Job Overview
We are seeking a seasoned security professional to spearhead our network security initiatives. This pivotal role involves the deployment and management of open-source network security platforms, ensuring seamless visibility and threat detection.
- Design, deploy, and configure advanced network security monitoring tools (e.g., Security Onion, Zeek, Suricata, Bro) to safeguard our networks.
- Develop and refine IDS / IPS signatures to effectively mitigate industrial and enterprise network threats.
- Build and maintain log pipelines using Filebeat, Logstash, or similar agents to enrich security telemetry for downstream SIEMs.
- Collaborate with SIEM engineers to ensure reliable alerts and dashboards.
- Support PCAP-based testing and validation for visibility and detection use cases.
Key Responsibilities :
This critical role demands expertise in the following areas :
Hands-on experience with open-source security monitoring platforms (Zeek, Suricata, Security Onion, or equivalent).Strong understanding of network protocols, particularly ICS / OT protocol exposure.Familiarity with log collection and enrichment tools (Logstash, Filebeat, or similar).Knowledge of SIEM concepts (rules, decoders, correlation).Linux administration and basic scripting skills.Ability to troubleshoot packet capture and log ingestion issues.Nice to Have :
While not essential, candidates with experience in the following areas will be considered highly competitive :
Exposure to industrial networks (ICS / OT).Familiarity with MITRE ATT&CK or other threat detection frameworks.