Skip to content

Open nowPosted 44 days ago

Security Platform Engineer (DevSecOps)

ECI63 open roles

Where
Dallas, TX, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Platform Engineer (DevSecOps)ECI · Dallas, TX, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on ECI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 44 days ago

The posting

Security Platform Engineer (DevSecOps) Position Summary The Security Platform Engineer is part of ECI's Security Engineering team and focuses on building, operating, and improving the platform layer that powers security services at scale. This is a hands-on engineering role with strong emphasis on Elastic platform operations, telemetry pipeline reliability, and lifecycle management. You will design and maintain data ingestion patterns, platform standards, and operational controls that ensure security data is reliable, performant, and ready for detection and response use. As part of our modern engineering approach, this role uses AI-assisted workflows to improve delivery quality, reduce repetitive operational effort, and accelerate security outcomes across detection, response, and platform services. You will work within the Platform function, where your focus is owning Elastic, Logstash, and core data pipeline operations across client environments. You will partner closely with Automation Engineering, which is accountable for detection-as-code workflows, SOAR orchestration, and automation delivery that runs on top of the platform. In practice, this means Platform owns data ingestion, parsing standards, schema quality, retention, and platform reliability, while Automation owns how workflows and detection logic are engineered, tested, deployed, and maintained.

Responsibilities

Build and maintain Elastic platform services, data pipelines, and operational standards across security environments. Own Logstash and ingestion pipeline lifecycle including onboarding, parsing, normalization, enrichment, and schema governance. Maintain platform reliability through performance tuning, capacity planning, retention management, and upgrade planning. Define and enforce data quality standards to ensure telemetry is complete, consistent, and usable for detection and response workflows. Troubleshoot and resolve ingestion, indexing, search performance, and pipeline stability issues in production environments. Own platform-side client lifecycle readiness including onboarding standards, technical validation, and production go-live criteria. Build and maintain platform observability using metrics, logging, health checks, and operational runbooks. Partner with Automation Engineering to provide stable data contracts and platform interfaces for detection and workflow delivery. Collaborate in architecture and operational review practices to raise engineering standards across the function. Explore and apply AI-assisted engineering practices to improve platform reliability, telemetry quality, operational documentation, and delivery efficiency.

Requirements

Degree in Computer Science, Cyber Security, Engineering, Information Technology, or equivalent practical experience. 3+ years supporting or engineering production SIEM, observability, or large-scale data platform environments. Strong understanding of telemetry ingestion, parsing, normalization, enrichment, and schema management. Experience troubleshooting distributed platform issues across ingestion, indexing, search, and data lifecycle. Practical experience with platform lifecycle operations including upgrades, patching, configuration management, and performance tuning. Experience working with REST APIs and integration patterns in operational environments. Working knowledge of Linux administration in engineering environments. Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP. Foundational understanding of detection and incident response concepts within security operations.

Preferred

Experience administering enterprise SIEM or security analytics platforms in production, especially Elastic Security. Hands-on experience with Elastic Stack platform operations, including Elasticsearch, Logstash, and Kibana. Familiarity with data retention strategy, index lifecycle management, and storage optimization in high-volume environments. Experience with infrastructure as code and configuration tooling such as Terraform or Ansible. Exposure to containerized deployment patterns with Docker or Kubernetes. Familiarity with MITRE ATT&CK and how telemetry quality supports detection coverage. Experience supporting managed client onboarding and multi-tenant security platform operations. Experience developing operational tooling or scripts to improve platform reliability and consistency.

What Good Looks Like

You keep the platform stable, performant, and dependable under real operational load. Data onboarding and pipeline changes are delivered consistently with clear validation and minimal production disruption. Telemetry quality is high, with clear standards and measurable improvements over time. Platform services are observable and maintainable through strong runbooks, metrics, and operational discipline. You raise team engineering standards through thoughtful design, documentation, and collaborative reviews. You use AI-assisted workflows in practical, controlled ways that improve platform reliability, operational consistency, and delivery speed.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against ECI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on ECI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    ECI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.