Vectra Detection Engineer
On-siteChantilly, Virginia, United States
Job Summary
Analyze network traffic to identify and document threat patterns, develop and maintain network-based security signatures in Suricata, and use offensive security tools to simulate attacks and generate sample traffic for testing detections. Collaborate with data scientists to support AI-driven detection efforts, continuously monitor and tune detection effectiveness, and contribute to threat hunting by identifying new attacker tactics, techniques, and procedures. Participate in incident response activities when required. This role supports the Attack Signal Production Group, building core threat detection technology using AI for networks, cloud, and hybrid environments.
Required Qualifications
- Active TS/SCI Clearance
- Strong background in network traffic analysis and threat detection
- Hands-on experience with tools like Suricata for signature-based detection
- Knowledge of offensive security (e.g., simulating attacks)
- Familiarity with MITRE ATT&CK framework and real-world attacker behaviors (lateral movement, C2, etc.)
- Collaboration skills for working with data scientists and researchers
- Understanding of networking protocols, OSI layers, and security concepts (often L3-L7)
- Relevant experience in cybersecurity (typically several years)
- Must meet eligibility requirements for access to classified information
Desired Qualifications
- Certifications such as OSCP, GCIA, GCDA, GSEC, or similar (optional but valued)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.