company

Network Intrusion Detection Engineer - Active TS/SCI with CI Poly

ENS Solutions, LLCNorfolk, Virginia, United States
On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Experience

Qualifications

Essential Qualifications:Proven experience with network IDS/IPS systems, particularly Suricata, Snort, or Corelight, including management of YAML configurations. In-depth knowledge of configuration structures and their impact on detection rules and logging outputs. Extensive experience with Red Hat Enterprise Linux (RHEL), covering package management (yum/dnf), kernel module management, and system optimization through Unix CLI and SSH. Hands-on experience tuning Suricata for high-performance packet capture, particularly with advanced NICs like Napatech. Familiarity with NIC-specific features such as DMA, RSS, and interrupt moderation.

About the job

Join our dynamic cybersecurity team as a Network Intrusion Detection Engineer, where your expertise will be pivotal in protecting our network infrastructure. We are looking for a talented individual with robust Linux engineering skills and a deep understanding of YAML configuration files, specifically how they interface with Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). The ideal candidate will have practical experience working with Suricata and similar network-based IDS solutions like Snort, VectraAI, or Corelight. In this role, you will be instrumental in deploying, optimizing, and maintaining IDS within a sophisticated enterprise IT environment, primarily utilizing Red Hat Enterprise Linux.

Key Responsibilities:

  • Design, deploy, and maintain IDS/IPS systems across a multifaceted enterprise environment.
  • Develop and refine YAML configuration files to maximize detection efficacy while minimizing false positives.
  • Manage the interaction between YAML configurations and runtime engines, focusing on rule loading, protocol decoding, and logging functionalities.
  • Tune IDS/IPS for peak performance, including NIC configuration for Direct Memory Access (DMA), Receive Side Scaling (RSS), and other acceleration techniques.
  • Collaborate with security teams to seamlessly integrate IDS/IPS solutions with SIEM and other security monitoring tools.
  • Address installation and operational challenges specific to IDS/IPS on Red Hat Enterprise Linux, including compatibility issues, kernel module requirements, SE-Linux policies, and performance tuning.
  • Identify and resolve common challenges faced when deploying IDS/IPS in large-scale enterprise settings, such as package dependencies and resource constraints.
  • Document detailed runbooks for Suricata configuration and NIC tuning processes.
  • Keep abreast of the latest software releases, NIC driver updates, and industry best practices for enhancing IDS/IPS performance.

About ENS Solutions, LLC

ENS Solutions, LLC is a leading cybersecurity firm dedicated to safeguarding organizations through innovative security solutions and expert guidance. We pride ourselves on our commitment to excellence and the continuous development of our talented team members, ensuring they are equipped to tackle the challenges of today's cyber landscape.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.