Professional Services Engineer - (TS/SCI Full Poly)

  • Posted 11 hours ago | Updated 11 hours ago

Overview

USD 200,000.00 - 325,000.00 per year
Full Time

Skills

SAFE
Open Source
Cloud Computing
Incident Management
Reporting
Professional Services
DMV
Security Clearance
FOCUS
Optimization
Educate
Dashboard
Testing
Knowledge Transfer
Collaboration
Product Management
Apache Kafka
Use Cases
Information Retrieval
International Relations
Investor Relations
Root Cause Analysis
Corrective And Preventive Action
Startups
System On A Chip
Computer Networking
Microsoft Windows
OS X
Linux
Unix
Operating Systems
IDS
IPS
Network Administration
Firewall
TCP/IP
SIEM
Splunk
Scripting
Bash
Python
Perl
Windows PowerShell
Amazon SES
Management
Investments
Venture Capital
Network
Research
Artificial Intelligence
Workflow
Machine Learning (ML)
Cloud Security
SaaS
ARM
Cyber Security
Problem Solving
Conflict Resolution
AIM

Job Details

Towards the end of our interview process is an in-person interview.

Do you want to help make the world safe from cyber attack? At Corelight, we believe that the best approach to cybersecurity risk starts with the network. Attackers can evade endpoint detection, firewalls and many other technologies - but they can't avoid leaving digital footprints on the networks they traverse. Built on open-source innovations from Zeek, Suricata and YARA and refined through years of real-world use, Corelight transforms network footprints from physical, virtual and cloud networks into actionable insights. Our customers use these insights to speed incident response and proactively hunt for threats. We are currently seeking a Staff Resident PSE to join our Federal Professional Services team, reporting to the manager of Professional Services. This role would be based in DC, Maryland, Virginia (DMV) area and requires a TS/SCI Clearance with Full Scope Polygraph.

In this role, the main focus is to prepare and validate equipment configurations for new installations, develop content for anomaly and hunt detections, assess the overall health of the Corelight infrastructure at the client's location. You're the ideal candidate if you are a strategic thinker with a strong networking and security background, work well independently, and are results-driven.

Key Responsibilities:
  • Help customers improve their cybersecurity posture, with a particular focus on process
    optimization
  • Help investigate incidents
  • Educate on Zeek Log use, including as it relates to Corelight Suricata alerts
  • Design and implement technical solutions with ecosystem partners (packet brokers,
    asset managers, SOAR systems, etc.)
  • Implement queries and dashboards in SIEMs - Splunk, Elastic, Humio, etc.
  • Influence customers and Corelight teams and be seen as a technical expert
  • Conduct network-related testing to ensure Corelight products operate correctly
  • Perform validation testing of Corelight products
  • Provide ongoing, informal, knowledge transfer
  • Collaborate with product management on product features/integrations
  • Work with back-end tools like Kafka and Logstash
  • Documenting the process for importing of data (MISP, Intel, etc)
  • Developing custom content for threat hunting use cases as defined by the customer
  • Developing playbooks for SOC/IR workflow automation based on Corelight data
  • Ad-hoc (as requested) written summary reports on equipment and security problems
  • Technical input to major service outage root cause analysis and corrective action reports
  • Leading project status meetings and wrap-up/post-mortem meetings
  • Some on-site work required

Qualifications:
  • TS/SCI Full Scope Poly Required
  • 5+ years of experience in cybersecurity (Prior startup experience preferred)
  • Extensive experience with a SOC environment
  • Zeek/Corelight experience is a plus
  • Security and/or Networking related certification(s)
  • Demonstrated expertise in Windows/MacOS/Linux/Unix operating systems, IDS/IPS,
  • Network administration, firewall configuration, and strong knowledge of TCP/IP
  • SIEM experience (Splunk required, others a bonus)
  • Scripting in (some of) Zeek, Bash, Python, Perl, Powershell, etc.
  • Strong briefing skills; experience interacting with SES/general officer-level management

Why Corelight?
Fueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is the fastest growing network detection and response platform in the industry. Our customers trust us to protect mission-critical assets in leading enterprises, government, and research institutions worldwide. We are leading the way with AI-assisted workflows, machine learning models, cloud security and SaaS-based solutions to arm defenders with the tools and knowledge they need to disrupt cyber attacks. Our team of passionate innovators are dedicated to solving some of the toughest challenges in cybersecurity, while fostering a collaborative, inclusive, and growth-oriented culture. Corelight is committed to a geographically distributed yet connected employee base with employees working from home and office locations around the world. At Corelight, we take pride in the diversity of our backgrounds and perspectives, and we are committed to fostering an inclusive environment that strengthens our company. By embracing a wide range of experiences, backgrounds,neurodiversity, talents, and approaches to problem-solving, we aim to create a workplace where everyone can thrive and contribute their best. We are looking forward to meeting you.

Check us out at ;br>
Notice of Pay Transparency:
The compensation for this position may vary depending on factors such as your location, skills and experience. Depending on the nature and seniority of the role, a percentage of compensation may come in the form of a commission-based or discretionary bonus. Equity and additional benefits will also be awarded.

Compensation Range

$200,000-$325,000 USD
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.