA, including public sector clients. The role involves designing and implementing SIEM, endpoint, and cloud security solutions, with up to 60% travel and remote-first work. Requires 5+ years in consulting or senior IT technical leadership, ideally in security, and eligibility for national security clearance.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Analyse customer goals, pain points, existing architecture, and threat landscape, translating them into technical requirements
- Design Elastic Security solution architectures (SIEM, endpoint, cloud security) that integrate with the customer's wider security ecosystem
- Advise on the customer's security strategy and own the Elastic side of it, aligning recommendations through regular sessions with senior and key stakeholders
- Lead hands-on delivery of Elastic Security projects end-to-end, including greenfield deployments and migrations from legacy SIEM/EDR platforms in mission-critical environments
- Deploy and secure the Elastic platform: cluster architecture, RBAC and role mapping, single sign-on, private connectivity (private links, VPC peering), and hardening for enterprise and government environments
- Architect and build large-scale data ingestion with Elastic Agent, Beats, and Logstash, normalising data to ECS and integrating sources such as Kafka, Azure Event Hub, and AWS S3
- Develop security content aligned to the customer's threat landscape: detection rules, dashboards, and alerting workflows
- Drive security migrations from competing platforms, applying deep knowledge of Elastic's capabilities to translate each use case into its best form, whether through feature parity mapping or full redesign
- Establish detection-as-code practices for customers managing detections programmatically: developing, testing, versioning, and deploying detection content with Python, Git, and CI/CD pipelines
- Apply and enable Elastic's Agentic AI capabilities (AI Assistant, Attack Discovery, agent-driven workflows) to accelerate customers' detection and response
- Identify and deliver new security use cases as customers mature their cyber defence journey with Elastic
- Deliver engagements on time and within the agreed Statement of Work (SOW) scope, surfacing opportunities for follow-on work
- Communicate confidently with stakeholders from SOC engineers up to CISO / C-suite level
- Partner with Elastic Sales and pre-sales to assess technical risks and shape opportunities
- Feed field insight back to Elastic Engineering, Product Management, and Support to drive feature enhancements
- Mentor and share knowledge with fellow Elastic consultants across a highly distributed team
- Lead or assist with demos and proof-of-concepts that showcase the value of the Elastic Stack, and deliver enablement sessions and hands-on workshops that make customer teams self-sufficient