Full-Time

Senior Sales Engineer

Posted on 7/30/2025

Corelight

Corelight

201-500 employees

Network detection and response technology provider

Compensation Overview

$190k - $270k/yr

+ Commission + Bonus + Equity + Additional Benefits

United States

Hybrid

Candidate must be willing to travel approximately 50% of the time for in-person engagements.

Category
Sales & Solution Engineering (1)
Requirements
  • Deep understanding of network security
  • Ability to communicate complex technical concepts clearly
  • Experience collaborating with sales teams
  • Experience engaging with customers
Responsibilities
  • Collaborate closely with sales teams to understand customer needs and provide technical guidance and demonstrations
  • Act as a trusted advisor, effectively communicating Corelight’s value propositions to both technical and business stakeholders
  • Customize and deliver compelling product demos and Proof of Value (POV) engagements that showcase the strength of our solutions
  • Engage with customers to understand their challenges, architect solutions, and drive business outcomes
  • Partner with our engineering, product, and customer success teams to ensure smooth delivery and feedback loops
  • Expect to travel approximately 50% of the time to meet customers and support in-person engagements
Desired Qualifications
  • Problem-solver with a knack for communicating complex technical concepts
  • Passionate about learning and evolving with the latest in security technology
  • Thrives in a collaborative, low-ego environment
  • Understands the importance of teamwork and contributes to a supportive culture

Corelight provides network detection and response (NDR) technology to improve cybersecurity. It collects and analyzes network data through the Open NDR Platform and the Cloud Sensor for AWS, giving customers visibility, aiding threat hunting, and speeding up incident response across on-premise and cloud environments. What sets Corelight apart is its open, partner-friendly approach that lets other security vendors build analytics on top of its technology, with interoperability across major vendors and a cloud-native option for AWS. The goal is to strengthen cyber defense by delivering scalable network visibility and fast detection, growing adoption through direct sales and partnerships that integrate Corelight’s Open NDR technology into other offerings.

Company Size

201-500

Company Stage

Series E

Total Funding

$309.2M

Headquarters

San Francisco, California

Founded

2013

Simplify Jobs

Simplify's Take

What believers are saying

  • Hatem Naguib and Jack Huffard appointments accelerate expansion against AI-driven threats.
  • CrowdStrike Falcon Next-Gen SIEM connector delivers 95% faster responses using Zeek data.
  • SentinelOne integration enriches logs for real-time SOC transformation and investigations.

What critics are saying

  • Vectra AI displaces Zeek-dependent Corelight with superior AI anomaly detection in 12-24 months.
  • CrowdStrike integration commoditizes Corelight as data feeder, eroding value in 6-12 months.
  • Zeek community Q1 2026 release enables free Elastic NDR, obliterating subscriptions in 12-18 months.

What makes Corelight unique

  • Corelight's Open NDR Platform leverages Zeek to extract 400+ fields across 35+ protocols in real time.
  • Agentic Triage uses expert playbooks and GenAI for 10x faster SOC triage with transparent evidence.
  • ML models detect encrypted tunneling, VPN anomalies, and credential theft without decryption.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Work Hours

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

4%

2 year growth

2%
Help Net Security
Mar 18th, 2026
Corelight's Agentic Triage turns SOC alerts into evidence-backed investigations.

Corelight's Agentic Triage turns SOC alerts into evidence-backed investigations. Corelight has introduced a new set of agentic AI capabilities aimed at helping security operations centers (SOCs) cut down on repetitive, time-consuming tasks. The updates are designed to boost analyst efficiency, speed up response times, and build trust through greater transparency. The release includes Agentic Triage to streamline SOC workflows, a new suite of machine learning models that turn encrypted traffic blind spots into actionable evidence, and expanded integrations "By pairing the industry's highest-fidelity network telemetry from Corelight with an expert-governed AI agent, we are giving security teams the evidence they need to trust, verify, and act on AI-generated insights," said Vijit Nair, Corelight vice president of product. "Only Corelight delivers true agentic AI triage in NDR, uniquely transforming overwhelming alert queues into verified, defensible investigations by applying expert playbooks to industry-leading network evidence with AI reasoning, drastically reducing time-to-triage and equipping analysts with definitive answers." Accelerating SOC workflow through agentic intelligence. SOCs are under pressure as adversaries actively leverage generative AI to automate reconnaissance and accelerate attacks, while most triage processes remain manual, repetitive, and highly variable across analysts. Corelight Agentic Triage is a category-first automated investigation capability that helps security teams move from high-volume alert noise to evidence-backed containment, making triage up to 10x faster. Powered by a modern GenAI agent architecture and driven by expert-written investigative playbooks, Agentic Triage automatically investigates the highest-risk entities in a customer's environment on a daily basis. Instead of requiring analysts to manually review hundreds of individual alerts, the Corelight Lux agent consolidates signals into entity-centric investigations, applies structured investigative logic, and delivers a single, evidence-backed triage verdict, complete with transparent reasoning a human analyst can inspect and verify. Unlike proprietary systems that hide the details used to inform AI decision-making, Corelight Agentic Triage exposes every playbook step, every query run, and every piece of evidence used to reach a conclusion. This "show-your-work" approach is purpose-built for enterprise SOCs that require AI to be accountable, reviewable, and defensible during audits and incident response reviews. Connecting to and empowering the ai-enabled ecosystem. Once analysts have identified the highest-risk entities and are ready to take action, they want to contain threats immediately without having to pivot to another system. Corelight ingests real-time identity data to enrich and complement the network evidence and correlate insights about problematic entities connected to the network. Now that analysts can connect the "who" to the "what" that is happening on the network, they can use the integrations with Microsoft Azure AD/Entra and CrowdStrike to trigger one-click actions such as universal logout and password resets without pivoting to a separate tool. This ability to take response actions directly on compromised identities builds on Corelight's ability to directly quarantine endpoints and trigger firewall block actions. In addition, Corelight has released a new integration with CrowdStrike's Charlotte AI and Agentic Response Collaboration, seamlessly working with other AI agents across the security stack to maximize the value of network data, providing critical context for investigations no matter where they occur. The integration creates a CrowdStike Fusion workflow that allows Charlotte AI to automatically pull Corelight ground truth data to help an analyst resolve an alert by validating host behavior against network reality. "The question facing every CISO today is not whether to adopt AI in the SOC - but rather how quickly and how comprehensively," said Andrew Braunberg, principal analyst at Omdia. "Adding to the urgency is the weaponization of generative models by adversaries to automate reconnaissance, accelerate attacks, and evade detection. Defenders need AI that can accelerate response, and critically, that shows its work. To build trust in these solutions, explainability isn't a nice-to-have; it's a requirement, particularly in regulated environments." Detecting multi-stage intrusions with advanced ML everywhere. Indisputable evidence and robust detections are the foundation for any AI capability to be successfully integrated into today's modern SOC. To support the advancement of AI in the SOC, Corelight is also introducing an expansion of its advanced machine learning and behavioral detections with a new suite of statistical models designed to detect evasive, post-exploitation techniques, including tunneling anomalies and VPN anomalies, without requiring decryption. Sophisticated threat actors are looking for the dark corners of target networks to exploit, increasingly tunneling attacks in encrypted sessions to evade detection and hide their true intent. By analyzing the statistical "shape" and behavioral metadata of traffic, Corelight is able to transform encrypted blind spots into high-fidelity evidence. This allows security teams to better identify covert command and control (C2) channels and lateral movement, even in environments where traditional inspection is impossible. Corelight's new ML models detect evasive threats that traditional signatures miss by analyzing behavioral patterns across the network, flagging unauthorized VPNs, identifying uncommon tunneling activity at the subnet level, and catching credential theft techniques like DCSync and NTDS.dit dumps before attackers can pivot. The platform has also expanded its brute force detection surface, correlating both low-and-slow and high-volume credential attacks across critical vectors including Kerberos, RDP, SMB, and SSH. Together, these models give security teams high-fidelity visibility into post-exploitation activity without requiring decryption. More about

PR Newswire
Mar 18th, 2026
Corelight launches agentic AI suite to accelerate SOC triage 10x faster with transparent evidence

Corelight has launched Agentic Triage, what it calls category-first agentic AI capabilities for security operations centres. The network detection and response company claims the system can make triage up to 10 times faster by automating repetitive investigative tasks. The platform uses AI agents powered by expert-written playbooks to automatically investigate high-risk entities, consolidating alerts into single, evidence-backed verdicts. Unlike proprietary systems, Corelight exposes every playbook step and piece of evidence used to reach conclusions, designed for enterprise environments requiring accountable AI. Corelight has also released integrations with Microsoft Azure AD/Entra and CrowdStrike, allowing analysts to trigger one-click containment actions like universal logout directly from the platform. Additionally, the company introduced new machine learning models to detect evasive techniques in encrypted traffic without requiring decryption.

PR Newswire
Oct 15th, 2025
Corelight Named a Leader in Network Analysis and Visibility Solutions, Q4 2025 report by Independent Research Firm

Corelight named a Leader in Network Analysis and Visibility Solutions, Q4 2025 report by independent research firm. News provided by. Oct 15, 2025, 12:00 ET SAN FRANCISCO, Oct. 15, 2025 /PRNewswire/ - Corelight, the fastest-growing leader in network detection and response (NDR), today announced it has been named a Leader in The Forrester Wave(TM): Network Analysis and Visibility Solutions, Q4 2025. The report evaluates the 12 most significant providers in the market, assessing them on their current offering, strategy, and customer feedback. According to the evaluation, Corelight's Open NDR Platform received the highest score possible in the deployment and administration criteria, which Corelight believes reflects the solution's flexible deployment options and ease of management. The company also received the highest scores possible in the protocol coverage criterion. "We believe this report by Forrester, our fifth major industry recognition this year, validates our data-centric approach to strengthening attack surface discovery and empowering security operations teams with the deep network context they need to detect and respond to increasingly sophisticated and persistent threats," said Brian Dye, Corelight CEO. "We see this as an acknowledgement of not just what we do today, but also the growth-driven investment against our vision, innovation, and long-term roadmap, earning us the highest possible score in the vision criterion." Corelight's Key Strengths Recognized by Forrester In Corelight's vendor profile, Forrester cited the following: * Data-Centric Innovation: Forrester noted that Corelight "positions its solution as a network context force multiplier, strengthening attack surface discovery/prioritization and the future SOC." The report states that the company's innovation approach "aligns with a data-centric strategy tailored to its target users" and is "backed by substantial R&D investment." * Comprehensive Detection Approach: According to the report, "Corelight minimizes reliance on a single approach to threat detection by relying on multiple mechanisms tailored to specific use cases." * Open-Source Foundation: Forrester recognized Corelight's roots in the open-source community, noting the company's "advantage of access to the broader Zeek community." Corelight's Open NDR platform provides organizations with deep network visibility through advanced traffic analysis, behavioral analytics, and threat intelligence integration. The solution enables security teams to detect lateral movement, insider threats, and advanced persistent threats that often evade perimeter defenses. The platform's key differentiators include: * Industry-leading network evidence - Rich, actionable evidence with full context helps defenders understand attack vectors, spot lateral movement and reconstruct attacker behaviors with clarity and certainty. * Proven multi-layered detection strategy - Fusing machine learning (ML), behavioral analytics, curated signatures, and threat intelligence provides defenders with prioritized, aggregated alerts based on risk and expert-tuned detections. * Open source advantage - Built on an open-source foundation that is used by the world's elite defenders, customers benefit from curated community content contributions that help detect emerging threats faster. * AI driven acceleration - Integration of large language models and ML-based detection algorithms enables evidence-backed summaries, guided triage, and analyst-ready workflows to accelerate investigations without locking customers into proprietary platforms. * Flexible deployment options - With a strong and growing technical ecosystem, Corelight Open NDR can be seamlessly deployed in a wide range of architectures from cloud to on-premises to hybrid with integrations across the security stack. * Leading customer support - An expert team of security professionals provides support and advice to customers from implementation and integration through the entire lifecycle of the customer relationship. The Forrester Wave(TM): Network Analysis and Visibility Solutions, Q4 2025 evaluated vendors based on current offering, strategy, and market presence, with emphasis on decryption capabilities, API-first integration strategies, and analyst experience. To learn more about Corelight's positioning as a Leader, visit https://corelight.com/blog/corelight-named-a-leader-in-2025-nav-solutions-by-forrester. About Corelight Corelight transforms network and cloud activity into evidence that security teams use to proactively hunt for threats, accelerate response to incidents, gain complete network visibility, and create powerful analytics. Corelight's customers include Global 2000 companies, major government agencies, and large research universities. Based in San Francisco, Corelight is an open-core security company founded by the creators of Zeek(R), the widely used open source network security technology. For more information, visit www.corelight.com. Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. For more information, read about Forrester's objectivity here. SOURCE Corelight

Cache Valley Daily
May 29th, 2025
Corelight Recognized as a Leader in the Inaugural Magic Quadrant(TM) for Network Detection and Response

SAN FRANCISCO, May 29, 2025 /PRNewswire/ - Corelight, the fastest-growing provider of network detection and response (NDR) solutions, today announced it has been named a Leader in the Gartner(R) Magic Quadrant(TM) for Network Detection and Response[[1]].

MSSP Alert
Nov 14th, 2024
MSSP Market Update: CRA Honors Women in IT Security

Government grant for cyber protection - Veracity Trust Network has been awarded the Cybersecurity Co-Innovation and Development Fund (CCDF) CyberCall grant of $1 million Singapore dollars by the Cyber Security Agency Singapore (CSA).

INACTIVE