Full-Time

Professional Services Engineer

Ts/Sci, FS Poly

Posted on 8/19/2024

Corelight

Corelight

201-500 employees

Provides network detection and response technology

Compensation Overview

$180k - $250kAnnually

+ Commission + Bonus + Equity + Additional Benefits

Senior, Expert

Washington, DC, USA + 2 more

More locations: Virginia, USA | Baltimore, MD, USA

Job locations include Baltimore, DC, and Virginia.

US Top Secret Clearance Required

Category
Cybersecurity
IT & Security
Required Skills
TCP/IP
PowerShell
Bash
Python
Communications
Perl
Splunk
Linux/Unix
Requirements
  • 5+ years experience in a security professional services role
  • Bachelor’s degree in a technical field (or equivalent experience)
  • Strong background in cybersecurity
  • Solid verbal and written communication skills
  • Enjoy designing novel solutions
  • Understand how to scope and describe a services engagement
  • Robust problem-solving skills, the ability to learn from doing, personal accountability, and a positive and professional attitude
  • Zeek log experience and log analysis skills are required
  • Network administration, firewall configuration, and strong knowledge of TCP/IP
  • Windows/MacOS/Linux/Unix administration experience
  • Scripting in (some of) Zeek, Bash, Python, Perl, Powershell, etc.
  • SIEM experience (Splunk required, others a bonus)
  • Travel up to 50% post-COVID; some travel now, depending on customer comfort levels
  • TS/SCI w/ Full Poly
Responsibilities
  • Help customers improve their cybersecurity posture, with a particular focus on process optimization
  • Help investigate incidents
  • Educate on Zeek Log use, including as it relates to Corelight Suricata alerts
  • Design and implement technical solutions with ecosystem partners (packet brokers, asset managers, SOAR systems, etc.)
  • Implement queries and dashboards in SIEMs - Splunk, Elastic, Humio, etc.
  • Influence customers and Corelight teams and be seen as a technical expert
  • Collaborate with product management on product features/integrations
  • Work with back-end tools like Kafka and Logstash

Corelight provides network detection and response (NDR) technology aimed at improving cybersecurity for businesses. Their products enhance network visibility, speed up investigations, and bolster defenses against cyber threats. Corelight's Open NDR technology is utilized by cybersecurity firms like Mandiant and CrowdStrike, allowing these companies to offer services such as incident response and network security monitoring. Corelight's offerings include the Open NDR Platform and the Cloud Sensor for AWS, which help organizations detect threats and respond more effectively, especially in cloud environments. Unlike many competitors, Corelight focuses on providing tools that integrate seamlessly with existing cybersecurity solutions, enhancing their capabilities. The primary goal of Corelight is to empower businesses and cybersecurity firms with advanced tools that improve their ability to detect and respond to cyber threats, ultimately strengthening their overall security posture.

Company Size

201-500

Company Stage

Series E

Total Funding

$300.8M

Headquarters

San Francisco, California

Founded

2013

Simplify Jobs

Simplify's Take

What believers are saying

  • Corelight raised $150M in Series E funding, fueling product expansion and market reach.
  • Inclusion in Fortune Cyber 60 list boosts Corelight's visibility and industry credibility.
  • Integration with SentinelOne enhances SOC transformation, improving threat detection and response.

What critics are saying

  • Increased competition from Bugcrowd could challenge Corelight's market position.
  • Departure of key sales executive Rick Beattie may impact sales momentum.
  • Over-reliance on partnerships with SentinelOne and CrowdStrike may limit independent innovation.

What makes Corelight unique

  • Corelight leverages open-source frameworks like Bro for real-time network traffic analysis.
  • Their Open NDR technology enhances network visibility and accelerates threat investigations.
  • Corelight's partnerships with firms like CrowdStrike boost their cybersecurity solution offerings.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

0%

2 year growth

2%
MSSP Alert
Nov 14th, 2024
MSSP Market Update: CRA Honors Women in IT Security

Government grant for cyber protection - Veracity Trust Network has been awarded the Cybersecurity Co-Innovation and Development Fund (CCDF) CyberCall grant of $1 million Singapore dollars by the Cyber Security Agency Singapore (CSA).

PR Newswire
Nov 10th, 2024
Corelight Included On Fortune Cyber 60 List Of Fastest-Growing Private Cybersecurity Companies

SAN FRANCISCO, Oct. 30, 2024 /PRNewswire/ -- Corelight, the leader in open network detection and response (NDR) solutions, today announced it has been named to the Fortune Cyber 60 list, presented by Lightspeed, a listing of the most important venture-backed startups that offer enterprise-grade cybersecurity solutions. Corelight was added to the growth stage companies category and is the only company providing NDR solutions included on the list. "Corelight is on this list because defenders need insight across the kill chain," said Brian Dye, Corelight CEO. "Attackers can't hide from the network. Corelight mines the network to provide customers with ground truth evidence detailing all activity traversing the network to identify and disrupt increasingly sophisticated threats."

Solutions Review
Nov 1st, 2024
Endpoint Security and Network Monitoring News for the Week of November 1st: XM Cyber, Fortinet, SecureCyber, and More

Bugcrowd, a crowdsource cybersecurity solution provider, has received $50 million in growth capital from Silicon Valley Bank (SVB), a division of First Citizens Bank.

Security Info Watch
Oct 15th, 2024
Corelight integrates SentinelOne Singularity data to accelerate SOC transformation

Corelight today announced a partnership with SentinelOne to provide real-time enrichment of Corelight logs.

PR Newswire
May 7th, 2024
Corelight Unveils Real-Time Data Enrichment For Crowdstrike Falcon(R) Next-Gen Siem

Corelight's industry-leading Open NDR solution delivers pre-correlated detections and out-of-the-box workflows to accelerate security operationsSAN FRANCISCO, May 7, 2024 /PRNewswire/ -- Corelight , the leader in open network detection and response (NDR), today unveiled an out-of-the-box connector to ingest real-time and enriched network data into CrowdStrike Falcon® Next-Gen SIEM. This native integration unifies Corelight third-party detections and data with CrowdStrike's security and threat intelligence data to drive AI-powered SOC transformation and help customers disrupt future attacks."Security operations teams need the best evidence to find and disrupt attacks," said Brian Dye, CEO of Corelight. "The combination of Corelight's network insight and CrowdStrike's Next-Gen SIEM allows defenders to minimize attacker dwell time and close out cases faster."Native integration between the two platforms, combined with Corelight's open approach to detections and evidence, delivers true ground truth for next-gen SIEM workflows. By leveraging open source technology such as Zeek and Suricata , organizations can tap into over two decades of insights from elite defenders and achieve 95% faster average response time. Falcon Next-Gen SIEM delivers more capabilities and up to 150x faster search performance than legacy SIEMs and solutions positioned as SIEM alternatives, at an 80% lower total cost of ownership.The new integration leverages CrowdStrike platform data, threat intelligence, AI, and workflow automation in Falcon Next-Gen SIEM, helping security teams orchestrate defenses, enable risk-based alert triage to prioritize exploits against known vulnerable hosts, and reduce asset inventory gaps through the identification of unmanaged endpoints on the network. Together, this enables customers to:Find and investigate evasive threats with AI-powered detections and full contextual insights from Corelight directly within the Falcon platform;Accelerate deployment with over 20 native dashboards, 25 correlation rules, and 60 queries designed specifically for Corelight third-party data;Unify SOC data and consolidate legacy network security solutions to improve operational efficiency"Today's SOC needs to operate faster than the adversary

INACTIVE