Remotery

Senior Technical Consultant – Network Security Operations

Posted Jul 18

This is a fully remote position, open to applicants in United States.

📋 Description

• Design and implement ExtraHop sensor architectures across physical, virtual, and cloud settings, including strategies for sensor placement involving TAPs, SPAN ports, and VPC traffic mirroring within AWS and Azure.

• Configure and design packet stores for retention, query performance, and compliance needs, making sizing decisions for high-throughput environments.

• Develop custom detections and bundles tailored to specific client environments, going beyond standard detections to address unique threats and patterns of false positives.

• Create custom dashboards in Reveal(x) utilizing metrics, device data, and application views to translate wire data into formats that align with client SOC workflows and executive reporting requirements.

• Establish and maintain REST API integrations between ExtraHop and SIEM, SOAR, ticketing, and CMDB platforms, including the creation of custom triggers and configurations for open data streams.

• Perform network visibility assessments for both prospective and existing clients, identifying blind spots in east-west traffic, coverage for encrypted traffic decryption, and segmentation vulnerabilities.

• Collaborate with clients to enhance and refine their deployment, providing guidance to assist in optimizing the platform.

• Serve as a technical resource for troubleshooting and resolving intricate ExtraHop-related issues during and after implementation.

• Contribute to project documentation, ensuring that Solution Designs and As-Built configurations are clear and comprehensive.

• Mentor junior AHEAD consultants, sharing your ExtraHop expertise and promoting their technical growth.


⛳️ Requirements

• Over 6 years of practical experience with ExtraHop Reveal(x) or Reveal(x) 360 in production settings or comparable NDR solutions.

• Experience in deploying and managing ExtraHop Reveal(x) Enterprise or Reveal(x) 360.

• Proven experience in deploying and tuning ExtraHop sensors, record stores, and packet stores, including aspects of sizing, retention configuration, and performance troubleshooting.

• Strong understanding of wire data analysis, including L2-L7 protocol behavior (TCP/IP, DNS, HTTP, etc.) and TLS/SSL decryption.

• Experience in creating custom detections, bundles, and dashboards that extend beyond default settings.

• Proficient in JavaScript and Python scripting for automation, customization, and workflow enhancement.

• Familiarity with at least one major SIEM (such as Splunk, XSIAM, Crowdstrike, or equivalent) and experience integrating ExtraHop as a data source.

• Experienced in proactive threat hunting and incident investigations utilizing frameworks like MITRE ATT&CK, Cyber Kill Chain, NIST Cybersecurity Framework (CSF), and CIS Critical Security Controls to identify adversary TTPs and enhance detection and response capabilities.

• Experience with cloud traffic mirroring (e.g., AWS VPC Traffic Mirroring, Azure vTAP, or GCP Packet Mirroring) is a significant advantage.

• Solid understanding of network security, cloud environments, identity management, and operating systems including Linux, Mac, and Windows.

• Strong analytical and troubleshooting skills.

• Excellent communication abilities, enabling effective engagement with clients and team members.

• ExtraHop certification (ECS or equivalent) is preferred, along with relevant industry certifications (CISSP, CYSA, CEH, Security+, Pentest+, OSCP) being advantageous.


🏝️ Benefits

• Medical, Dental, and Vision Insurance

• 401(k)

• Paid company holidays

• Paid time off

• Paid parental and caregiver leave

• Plus more! See benefits here for additional details.

People also viewed

Upstart6 days ago

Security Operations Engineer II

US flagUnited States OnlyFull-timeSecurity Operations$134.1k – $185.6k/year
ApplyView job
Paxos6 days ago

Security Operations Engineer

US flagUnited States OnlyFull-timeSecurity Operations$169k – $194k/year
ApplyView job
ConduentJul 25

Cyber Operations Engineer, Senior

US flagUtah OnlyFull-timeSecurity Operations$91.4k – $118.8k/year
ApplyView job
SembiJul 25

Security Operations Engineer

US flagUnited States OnlyFull-timeSecurity Operations
ApplyView job
NTTJul 24

Information Security Incident Response Analyst

GB flagUnited Kingdom OnlyFull-timeSecurity Operations
ApplyView job
Yellow Card AppJul 24

Security Operations Engineer

Anywhere in the WorldFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers