Network Security Engineer
LUNA DATA SOLUTIONS
Austin, TX, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
JIRA
Network Analysis
Cyber Security
Data Normalization
Issue Tracking Systems
Intrusion Detection and Prevention
Intrusion Detection Systems
Network Security
Pcap
Packet Analyzer
Performance Tuning
Security Information and Event Management
+7 more
Systems Integration
Mitre Att&ck
Cyber Threat Analysis
Microsoft Sentinel
Firepower
SentinelOne Expertise
Cisco
Job description
- Engineer, maintain, and tune SIEM platforms, including:
- Google SecOps
- Gravwell
- Correlation rules
- Dashboards
- Enrichment logic
- Detection content
- Configure, tune, and optimize IDS/IPS technologies, including:
- Corelight
- TippingPoint
- Cisco Firepower
- Signature development
- False-positive reduction
- Perform packet capture (PCAP) analysis using NetWitness and Corelight to:
- Validate alerts
- Identify malicious traffic
- Support incident investigations
- Conduct network traffic analysis to identify:
- Anomalies
- Lateral movement
- Command-and-control activity
- Maintain and enhance network security architecture, including:
- Distributed sensors (Corelight)
- Packet capture systems (NetWitness)
- Log pipelines (Cribl, Gravwell, Google SecOps)
- Operationalize threat intelligence by:
- Converting indicators into detection logic
- Developing correlation rules
- Creating automated enrichment workflows
- Continuously improve detection content using threat intelligence to:
- Increase alert fidelity
- Reduce false positives
- Develop and maintain Cyware SOAR playbooks integrating:
- SIEM
- EDR
- Threat intelligence
- Ticketing systems
- Support SOC operations through:
- Detection engineering
- Log onboarding
- Data normalization
- Develop and maintain:
- Network security monitoring infrastructure
- Sensors
- Collectors
- Log pipelines
- Collaborate with Incident Responders to provide:
- Network-level evidence
- Threat validation
- Investigative context
- Produce:
- Engineering reports
- Tuning documentation
- Platform health assessments
- Detection coverage maps
- Implement detection logic aligned with:
- MITRE ATT&CK
- Threat intelligence
- Emerging adversary behaviors
- Utilize technologies including:
- Cisco Firepower
- TippingPoint
- Corelight
- NetWitness
- Microsoft Sentinel
- Google SecOps, * Experience operationalizing threat intelligence from:
- Recorded Future
- ThreatMon
- GreyNoise
- Google Threat Intelligence
- VirusTotal
- Mandiant
- Experience converting indicators and TTPs into:
- SIEM rules
- IPS signatures
- Automated enrichment workflows
- Perform packet-level analysis to:
- Validate alerts
- Identify malicious activity
- Serve as an escalation resource for:
- SOC Analysts
- Incident Responders
- Proficiency with:
- Google SecOps
- Cyware SOAR
- Automated workflow development
- Jira integration
- Experience integrating:
- SIEM
- IDS/IPS
- CrowdStrike
- SentinelOne
- Threat intelligence platforms
- Preferred security certifications:
- CISSP
- CEH
- GISF
- GSEC
- CySA+
- Security+
Requirements
- SOC operations experience
- Hands-on experience with IDS/IPS platforms, including:
- Cisco Firepower
- TippingPoint
- Signature tuning
- False-positive reduction
- Threat-driven detection improvements
- Advanced packet capture (PCAP) and network analysis using:
- Corelight
- NetWitness
- Cribl
- Experience identifying:
- Network anomalies
- Malicious traffic
- Lateral movement
- Experience maintaining and tuning EDR platforms, including:
- CrowdStrike Falcon
- SentinelOne
- Experience integrating EDR telemetry into:
- SIEM platforms
- Orchestration workflows
- Threat intelligence application expertise
- Experience developing detection logic aligned with adversary TTPs
Benefits & conditions
- Opportunity to make a significant impact and own technology initiatives
- Meaningful, mission-driven work
- Competitive compensation and comprehensive benefits, including:
- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- Accident insurance
- Short-term disability insurance
- Additional benefits
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago