Jobs · Engineering · New York

Security Platform Engineer (DevSecOps)

ECI · New York, NY · 2 days ago
EngineeringFull-time

ECI is the leading global provider of managed services, cybersecurity, and business transformation for mid-market financial services organizations. From its unmatched range of services, ECI provides stability, security, and improved business performance, freeing clients from technology concerns. More than 1,000 customers worldwide with over $3 trillion of assets under management trust ECI. At ECI, success is driven by passion and purpose, with a commitment to empowering employees globally.

About the role

The Security Platform Engineer is part of ECI's Security Engineering team and focuses on building, operating, and improving the platform layer that powers security services at scale. This hands-on engineering role emphasizes Elastic platform operations, telemetry pipeline reliability, and lifecycle management. You will design and maintain data ingestion patterns, platform standards, and operational controls to ensure security data is reliable, performant, and ready for detection and response use. The role leverages AI-assisted workflows to improve delivery quality, reduce repetitive operational effort, and accelerate security outcomes across detection, response, and platform services.

You will work within the Platform function, owning Elastic, Logstash, and core data pipeline operations across client environments. The Platform team owns data ingestion, parsing standards, schema quality, retention, and platform reliability, while partnering with Automation Engineering, which handles detection-as-code workflows, SOAR orchestration, and automation delivery.

Responsibilities

  • Build and maintain Elastic platform services, data pipelines, and operational standards across security environments.
  • Own Logstash and ingestion pipeline lifecycle including onboarding, parsing, normalization, enrichment, and schema governance.
  • Maintain platform reliability through performance tuning, capacity planning, retention management, and upgrade planning.
  • Define and enforce data quality standards to ensure telemetry is complete, consistent, and usable for detection and response workflows.
  • Troubleshoot and resolve ingestion, indexing, search performance, and pipeline stability issues in production environments.
  • Own platform-side client lifecycle readiness including onboarding standards, technical validation, and production go-live criteria.
  • Build and maintain platform observability using metrics, logging, health checks, and operational runbooks.
  • Partner with Automation Engineering to provide stable data contracts and platform interfaces for detection and workflow delivery.
  • Collaborate in architecture and operational review practices to raise engineering standards across the function.
  • Explore and apply AI-assisted engineering practices to improve platform reliability, telemetry quality, operational documentation, and delivery efficiency.

Requirements

  • Degree in Computer Science, Cyber Security, Engineering, Information Technology, or equivalent practical experience.
  • 3+ years supporting or engineering production SIEM, observability, or large-scale data platform environments.
  • Strong understanding of telemetry ingestion, parsing, normalization, enrichment, and schema management.
  • Experience troubleshooting distributed platform issues across ingestion, indexing, search, and data lifecycle.
  • Practical experience with platform lifecycle operations including upgrades, patching, configuration management, and performance tuning.
  • Experience working with REST APIs and integration patterns in operational environments.
  • Working knowledge of Linux administration in engineering environments.
  • Working knowledge of cloud platforms and services, including IAM, networking, and secure integration patterns in AWS, Azure, or GCP.
  • Foundational understanding of detection and incident response concepts within security operations.

Preferred Qualifications

  • Experience administering enterprise SIEM or security analytics platforms in production, especially Elastic Security.
  • Hands-on experience with Elastic Stack platform operations, including Elasticsearch, Logstash, and Kibana.
  • Familiarity with data retention strategy, index lifecycle management, and storage optimization in high-volume environments.
  • Experience with infrastructure as code and configuration tooling such as Terraform or Ansible.
  • Exposure to containerized deployment patterns with Docker or Kubernetes.
  • Familiarity with MITRE ATT&CK and how telemetry quality supports detection coverage.
  • Experience supporting managed client onboarding and multi-tenant security platform operations.
  • Experience developing operational tooling or scripts to improve platform reliability and consistency.

What Good Looks Like

  • You keep the platform stable, performant, and dependable under real operational load.
  • Data onboarding and pipeline changes are delivered consistently with clear validation and minimal production disruption.
  • Telemetry quality is high, with clear standards and measurable improvements over time.
  • Platform services are observable and maintainable through strong runbooks, metrics, and operational discipline.
  • You raise team engineering standards through thoughtful design, documentation, and collaborative reviews.
  • You use AI-assisted workflows in practical, controlled ways that improve platform reliability, operational consistency, and delivery speed.

Benefits

ECI offers a competitive compensation package and opportunities to work with an amazing global team.

Similar jobs