> Markdown version of [/jobs/ext/655654-network-security-engineer](https://www.wearedevelopers.com/jobs/ext/655654-network-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Engineer - **Company:** LUNA DATA SOLUTIONS - **Location:** Austin, TX, United States - **Contract:** Permanent contract - **Skills:** JIRA, Network Analysis, Cyber Security, Data Normalization, Issue Tracking Systems, Intrusion Detection and Prevention, Intrusion Detection Systems, Network Security, Pcap, Packet Analyzer, Performance Tuning, Security Information and Event Management, Systems Integration, Mitre Att&ck, Cyber Threat Analysis, Microsoft Sentinel, Firepower, SentinelOne Expertise, Cisco - **Published:** June 26, 2026 - **Apply:** https://www.dice.com/job-detail/5bea8be8-b100-4059-8a61-87d2ba2ce290 ## About the Role * SOC operations experience * Hands-on experience with IDS/IPS platforms, including: + Cisco Firepower + TippingPoint + Signature tuning + False-positive reduction + Threat-driven detection improvements * Advanced packet capture (PCAP) and network analysis using: + Corelight + NetWitness + Cribl * Experience identifying: + Network anomalies + Malicious traffic + Lateral movement * Experience maintaining and tuning EDR platforms, including: + CrowdStrike Falcon + SentinelOne * Experience integrating EDR telemetry into: + SIEM platforms + Orchestration workflows * Threat intelligence application expertise * Experience developing detection logic aligned with adversary TTPs ## Description * Engineer, maintain, and tune SIEM platforms, including: + Google SecOps + Gravwell + Correlation rules + Dashboards + Enrichment logic + Detection content * Configure, tune, and optimize IDS/IPS technologies, including: + Corelight + TippingPoint + Cisco Firepower + Signature development + False-positive reduction * Perform packet capture (PCAP) analysis using NetWitness and Corelight to: + Validate alerts + Identify malicious traffic + Support incident investigations * Conduct network traffic analysis to identify: + Anomalies + Lateral movement + Command-and-control activity * Maintain and enhance network security architecture, including: + Distributed sensors (Corelight) + Packet capture systems (NetWitness) + Log pipelines (Cribl, Gravwell, Google SecOps) * Operationalize threat intelligence by: + Converting indicators into detection logic + Developing correlation rules + Creating automated enrichment workflows * Continuously improve detection content using threat intelligence to: + Increase alert fidelity + Reduce false positives * Develop and maintain Cyware SOAR playbooks integrating: + SIEM + EDR + Threat intelligence + Ticketing systems * Support SOC operations through: + Detection engineering + Log onboarding + Data normalization * Develop and maintain: + Network security monitoring infrastructure + Sensors + Collectors + Log pipelines * Collaborate with Incident Responders to provide: + Network-level evidence + Threat validation + Investigative context * Produce: + Engineering reports + Tuning documentation + Platform health assessments + Detection coverage maps * Implement detection logic aligned with: + MITRE ATT&CK + Threat intelligence + Emerging adversary behaviors * Utilize technologies including: + Cisco Firepower + TippingPoint + Corelight + NetWitness + Microsoft Sentinel + Google SecOps, * Experience operationalizing threat intelligence from: + Recorded Future + ThreatMon + GreyNoise + Google Threat Intelligence + VirusTotal + Mandiant * Experience converting indicators and TTPs into: + SIEM rules + IPS signatures + Automated enrichment workflows * Perform packet-level analysis to: + Validate alerts + Identify malicious activity * Serve as an escalation resource for: + SOC Analysts + Incident Responders * Proficiency with: + Google SecOps + Cyware SOAR + Automated workflow development + Jira integration * Experience integrating: + SIEM + IDS/IPS + CrowdStrike + SentinelOne + Threat intelligence platforms * Preferred security certifications: + CISSP + CEH + GISF + GSEC + CySA+ + Security+ ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)