Suricata Cyber Security Engineer, Senior (Washington) Job at Phase2 Technology, Washington DC

aHpXaVdnSlJ3TndkUGVzMVdvNnoyNFlpNkE9PQ==
  • Phase2 Technology
  • Washington DC

Job Description

Your growth matters to us - explore our career development opportunities.

BE EMPOWERED TO SUCCEED

Connect with others in our people-first culture and enhance our collective ingenuity.

SUPPORT YOUR WELLBEING

Learn how well support you as you pursue a balanced, fulfilling life.

YOUR CANDIDATE JOURNEY

Discover what to expect during your journey as a candidate with us.

Suricata Cyber Security Engineer, Senior

The Opportunity:

We are seeking an experienced Suricata Engineer to join our cybersecurity team. You will leverage your deep technical expertise in Suricata, particularly in understanding and managing its YAML configuration files, and how these configurations integrate and influence the Suricata Int rus ion Detection Systems / Int rus ion Prevention Systems ( IDS / IPS ) . You will play a critical role in deploying, tuning, and maintaining Suricata within a complex enterprise IT environment, primarily running on Red Hat Enterprise Linux.

A key focus of this role will be tuning Suricata to operate optimally with network interface cards ( NICs ) , ensuring high-performance packet capture and processing while minimizing packet loss and system resource overhead.

Work with us as we secure and protect our nation's most sensitive capabilities.

What Youll Work On:

  • Designing, deploying, and maintaining Suricata IDS / IPS systems across enterprise networks.
  • Developing, reviewing, and optimizing Suricata YAML configuration files to ensure optimal detection capabilities and minimal false positives.
  • Understanding and managing the interaction between Suricatas YAML configuration and its runtime engine, including rule loading, protocol decoding, and logging.
  • Tuning Suricata for optimal performance with Napatech NICs, including configuring Direct Memory Access ( DMA ) , RSS queues, interrupt coalescing, and leveraging any NIC-specific acceleration features.
  • Collaborating with security teams to integrate Suricata with SIEM and other security monitoring platforms.
  • Troubleshooting installation and operational issues specific to Suricata on Red Hat Enterprise Linux, addressing compatibility, kernel module requirements, SELinux policies , and performance tuning.
  • Identifying and mitigating common pitfalls encountered when deploying Suricata in large-scale enterprise environments, including package dependencies, system resource constraints, and NIC driver or configuration issues.
  • Provide detailed documentation and runbooks for Suricata configuration, tuning NICs, and deployment processes.
  • Staying current with Suricata releases, NIC driver updates, and community best practices for network interface tuning and IDS / IPS performance enhancement.

Join us. The world cant wait.

You Have:

  • Experience working with Suricata IDS / IPS systems, including hands-on management of its YAML configuration files
  • Experience administering Red Hat Enterprise Linux ( RHEL ) systems, including package management, kernel module management, SELinux configuration, and system optimization
  • Experience tuning Suricata for high-performance packet capture with advanced network interface cards, such as Napatech NICs, and with NIC-specific features such as DMA, Receive Side Scaling ( RSS ) , interrupt moderation, and offload capabilities, and how to configure them for Suricata
  • Experience troubleshooting Suricatas interaction with NIC drivers and kernel modules in an enterprise environment
  • Experience with scripting languages, including Bash or Python, to automate Suricata configuration and deployment tasks
  • Knowledge of the Suricata configuration structure, syntax, and how it controls detection rules, logging, and output modules
  • Active TS/SCI clearance; willingness to take a polygraph exam
  • Associates degree and 5+ years of experience supporting IT projects and activities, Bachelors degree and 3+ years of experience supporting IT projects and activities, or Masters degree and 1+ years of experience supporting IT projects, or 7+ years of experience supporting IT projects and activities in lieu of a degree
  • DoD 8570 IAT Level II Certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification
  • Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 60 days of start date

Nice If You Have:

  • Experience integrating Suricata with Splunk, or other SIEM solutions
  • Knowledge of containerized deployments of Suricata, such as Docker or Kubernetes, in enterprise environments
  • Experience with common Linux operating systems, including Oracle or CentOS
  • Experience with other industry-standard IDS / IPS solutions and related technologies
  • Knowledge of network protocols, intrusion detection methodologies, and security event correlation
  • Ability to be a self-starter, work without considerable direction, and work with a team
  • Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations

Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allens benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individuals particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $77,600.00 to $176,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allens total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Work Model

Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.

  • If this position is listed as remote or hybrid, youll periodically work from a Booz Allen or client site facility.
  • If this position is listed as onsite, youll work with colleagues and clients in person, as needed for the specific role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

#J-18808-Ljbffr

Job Tags

Full time, Contract work, Part time, Local area, Remote work,

Similar Jobs

Irvine Park Railroad

Event Staff Job at Irvine Park Railroad

Position SummaryIrvine Park Railroad is hiring seasonal event staff for our Pumpkin Patch. This position is responsible for day-to-day operations of the game booths, activity locations, and providing excellent customer service. This position requires a positive personality... 

General Motors

Mechanical Journeyperson (Pipefitter) - Warren Tech Center Job at General Motors

 ...a very competitive compensation and benefit package. An annual incentive payout is also available, as qualified. Relocation and travel expenses will be the responsibility of the applicant. Please note - per the labor agreement between GM and the UAW, GM may share... 

Qualigence International

Chemical Mixier/Operator Job at Qualigence International

 ...Job Description Job Description Mixer/Operator 7am - 5pm $16/Hour - on the job training The Mixer Operator role is focused on the mixing of 300 gal. batches of various formulations. Responsibilities: Operates an industrial mixer, vacuum... 

Tropical Ford Inc

Service Valet/Lot Porter- 9am-6pm Job at Tropical Ford Inc

 ...upbeat attitude, answers their questions, and directs them to the appropriate person or location. Controls service traffic flow and parking. Assists service advisors when needed Maintains a clean and safe service drive area, free of dirt, water, leaves, snow, etc.... 

Kenan Advantage Group

OTR CDL-A Owner Operator Truck Driver Job at Kenan Advantage Group

 ...company truck then 2-3 days classroom time) -Training pay: $225.00/day flat rate No trailer rental Trailers supplied with all delivery equipment needed CDL-A Truck Driver Requirements: ~ CDL-A~12 months recent and verifiable tractor/trailer experience~...