Network Security Engineer

LUNA DATA SOLUTIONS
Austin, TX, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

JIRA Network Analysis Cyber Security Data Normalization Issue Tracking Systems Intrusion Detection and Prevention Intrusion Detection Systems Network Security Pcap Packet Analyzer Performance Tuning Security Information and Event Management
+7 more
Systems Integration Mitre Att&ck Cyber Threat Analysis Microsoft Sentinel Firepower SentinelOne Expertise Cisco

Job description

  • Engineer, maintain, and tune SIEM platforms, including:
  • Google SecOps
  • Gravwell
  • Correlation rules
  • Dashboards
  • Enrichment logic
  • Detection content
  • Configure, tune, and optimize IDS/IPS technologies, including:
  • Corelight
  • TippingPoint
  • Cisco Firepower
  • Signature development
  • False-positive reduction
  • Perform packet capture (PCAP) analysis using NetWitness and Corelight to:
  • Validate alerts
  • Identify malicious traffic
  • Support incident investigations
  • Conduct network traffic analysis to identify:
  • Anomalies
  • Lateral movement
  • Command-and-control activity
  • Maintain and enhance network security architecture, including:
  • Distributed sensors (Corelight)
  • Packet capture systems (NetWitness)
  • Log pipelines (Cribl, Gravwell, Google SecOps)
  • Operationalize threat intelligence by:
  • Converting indicators into detection logic
  • Developing correlation rules
  • Creating automated enrichment workflows
  • Continuously improve detection content using threat intelligence to:
  • Increase alert fidelity
  • Reduce false positives
  • Develop and maintain Cyware SOAR playbooks integrating:
  • SIEM
  • EDR
  • Threat intelligence
  • Ticketing systems
  • Support SOC operations through:
  • Detection engineering
  • Log onboarding
  • Data normalization
  • Develop and maintain:
  • Network security monitoring infrastructure
  • Sensors
  • Collectors
  • Log pipelines
  • Collaborate with Incident Responders to provide:
  • Network-level evidence
  • Threat validation
  • Investigative context
  • Produce:
  • Engineering reports
  • Tuning documentation
  • Platform health assessments
  • Detection coverage maps
  • Implement detection logic aligned with:
  • MITRE ATT&CK
  • Threat intelligence
  • Emerging adversary behaviors
  • Utilize technologies including:
  • Cisco Firepower
  • TippingPoint
  • Corelight
  • NetWitness
  • Microsoft Sentinel
  • Google SecOps, * Experience operationalizing threat intelligence from:
  • Recorded Future
  • ThreatMon
  • GreyNoise
  • Google Threat Intelligence
  • VirusTotal
  • Mandiant
  • Experience converting indicators and TTPs into:
  • SIEM rules
  • IPS signatures
  • Automated enrichment workflows
  • Perform packet-level analysis to:
  • Validate alerts
  • Identify malicious activity
  • Serve as an escalation resource for:
  • SOC Analysts
  • Incident Responders
  • Proficiency with:
  • Google SecOps
  • Cyware SOAR
  • Automated workflow development
  • Jira integration
  • Experience integrating:
  • SIEM
  • IDS/IPS
  • CrowdStrike
  • SentinelOne
  • Threat intelligence platforms
  • Preferred security certifications:
  • CISSP
  • CEH
  • GISF
  • GSEC
  • CySA+
  • Security+

Requirements

  • SOC operations experience
  • Hands-on experience with IDS/IPS platforms, including:
  • Cisco Firepower
  • TippingPoint
  • Signature tuning
  • False-positive reduction
  • Threat-driven detection improvements
  • Advanced packet capture (PCAP) and network analysis using:
  • Corelight
  • NetWitness
  • Cribl
  • Experience identifying:
  • Network anomalies
  • Malicious traffic
  • Lateral movement
  • Experience maintaining and tuning EDR platforms, including:
  • CrowdStrike Falcon
  • SentinelOne
  • Experience integrating EDR telemetry into:
  • SIEM platforms
  • Orchestration workflows
  • Threat intelligence application expertise
  • Experience developing detection logic aligned with adversary TTPs

Benefits & conditions

  • Opportunity to make a significant impact and own technology initiatives
  • Meaningful, mission-driven work
  • Competitive compensation and comprehensive benefits, including:
  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Accident insurance
  • Short-term disability insurance
  • Additional benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

57 sec

Analyzing network traffic locally with open source security tooling

Chris Heilmann +2 · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all