Full Job Description
This role supports Vectra's Attack Signal Production Group, which builds core threat detection technology using AI and other methods for networks, cloud, and hybrid environments.
Key Responsibilities
• Implement and maintain architecture
• Analyze network traffic to identify and document threat patterns.
• Develop and maintain network-based security signatures (e.g., in Suricata).
• Use offensive security tools and techniques to simulate attacks and generate sample network traffic for testing detections.
• Collaborate with data scientists and security researchers to support AI-driven detection efforts and improve accuracy.
• Continuously monitor and tune the effectiveness of network detections, adjusting as needed.
• Contribute to threat hunting by identifying new attacker tactics, techniques, and procedures (TTPs).
• Participate in incident response activities when required.
Required Skills
• Active TS/SCI Clearance
• Strong background in network traffic analysis and threat detection.
• Hands-on experience with tools like Suricata for signature-based detection.
• Knowledge of offensive security (e.g., simulating attacks).
• Familiarity with MITRE ATT&CK framework and real-world attacker behaviors (lateral movement, C2, etc.).
• Collaboration skills for working with data scientists and researchers.
• Understanding of networking protocols, OSI layers, and security concepts (often L3-L7).
Education/Certifications (often preferred or optional):
• Relevant experience in cybersecurity (typically several years).
• Certifications such as OSCP, GCIA, GCDA, GSEC, or similar (optional but valued).