5+ years of hands-on experience in on-premise network engineering or cybersecurity platforms.
Experience deploying NDR platforms, preferably VectraAI, in data center environments.
Strong knowledge of TCP/IP, DNS, TLS, HTTP/S, and packet capture.
Familiarity with packet analytics tools like Zeek, Suricata, or Arkime.
Proficiency in Linux engineering and system operations.
Active TS/SCI clearance with willingness to take a polygraph exam.
Ability to obtain relevant cybersecurity certifications within 30 days of start date.
Responsibilities
Deploy and maintain VectraAI sensors and metadata pipelines in on-premise networks.
Integrate VectraAI with SIEM/SOAR/EDR and other analysis tools.
Engineer sensor placement for optimal visibility and data capture.
Manage routing, VLANs, and metadata transformation processes.
Support secure configurations aligned with operational guidance.
Build monitoring dashboards and performance tuning workflows.
Coordinate with operations teams for reliable telemetry and threat detection.
Benefits
Opportunity to work in a high-security environment with cutting-edge technology.
Hands-on experience with advanced network detection and response tools.
Collaboration with operations teams to enhance cybersecurity measures.
Potential for professional growth through certification opportunities.
Full Job Description
REQUIRES AN ACTIVE / EXISTING TS/SCI WITH CI POLY - NO REMOTE WORK
Location: Reston, VA OR Washington, DC
Funding Status: Contingent
Position Description:
We are seeking an VectraAI Integration Engineer to deploy, tune, and sustain VectraAI Detect sensors and Recall pipelines in physical data centers, air-gapped networks, and enterprise on-premise environments. This role focuses on network metadata, packet-level telemetry, routing, sensor placement, and integration with on-premise SOC tooling.
Job Responsibilities:
Deploy and sustain VectraAI sensors, collectors, and metadata pipelines in on-premise networks.
Integrate VectraAI with on-premise SIEM/SOAR/EDR, packet brokers, and analysis tools.
Engineer physical and virtual sensor placement including SPANs, taps, packet brokers, and east-west segmentation visibility.
Manage routing, VLANs, packet capture, and metadata transformation.
Support STIG-aligned configurations and secure baselines consistent with your on-prem operating guidance
Build monitoring dashboards, sensor health checks, and performance tuning workflows.
Coordinate with operations teams to ensure reliable on-prem telemetry ingestion and threat detection fidelity.
Basic Qualifications:
5+ years of hands-on experience with on-premise network engineering or cybersecurity platforms.
Experience deploying NDR platforms (VectraAI preferred) in physical/virtual data center environments.
Strong knowledge of TCP/IP, DNS, TLS, HTTP/S, NetFlow/IPFIX, packet capture, and metadata pipelines.
Experience with Zeek, Suricata, Arkime, Endace, or similar packet analytics tools.
Experience with hardened OS builds, secure enclaves, access controls, and network segmentation.
Proficiency with Linux engineering and system operations.
Active TS/SCI clearance; willingness to take a polygraph exam
HS diploma or GED and 7+ years of experience with supporting IT projects and activities, Associate's degree and 5+ years of experience supporting IT projects and activities, Bachelor's degree and 3+ years of experience supporting IT projects and activities, or Master's degree and 1+ years of experience supporting IT projects and activities.
Ability to obtain a DoD 8570 IAT Level III Certification such as SecurityX (formerly CASP+), CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP certification within 30 days of start date
Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification (CSSP-IS), including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date
Additional Qualifications:
Experience integrating NDR telemetry into SOC pipelines in secure on-prem environments.
Experience in environments with strict access controls or Zero Trust requirements
Familiarity with virtualization platforms, physical rack deployments, and packet brokers.
Experience with incident response and threat hunting based on raw network metadata.