Senior Technical Consultant - Network Security Operations
Likely real
- 148 open roles at this company in 30 days (mass-hiring blitz)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
Responsibilities:
Design and deploy ExtraHop sensor architectures across physical, virtual, and cloud environments, including sensor placement strategy for TAPs, SPAN ports, and VPC traffic mirroring in AWS and Azure
Configure and design packetstores for retention, query performance, and compliance requirements, including sizing decisions for high-throughput environments
Create custom detections and bundles tailored to client environments, moving beyond out-of-box detections to address specific threats and false-positive patterns
Develop custom dashboards in Reveal(x) using metrics, devices, and applications views, translating wire data into views that map to client SOC workflows and executive reporting needs
Build and maintain REST API integrations between ExtraHop and SIEM, SOAR, ticketing, and CMDB platforms, including custom triggers and open data stream configurations
Conduct network visibility assessments for prospective and existing clients, identifying blind spots in east-west traffic, encrypted traffic decryption coverage, and segmentation gaps
Collaborate with clients to optimize and fine tune their deployment and provide guidance to assist with the optimization of the platform.
Act as a technical resource for troubleshooting and resolving complex Extrahop related issues during and post-implementation.
Contribute to project documentation, ensuring clarity and completeness of Solution Designs and As-Built configurations.
Mentor junior AHEAD consultants, sharing your Extrahop knowledge and fostering their technical development.
Qualifications:
6+ years of hands-on experience with ExtraHop Reveal(x) or Reveal(x) 360 in production environments or similar NDR solutions.
Experience deploying and administering ExtraHop Reveal(x) Enterprise or Reveal(x) 360
Demonstrated experience deploying and tuning ExtraHop sensors, recordstores, and packetstores, including sizing, retention configuration, and performance troubleshooting
Strong grasp of wire data analysis: L2-L7 protocol behavior (TCP/IP, DNS, HTTP, etc), TLS/SSL decryption
Experience building custom detections, bundles, and dashboards beyond default configurations
Proficient in JavaScript and Python scripting for automation, customization, and workflow optimization
Working knowledge of at least one major SIEM (Splunk, XSIAM, Crowdstrike or equivalent) and experience integrating ExtraHop as a data source
Experienced in proactive threat hunting and incident investigations using the MITRE ATT&CK framework, Cyber Kill Chain, NIST Cybersecurity Framework (CSF), and CIS Critical Security Controls to identify adversary TTPs and strengthen detection and response capabilities.
Experience with cloud traffic mirroring (AWS VPC Traffic Mirroring, Azure vTAP, or GCP Packet Mirroring) is a strong plus
Solid Understanding of network security, cloud environments, Identity, Linux, Mac and Windows.
Strong analytical and troubleshooting capabilities.
Effective communication skills with the ability to engage with clients and Team members.
ExtraHop certification (ECS or equivalent) preferred or relevant industry certifications ( CISSP, CYSA, CEH, Security+, Pentest+, OSCP) are a plus.
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot