We are seeking an experienced Network Security Engineer to join our team on a long-term contract in Austin, TX. This role focuses on security monitoring, detection engineering, network traffic analysis, threat intelligence integration, and SOC support in a large-scale enterprise environment.
Responsibilities
- Engineer, maintain, and tune SIEM platforms, including:
- Google SecOps
- Gravwell
- Correlation rules
- Dashboards
- Enrichment logic
- Detection content
- Configure, tune, and optimize IDS/IPS technologies, including:
- Corelight
- TippingPoint
- Cisco Firepower
- Signature development
- False-positive reduction
- Perform packet capture (PCAP) analysis using NetWitness and Corelight to:
- Validate alerts
- Identify malicious traffic
- Support incident investigations
- Conduct network traffic analysis to identify:
- Anomalies
- Lateral movement
- Command-and-control activity
- Maintain and enhance network security architecture, including:
- Distributed sensors (Corelight)
- Packet capture systems (NetWitness)
- Log pipelines (Cribl, Gravwell, Google SecOps)
- Operationalize threat intelligence by:
- Converting indicators into detection logic
- Developing correlation rules
- Creating automated enrichment workflows
- Continuously improve detection content using threat intelligence to:
- Increase alert fidelity
- Reduce false positives
- Develop and maintain Cyware SOAR playbooks integrating:
- SIEM
- EDR
- Threat intelligence
- Ticketing systems
- Support SOC operations through:
- Detection engineering
- Log onboarding
- Data normalization
- Develop and maintain:
- Network security monitoring infrastructure
- Sensors
- Collectors
- Log pipelines
- Collaborate with Incident Responders to provide:
- Network-level evidence
- Threat validation
- Investigative context
- Produce:
- Engineering reports
- Tuning documentation
- Platform health assessments
- Detection coverage maps
- Implement detection logic aligned with:
- MITRE ATT&CK
- Threat intelligence
- Emerging adversary behaviors
- Utilize technologies including:
- Cisco Firepower
- TippingPoint
- Corelight
- NetWitness
- Microsoft Sentinel
- Google SecOps
Required Skills
- SOC operations experience
- Hands-on experience with IDS/IPS platforms, including:
- Cisco Firepower
- TippingPoint
- Signature tuning
- False-positive reduction
- Threat-driven detection improvements
- Advanced packet capture (PCAP) and network analysis using:
- Experience identifying:
- Network anomalies
- Malicious traffic
- Lateral movement
- Experience maintaining and tuning EDR platforms, including:
- CrowdStrike Falcon
- SentinelOne
- Experience integrating EDR telemetry into:
- SIEM platforms
- Orchestration workflows
- Threat intelligence application expertise
- Experience developing detection logic aligned with adversary TTPs
Preferred Skills
- Experience operationalizing threat intelligence from:
- Recorded Future
- ThreatMon
- GreyNoise
- Google Threat Intelligence
- VirusTotal
- Mandiant
- Experience converting indicators and TTPs into:
- SIEM rules
- IPS signatures
- Automated enrichment workflows
- Perform packet-level analysis to:
- Validate alerts
- Identify malicious activity
- Serve as an escalation resource for:
- SOC Analysts
- Incident Responders
- Proficiency with:
- Google SecOps
- Cyware SOAR
- Automated workflow development
- Jira integration
- Experience integrating:
- SIEM
- IDS/IPS
- CrowdStrike
- SentinelOne
- Threat intelligence platforms
- Preferred security certifications:
- CISSP
- CEH
- GISF
- GSEC
- CySA+
- Security+
What We Offer
- Work on a highly innovative team using cutting-edge technology
- Opportunity to make a significant impact and own technology initiatives
- Meaningful, mission-driven work
- Competitive compensation and comprehensive benefits, including:
- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- Accident insurance
- Short-term disability insurance
- Additional benefits
Equal Opportunity Employer
Luna Data Solutions, Inc. (LDS) is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, genetics, protected veteran status, disability status, or any other protected characteristic.