A&M Technologies is seeking an experienced Elastic Defend Architect to join our partner's Managed Security Service Provider (MSSP) team. The ideal candidate will possess deep expertise in Elastic Defend, Elastic Security, and Elasticsearch, with strong experience designing and implementing scalable, resilient endpoint security architectures. This role combines the engineering rigor of Elasticsearch/observability management with the specialized focus of Elastic Security and EDR. You will work closely with cross-functional teams to build, optimize, and maintain high-performing Elastic Defend environments that support mission-critical cybersecurity operations.
Responsibilities
Architect, design, and deploy Elastic Defend across large and distributed enterprise environments.
Configure and manage Fleet Servers, agent enrollment workflows, endpoint security policies, and security integrations.
Design and maintain scalable Elasticsearch clusters supporting Elastic Security workloads.
Build and optimize ingestion pipelines for endpoint telemetry, audit logs, alerts, and other security-relevant data.
Improve Elastic Security performance through index management, ILM tuning, mapping optimization, and ingest pipeline enhancements.
Develop and maintain observability frameworks using Kibana and related tooling, ensuring complete visibility into cluster and EDR operations.
Implement and support logging, metrics, and tracing systems needed for real-time monitoring and detection.
Analyze and visualize datasets to support threat hunting, anomaly detection, and operational insights.