← All verified jobs

Senior Technical Consultant - Network Security Operations

ahead United StatesRemote

See all open roles at ahead

Ghost-risk verdict

Likely real

  • 148 open roles at this company in 30 days (mass-hiring blitz)

How we score ghost risk →

See your fit for this role and apply with a truthfully tailored résumé.

See my fit, free

About the role

Responsibilities:

Design and deploy ExtraHop sensor architectures across physical, virtual, and cloud environments, including sensor placement strategy for TAPs, SPAN ports, and VPC traffic mirroring in AWS and Azure

Configure and design packetstores for retention, query performance, and compliance requirements, including sizing decisions for high-throughput environments

Create custom detections and bundles tailored to client environments, moving beyond out-of-box detections to address specific threats and false-positive patterns

Develop custom dashboards in Reveal(x) using metrics, devices, and applications views, translating wire data into views that map to client SOC workflows and executive reporting needs

Build and maintain REST API integrations between ExtraHop and SIEM, SOAR, ticketing, and CMDB platforms, including custom triggers and open data stream configurations

Conduct network visibility assessments for prospective and existing clients, identifying blind spots in east-west traffic, encrypted traffic decryption coverage, and segmentation gaps

Collaborate with clients to optimize and fine tune their deployment and provide guidance to assist with the optimization of the platform.

Act as a technical resource for troubleshooting and resolving complex Extrahop related issues during and post-implementation.

Contribute to project documentation, ensuring clarity and completeness of Solution Designs and As-Built configurations.

Mentor junior AHEAD consultants, sharing your Extrahop knowledge and fostering their technical development.

Qualifications:

6+ years of hands-on experience with ExtraHop Reveal(x) or Reveal(x) 360 in production environments or similar NDR solutions.

Experience deploying and administering ExtraHop Reveal(x) Enterprise or Reveal(x) 360

Demonstrated experience deploying and tuning ExtraHop sensors, recordstores, and packetstores, including sizing, retention configuration, and performance troubleshooting

Strong grasp of wire data analysis: L2-L7 protocol behavior (TCP/IP, DNS, HTTP, etc), TLS/SSL decryption

Experience building custom detections, bundles, and dashboards beyond default configurations

Proficient in JavaScript and Python scripting for automation, customization, and workflow optimization

Working knowledge of at least one major SIEM (Splunk, XSIAM, Crowdstrike or equivalent) and experience integrating ExtraHop as a data source

Experienced in proactive threat hunting and incident investigations using the MITRE ATT&CK framework, Cyber Kill Chain, NIST Cybersecurity Framework (CSF), and CIS Critical Security Controls to identify adversary TTPs and strengthen detection and response capabilities.

Experience with cloud traffic mirroring (AWS VPC Traffic Mirroring, Azure vTAP, or GCP Packet Mirroring) is a strong plus

Solid Understanding of network security, cloud environments, Identity, Linux, Mac and Windows.

Strong analytical and troubleshooting capabilities.

Effective communication skills with the ability to engage with clients and Team members.

ExtraHop certification (ECS or equivalent) preferred or relevant industry certifications ( CISSP, CYSA, CEH, Security+, Pentest+, OSCP) are a plus.

Stop applying to ghosts.

OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.