Professional Services Engineer
Be part of the team that defends the networks the world depends onCorelight defends the world's most sensitive networks—from global commerce to national defense—quietly, relentlessly, and with resolve. As cyber threats grow faster and smarter, we serve as the trusted force behind network resilience, putting elite defense within reach.By transforming digital footprints from physical, virtual, and cloud networks into actionable insights, we empower defenders to illuminate blind spots and stay ahead of an evolving threat landscape. Built on open-source innovations and fueled by industry leading agentic AI technology, Corelight helps teams to detect advanced threats and close cases with unprecedented clarity and precision.Do you want to help make the world safe from cyber attack?At Corelight, we believe that the best approach to cybersecurity risk starts with the network. Attackers can evade endpoint detection, firewalls and many other technologies - but they can't avoid leaving digital footprints on the networks they traverse. Built on open-source innovations from Zeek, Suricata and YARA and refined through years of real-world use, Corelight transforms network footprints from physical, virtual and cloud networks into actionable insights. Our customers use these insights to speed incident response and proactively hunt for threats.Job Summary:We are currently seeking a Staff Resident PSE to join our Federal Professional Services team, reporting to the manager of Professional Services. In this role, the main focus is to prepare and validate equipment configurations for new installations, develop content for anomaly and hunt detections, assess the overall health of the Corelight infrastructure at the client's location. You're the ideal candidate if you are a strategic thinker with a strong networking and security background, work well independently, and are results-driven.Key Responsibilities:Help customers improve their cybersecurity posture, with a particular focus on process optimizationHelp investigate incidentsEducate on Zeek Log use, including as it relates to Corelight Suricata alertsDesign and implement technical solutions with ecosystem partners (packet brokers, asset managers, SOAR systems, etc.)Implement queries and dashboards in SIEMs - Splunk, Elastic, Humio, etc.Influence customers and Corelight teams and be seen as a technical expertConduct network-related testing to ensure Corelight products operate correctlyPerform validation testing of Corelight productsProvide ongoing, informal, knowledge transferCollaborate with product management on product features/integrationsWork with back-end tools like Kafka and LogstashDocumenting the process for importing of data (MISP, Intel, etc)Developing custom content for threat hunting use cases as defined by the customerDeveloping playbooks for SOC/IR workflow automation based on Corelight dataAd-hoc (as requested) written summary reports on equipment and security problemsTechnical input to major service outage root cause analysis and corrective action reportsLeading project status meetings and wrap-up/post-mortem meetingsSome on-site work requiredMinimum Qualifications:US Citizen5+ years of experience in cybersecurity (Prior startup experience preferred)Extensive experience with a SOC environmentZeek/Corelight experience is a plusSecurity and/or Networking related certification(s)Demonstrated expertise in Windows/MacOS/Linux/Unix operating systems, IDS/IPS,Network administration, firewall configuration, and strong knowledge of TCP/IPSIEM experience (Splunk required, others a bonus)Scripting in (some of) Zeek, Bash, Python, Perl, Powershell, etc.Strong briefing skills; experience interacting with SES/general officer-level managementFueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is the fastest growing network detection and response platform in the industry. Our customers trust us to protect mission-critical assets in leading enterprises, government, and research institutions worldwide. We are leading the way with AI-assisted workflows, machine learning models, cloud security and SaaS-based solutions to arm defenders with the tools and knowledge they need to disrupt cyber attacks. Our team of passionate innovators are dedicated to solving some of the toughest challenges in cybersecurity, while fostering a collaborative, inclusive, and growth-oriented culture.Corelight is committed to a geographically distributed yet connected employee base with employees working from home and office locations around the world. At Corelight, we take pride in the diversity of our backgrounds and perspectives, and we are committed to fostering an inclusive environment that strengthens our company.We look forward to meeting you. Check us out at www.corelight.comNotice of Pay Transparency:The compensation for this position may vary depending on factors such as your location, skills and experience. Depending on the nature and seniority of the role, a percentage of compensation may come in the form of a commission-based or discretionary bonus. Equity and additional benefits will also be awarded.Compensation Range$124,000—$160,000 USDWhy Join Us?Fueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is one of the fastest growing network detection and response platforms in the industry. Our passionate team thrives in a collaborative, inclusive, and geographically distributed culture. We embrace diverse perspectives, neurodiversity, curiosity and low ego results - fostering an environment where every innovator can solve the toughest challenges in cybersecurity and contribute their best work.We are looking forward to meeting you. Check us out at www.corelight.com