Logo
Phase2 Technology

Phase2 Technology is hiring: Suricata Cybersecurity Engineer in Honolulu

Phase2 Technology, Honolulu, HI, United States, 96814

Save Job

Overview

We are seeking an experienced Suricata Engineer to join our cybersecurity team. You will leverage your deep technical expertise in Suricata, particularly in understanding and managing its YAML configuration files, and how these configurations integrate and influence the Suricata Intrusion Detection Systems or Intrusion Prevention Systems (IDS / IPS). You will play a critical role in deploying, tuning, and maintaining Suricata within a complex enterprise IT environment, primarily running on Red Hat Enterprise Linux.

A key focus of this role will be tuning Suricata to operate optimally with network interface cards (NICs), ensuring high-performance packet capture and processing while minimizing packet loss and system resource overhead. Work with us as we secure and protect our nation\'s most sensitive capabilities.

You Have / Responsibilities:

  • Design, deploy, and maintain Suricata IDS / IPS systems across enterprise networks.
  • Develop, review, and optimize Suricata YAML configuration files to ensure optimal detection capabilities and minimal false positives.
  • Understand and manage the interaction between Suricata\'s YAML configuration and its runtime engine, including rule loading, protocol decoding, and logging.
  • Tune Suricata for optimal performance with Napatech NICs, including configuring Direct Memory Access (DMA), RSS queues, interrupt coalescing, and leveraging NIC-specific acceleration features.
  • Collaborate with security teams to integrate Suricata with SIEM and other security monitoring platforms.
  • Troubleshoot installation and operational issues specific to Suricata on Red Hat Enterprise Linux, addressing compatibility, kernel module requirements, SELinux policies, and performance tuning.
  • Identify and mitigate common pitfalls encountered when deploying Suricata in large-scale enterprise environments, including package dependencies, system resource constraints, and NIC driver or configuration issues.
  • Provide detailed documentation and runbooks for Suricata configuration, tuning NICs, and deployment processes.
  • Stay up-to-date with Suricata releases, NIC driver updates, and community best practices for network interface tuning and IDS / IPS performance enhancement.

What You\'ll Work On:

(Content above summarized under Overview and You Have / Responsibilities.)

Nice If You Have:

  • Experience integrating Suricata with Splunk, or other SIEM solutions.
  • Experience with common Linux operating systems, including Oracle or CentOS.
  • Experience with other industry-standard IDS / IPS solutions and related technologies.
  • Knowledge of containerized deployments of Suricata like Docker or Kubernetes in enterprise environments.
  • Knowledge of network protocols, intrusion detection methodologies, and security event correlation.
  • Ability to be a self-starter, work without considerable direction, and collaborate with a team.
  • Excellent verbal and written communication skills for coordinating efforts and customer relations.

Clearance:

Active TS/SCI clearance; willingness to take a polygraph exam. Applicants may be subject to a security investigation and must meet eligibility requirements for access to classified information.

Qualifications / Education:

  • Associate\'s degree and 5+ years of experience supporting IT projects and activities, Bachelor\'s degree and 3+ years, Master\'s degree and 1+ years, or 7+ years of experience in lieu of a degree.
  • DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification.
  • Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification within 30 days of start date.

Compensation:

At Booz Allen, we celebrate your contributions, provide opportunities and choices, and support your total well-being. The projected compensation range for this position is $77,600.00 to $176,000.00 (annualized USD). This posting will close within 90 days from the Posting Date.

Identity Statement:

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Work Model: Our people-first culture prioritizes flexibility and collaboration, whether in person or remotely.

  • If this position is listed as remote or hybrid, you\'ll periodically work from a Booz Allen or client site facility.
  • If this position is listed as onsite, you\'ll work with colleagues and clients in person, as needed for the specific role.

Commitment to Non-Discrimination:

All qualified applicants will receive consideration for employment without regard to disability, veteran status, or any other status protected by applicable law.

We are directing you to the original job posting. Please apply directly for this job at the employer\'s website.

#J-18808-Ljbffr