Cybersecurity Sensor Engineer
Listed on 2026-02-24
-
Engineering
Cybersecurity, Systems Engineer -
IT/Tech
Cybersecurity, Systems Engineer
Job Number: R0233950
Cybersecurity Sensor Engineer The OpportunityWe are looking for a skilled Cyber Security Sensor Engineer to enhance our cybersecurity team. The ideal candidate will have extensive technical knowledge and a comprehensive understanding of cyber security technologies that detect incoming data within enterprise environments. Responsibilities include installing, engineering, and providing Tier III troubleshooting for sensors operating on predominantly Linux-based systems. The role involves deploying, tuning, and maintaining sensors across a complex, multi-network global enterprise environment.
This position emphasizes daily operations, maintenance, troubleshooting, and engineering tasks related to cyber security sensor tools. These include Network Intrusion Detection Systems (IDS), Data Loss Prevention (DLP), threat detection, Deep Session Inspection, and full Packet Capture (PCAP) storage and analysis. While vendor-neutral, the role often involves working with tools from vendors such as Trellix/Fire Eye, Fidelis Security, Endace, SNORT, Suricata, Corelight, and Vectra AI.
The candidate must be capable of supporting security sensor solutions and ensuring their optimal performance within a complex security infrastructure.
Work with us as we secure and protect our nation's most sensitive capabilities.
What You'll Work OnDesign, deploy, and maintain Linux-based IDS/IPS systems across geographically dispersed, multi-domain enterprise networks.
Develop, review, and optimize configuration files while collaborating with Security Operations Center analysts to enhance detection accuracy and reduce false positives.
Manage the interaction between sensor configurations and runtime engines, including rule loading, protocol decoding, and logging processes.
Work with security teams to integrate sensors with SIEM, SOAR, and other monitoring platforms.
Keep abreast of updates to sensor operating systems, vendor software, NIC drivers, and community best practices for network interface tuning and IDS/IPS performance improvements, ensuring system effectiveness and security posture.
Join us. The world can't wait.
You HaveExperience managing IDS, IPS, PCAP, and NDR systems, including configuration management, OS upgrades, hotfix application, and adherence to STIGs for cybersecurity tools
Experience in administering Red Hat Enterprise Linux (RHEL) systems, covering package management, such as yum/dnf, kernel module handling, SELinux configuration, and system performance tuning
Experience optimizing sensors for high-performance packet capture, utilizing advanced network interfaces, such as Napatech NICs, or hardware with direct-memory access capabilities
Experience managing administrative and user access to appliances, servers, and endpoints using domain accounts, TPAM, LDAP, Kerberos, and Active Directory
Experience with scripting languages, such as Bash or Python, and automation tools, such as Ansible, to streamline configuration and deployment processes across large-scale systems
Ability to troubleshoot Linux interactions with NICs, drivers, and kernel modules within enterprise environments
Active TS/SCI clearance; willingness to take a polygraph exam
Associate's degree and 5+ years of experience supporting IT projects and activities, or Bachelor's degree and 3+ years of experience supporting IT projects and activities, or Master's degree and 1+ years of experience supporting IT projects and activities
DoD 8570 IAT Level II Certification, including Security+ CE, CCNA‑Security, GSEC, SSCP, CySA+, GICSP, or CND Certification
Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support (CSSP‑IS) Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 60 days of start date
Experience remotely managing sensors, servers, and endpoints via SSH and SCP, using Linux and Windows command-line tools, including PuTTY
Experience managing large enterprise data storage and RAID arrays in configurations, such as RAID 5/6/10/50/60, and fine‑tuning packet capture sensors feeding sensor storage array for optimal throughput
Experience with SOC operations,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).