
Senior Technical Consultant – Network Security Operations
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in United States.
• Design and implement ExtraHop sensor architectures across physical, virtual, and cloud settings, including strategies for sensor placement involving TAPs, SPAN ports, and VPC traffic mirroring within AWS and Azure.
• Configure and design packet stores for retention, query performance, and compliance needs, making sizing decisions for high-throughput environments.
• Develop custom detections and bundles tailored to specific client environments, going beyond standard detections to address unique threats and patterns of false positives.
• Create custom dashboards in Reveal(x) utilizing metrics, device data, and application views to translate wire data into formats that align with client SOC workflows and executive reporting requirements.
• Establish and maintain REST API integrations between ExtraHop and SIEM, SOAR, ticketing, and CMDB platforms, including the creation of custom triggers and configurations for open data streams.
• Perform network visibility assessments for both prospective and existing clients, identifying blind spots in east-west traffic, coverage for encrypted traffic decryption, and segmentation vulnerabilities.
• Collaborate with clients to enhance and refine their deployment, providing guidance to assist in optimizing the platform.
• Serve as a technical resource for troubleshooting and resolving intricate ExtraHop-related issues during and after implementation.
• Contribute to project documentation, ensuring that Solution Designs and As-Built configurations are clear and comprehensive.
• Mentor junior AHEAD consultants, sharing your ExtraHop expertise and promoting their technical growth.
• Over 6 years of practical experience with ExtraHop Reveal(x) or Reveal(x) 360 in production settings or comparable NDR solutions.
• Experience in deploying and managing ExtraHop Reveal(x) Enterprise or Reveal(x) 360.
• Proven experience in deploying and tuning ExtraHop sensors, record stores, and packet stores, including aspects of sizing, retention configuration, and performance troubleshooting.
• Strong understanding of wire data analysis, including L2-L7 protocol behavior (TCP/IP, DNS, HTTP, etc.) and TLS/SSL decryption.
• Experience in creating custom detections, bundles, and dashboards that extend beyond default settings.
• Proficient in JavaScript and Python scripting for automation, customization, and workflow enhancement.
• Familiarity with at least one major SIEM (such as Splunk, XSIAM, Crowdstrike, or equivalent) and experience integrating ExtraHop as a data source.
• Experienced in proactive threat hunting and incident investigations utilizing frameworks like MITRE ATT&CK, Cyber Kill Chain, NIST Cybersecurity Framework (CSF), and CIS Critical Security Controls to identify adversary TTPs and enhance detection and response capabilities.
• Experience with cloud traffic mirroring (e.g., AWS VPC Traffic Mirroring, Azure vTAP, or GCP Packet Mirroring) is a significant advantage.
• Solid understanding of network security, cloud environments, identity management, and operating systems including Linux, Mac, and Windows.
• Strong analytical and troubleshooting skills.
• Excellent communication abilities, enabling effective engagement with clients and team members.
• ExtraHop certification (ECS or equivalent) is preferred, along with relevant industry certifications (CISSP, CYSA, CEH, Security+, Pentest+, OSCP) being advantageous.
• Medical, Dental, and Vision Insurance
• 401(k)
• Paid company holidays
• Paid time off
• Paid parental and caregiver leave
• Plus more! See benefits here for additional details.
Upstart
Paxos
Conduent
Get handpicked remote jobs straight to your inbox weekly.