Senior Security Engineer - Elastic SIEM and Detection Engineering
Acronis is a global leader in cyber protection, delivering AI-powered protection for productive MSPs in a single, natively integrated platform that unifies operations management, cybersecurity, and data protection. Driven by our mission to protect, manage and automate every workload that businesses and lives depend on, we’ve built the industry’s only all-in-one solution.We’re looking for a Senior Security Engineer to lead our Elastic SIEM and Detection Engineering program. This is an engineering-first role focused on building scalable detection pipelines, improving telemetry quality, and developing high-confidence detections that help security teams move faster and respond more effectively.You’ll own the evolution of our Elastic Security environment — from log ingestion and platform optimization to Detection-as-Code pipelines and detection coverage strategy. This role is ideal for someone who enjoys building systems, improving signal quality, automating workflows, and solving detection engineering problems at scale.While the primary focus is engineering, you’ll also serve as a Tier 2 escalation point for complex security events, helping scope incidents, initiate containment when needed, and improve detections based on real-world activity.This is a high-impact role with significant ownership and the opportunity to shape how detection engineering is implemented across the organization.What You'll DoElastic SIEM & Platform Engineering:Own and optimize the Elastic Security platform (Elasticsearch, Kibana, Fleet, Logstash, Elastic Agents)Design and maintain ingestion pipelines for cloud, endpoint, network, and application telemetryImprove telemetry quality, data retention, performance, and investigation workflowsIntegrate SIEM workflows with SOAR and automation toolingDetection Engineering & Detection-as-CodeBuild and maintain a Detection-as-Code pipeline using Git-based workflows and CI/CD automationDevelop, test, tune, and maintain high-fidelity detections using Elastic Security, EQL, and KQLReduce alert noise through tuning, enrichment, suppression, and exception handlingMap detections to MITRE ATT&CK and help drive detection coverage strategyTrack detection quality metrics including alert fidelity, false positive rates, and coverage gapsIncident Response SupportAssist with complex alert escalations and perform initial incident scopingExecute initial containment actions when necessary (endpoint isolation, IP/domain blocking, account suspension)Participate in a low-frequency on-call rotation for critical incidentsTranslate incident learnings into improved detections and telemetry coverageCollaboration & AutomationPartner with infrastructure, DevSecOps, and cloud teams to improve logging and visibilityBuild automation and tooling using Python and/or PowerShellSupport purple team exercises and adversary simulationsWho We're Looking For5+ years of cybersecurity engineering experience3+ years focused on SIEM engineering, detection engineering, or security analyticsStrong hands-on experience with Elastic Security and the Elastic StackExperience building or maintaining Detection-as-Code workflows using Git and CI/CD pipelinesStrong understanding of detection tuning, alert fidelity, and operational detection qualityAbility to independently investigate complex alerts and produce actionable findingsTechnical ExperienceElastic Security, Kibana, Fleet, Elastic Agents, EQL/KQLDetection engineering and MITRE ATT&CK mappingJenkins, Bitbucket Pipelines, GitHub Actions, or similar CI/CD toolingPython and/or PowerShell scriptingAWS CloudTrail, VPC Flow Logs, Azure Monitor, or similar telemetry sourcesTCP/IP, DNS, HTTP/S, and common attack patternsThreat intelligence enrichment and operationalizationNice To HaveSOAR playbook development and automated response workflowsSigma rule developmentElastic detection-rules ecosystem familiarityTerraform or Ansible experiencePrevious SOC or Incident Response backgroundWhat Success Looks Like30 Days: Validate telemetry sources and establish initial detection coverage baseline90 Days: Operational Detection-as-Code pipeline with initial custom detections deployed180 Days: Reduced alert noise, improved coverage visibility, and stabilized SIEM operationsWho We AreA Swiss company founded in Singapore in 2003, Acronis offers over twenty years of innovation with 15 offices worldwide and more than 1800 employees in 50+ countries. Acronis Cyber Protect is available in 26 languages in 150 countries and is used by over 20,000 service providers to protect over 750,000 businesses.Our corporate culture centers on innovation, accountability, and impact. We encourage our people to think boldly, challenge conventional approaches, and take ownership of outcomes. As a member of our global “A-Team,” you’ll operate in a high-growth, fast-paced environment where resilience, adaptability, and a commitment to continuous improvement drive success.The US pay range for this position is $123,000–$180,000. This range reflects the minimum and maximum total target annual compensation for this role across all U.S. locations. The actual compensation offered at the start of employment is determined based on factors including, but not limited to, experience level, knowledge, skills, and geographic location. In addition to competitive compensation, this role includes a comprehensive benefits package featuring medical, dental, and vision coverage, flexible spending accounts (FSA), disability and life insurance, a 401(k) retirement plan with company match, and a generous vacation policy.