Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IDS/IPS Cyber Security Engineer, Mid

DAn Solutions Inc

REQUIRES AN EXISTING/ACTIVE TS/SCI WITH CI POLYGRAPH - NO REMOTE WORK, MUST WORK ON SITE

Job Description:

We are seeking an experienced Network Intrusion Detection Engineer to join our cybersecurity team. The ideal candidate must possess strong Linux engineering expertise with experience managing YAML configuration files, and how these configurations integrate and influence the Intrusion Detection Systems/Intrusion Prevention Systems (IDS/IPS). Highly qualified candidates will have hands-on engineering and O&M experience with Suricata and/or other network-based IDS capabilities such as Snort, VectraAI, Corelight, etc. You will play a critical role in deploying, tuning, and maintaining the IDS within a complex enterprise IT environment, primarily running on Red Hat Enterprise Linux.

What You'll Work On:

· Designing, deploying, and maintaining IDS/IPS systems across a large enterprise with multiple networks.

· Developing, reviewing, and optimizing YAML configuration files to ensure optimal detection capabilities and minimal false positives.

· Understanding and managing the interaction between YAML configuration and its runtime engine, including rule loading, protocol decoding, and logging.

· Tuning IDS/IPS for optimal performance with NICs, including configuring Direct Memory Access (DMA), RSS queues, interrupt coalescing, and leveraging any NIC-specific acceleration features.

· Collaborating with security teams to integrate IDS/IPS with SIEM and other security monitoring platforms.

· Troubleshooting installation and operational issues specific to IDS/IPS on Red Hat Enterprise Linux, addressing compatibility, kernel module requirements, SE-Linux policies, and performance tuning.

· Identifying and mitigating common pitfalls encountered when deploying IDS/IPS in large-scale enterprise environments, including package dependencies, system resource constraints, and NIC driver/configuration issues.

· Provide detailed documentation and runbooks for Suricata configuration, tuning NICs, and deployment processes.

· Staying current with Platform IDS/IPS Software releases, NIC driver updates, and community best practices for network interface tuning and IDS/IPS performance enhancement.

Basic Qualifications:

· Proven experience working with Snort, Suricata, Corelight or other network IDS/IPS systems, including hands-on management of its YAML configuration files.

· Strong knowledge of configuration structure, syntax, and how it controls detection rules, logging, and output modules.

· Extensive experience administering Red Hat Enterprise Linux (RHEL) systems, including package management (yum/dnf), kernel module management, SE-Linux configuration, and system optimization via Unix CLI and other remote shell access vectors (puTTY, SSH, etc.)

· Hands-on experience tuning Suricata for high-performance packet capture with Napatech NICs or similar advanced network interface cards.

· Familiarity with NIC-specific features such as DMA, Receive Side Scaling (RSS), interrupt moderation, and offload capabilities, and how to configure them for Suricata.

· Experience troubleshooting Suricata's interaction with NIC drivers and kernel modules in an enterprise environment.

· TS/SCI clearance with the ability to obtain a counter-intelligence polygraph.

· Associate's degree and 5+ years of experience supporting IT projects and activities or Bachelor's degree and 3+ years of experience supporting IT projects and activities or Master's degree and 1+ years of experience supporting IT projects and activities. Years of experience may be accepted in lieu of degree.

· DoD 8570 IAT Level II Certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification.

· Ability to obtain a DoD 8570 Cyber Security Service Provider - Infrastructure Support Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 60 days of start date.

Additional Qualifications:

· Experience with scripting languages (Bash, Python, YAML/Ansible, etc.) to automate Suricata configuration and deployment tasks.

· Proficient understanding of network protocols, intrusion detection methodologies, and security event correlation.

· Experience integrating Suricata with Splunk, or other SIEM solutions.

· Knowledge of containerized deployments of Suricata (Docker/Kubernetes) in enterprise environments.

· Detection and Response (NDR) solutions, including Trellix/FireEye, Corelight, Endace, Vectra AI, Dark Trace, Cisco Security Network Analytics, Open XDR, Fortinet FortiNDR, Trend Vision, etc.

· Ability to be a self-starter, work without considerable direction, and work with a team.

· Possession of excellent verbal and written communication skills, including client briefings and coordinating efforts

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the IDS/IPS Cyber Security Engineer, Mid in Washington DC vacancy
  •  ...We are looking to hire a Mid-Level Cyber Defense Analyst to support a full range of cyber security services on a long-term contract in...  ...and routing protocols (e.g. TCP/IP), services (e.g., web, mail, DNS...  ...and intrusion detection system [IDS] logs) to identify possible... 
    Suggested
    Long term contract
    Permanent employment
    Full time
    Immediate start
    Shift work

    Redhawk Federal Solutions LLC

    Suitland, MD
    4 days ago
  • $160.33k - $181.7k

     ...Requisition ID: 2489 Standard Title: Senior Cyber Security Engineer Required Security Clearance: Top Secret/SCI Location: Bethesda, MD Work Type...  ...Experience with middleware/web technologies, databases, TCP/IP networking, and CI/CD platforms. Familiarity... 
    Suggested
    Hourly pay
    Contract work
    Temporary work
    Immediate start
    Flexible hours
    Shift work

    Base2 Solutions

    Bethesda, MD
    4 days ago
  •  ...Forescout Cyber Security Engineer, Mid What You'll Work On: · Develop relationships quickly and easily with other teams, communicating the...  ...security upgrades · Experience architecting and designing IP networks, including developing and documenting network topologies... 
    Suggested
    Contract work

    Cinteot Inc.

    Washington DC
    a month ago
  •  ...Job Description Job Title: Cyber Security Engineer Company: Client of BizFirst Employment Type: Full-time Permanent W-2 Employee...  ...with security tools and technologies such as firewalls, IDS/IPS, SIEM, antivirus, and endpoint protection. • Vulnerability... 
    Suggested
    Permanent employment
    Full time
    2 days per week
    3 days per week

    Biz First

    Alexandria, VA
    1 day ago
  •  ...clients to fulfill staffing needs in IT, Security, Business Support, and Operations....  ...and networks from potential cyber-attacks. The Cyber Security Engineer must display an excellent understanding...  ...VPNs, Data Loss Prevention (DPS), IDS/IPS, Web-Proxy, Security tools, and... 
    Suggested
    For subcontractor
    Local area

    Red Key Solutions

    Bethesda, MD
    9 hours ago
  •  ...Senior Cyber Security Engineer Our esteemed Randstad client in Washington, D.C. is seeking a Senior Cyber Security Engineer for a 12+ month...  ...Data Classification, Access Controls, Network Security (FW, IDS, IPS, etc.), and Web Application Firewall Security.... 
    Contract work

    Samprasoft

    Washington DC
    5 days ago
  •  ...Description Senior Cybersecurity Engineer Role Summary The Senior Cybersecurity...  ...'s technology environment remains secure, compliant, and resilient against emerging...  ...remediation actions. Utilize SIEM, EDR, and IDS/IPS platforms such as CrowdStrike and... 
    Full time
    Local area

    Howard University Hospital

    Washington DC
    3 days ago
  •  ...firewalls ~ Hands-on experience with operations and security in Amazon Web Services (AWS) and Microsoft Azure with Palo...  ...and ability to investigate Intrusion Detection System (IDS) / Intrusion Prevention Systems (IPS) alerts ~ Familiarity with Payment Card Industry (PCI... 
    Work at office
    Remote work

    InstantServe LLC

    Washington DC
    1 day ago
  •  ...Mid-Level InfoSec Security Engineer (With Focus On Securing Virtual Machines) ProSidian...  ...Machines) Consultant focusing on Cyber-Security/Information...  ...Intrusion Prevention Systems (IPS) and Intrusion Detection...  ...security systems including IDS and firewalls; Monitoring... 
    For contractors
    Work experience placement
    Work at office
    Monday to Friday
    Shift work

    ProSidian Consulting

    Washington DC
    4 days ago
  •  ...Cybersecurity Engineer – Mid The Cybersecurity Engineer – Mid supports the Small Business...  ...implementation services aligned with enterprise security modernization initiatives. The...  ...including SIEM, EDR, vulnerability management, IDS/IPS, MFA, and security monitoring platforms... 

    cFocus Software

    Washington DC
    1 day ago
  • $66.9k - $82.1k

     ...Cybersecurity Incident Response Engineer, Mid supports the detection,...  ...the speed and consistency of security operations. The engineer performs...  ...and incidents using SIEM, IDS/IPS, EDR, and related tools to...  ...platforms integrated with SOC and cyber defense functions.... 
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    5 days ago
  • $107.9k - $195.05k

     ...Leidos has an exciting opening for you, our next TS/SCI Cyber Security Engineer working across several Task Orders under the DOMEX Technology...  ...MS SQL, MySQL, ElasticSearch, etc.) Understanding of TCP/IP networking. Experience with Continuous Integration and Continuous... 
    Contract work
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Bethesda, MD
    2 days ago
  •  ...Cyber Security Threat Engineer Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across...  ...Perform software testing (patches, other updates) Troubleshoot OSI layer and TCP/IP related problems.... 

    Comtech LLC

    Washington DC
    4 days ago
  •  ...Sr. Cyber Security Engineer Category: Analytics and Emerging Digital Technologies Main location: United States, District of Columbia, Washington Position ID:J0426-1406 Employment Type: Full Time U.S. - What we do matters By playing... 
    Full time
    Local area

    CGI

    Washington DC
    2 days ago
  •  ...experience levels. ** Security Clearance: Ability to obtain...  ...: Yes, with Real ID Compensation : Salary is...  ...Position Description The Field Engineer positions will be part...  ...on level (Junior, Mid, Senior, SME) Hands‑on...  ...basic understanding of IP networking concepts Experience... 
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Relocation
    1 day per week

    Blackwatch International

    Alexandria, VA
    5 days ago
  •  ...Job Title: IT - Cyber Security Architect/Engineer III Location work will be performed: DCO048 - Washington, DC - (Remote support is authorized...  ...exception documentation. Configure and maintain IDS/IPS policies Perform database maintenance on IDS/IPS management... 
    Interim role
    Remote work

    Kaav Inc.

    Falls Church, VA
    3 days ago
  •  ...Senior Cyber Security Analyst The client is looking for a Senior Cyber...  ...swings (second shift), and mids. The current position will...  ...Utilize alerts from endpoints, IDS/IPS, netflow, and custom sensors...  ...knowledge of architecture, engineering, and operations of at least... 
    Work experience placement
    Shift work
    Day shift
    Afternoon shift

    Beyond SOF

    Arlington, VA
    4 days ago
  • $130k - $145k

     ...SECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITY ***POSITION REQUIRES US CITIZENSHIP*** Position Title: Information System Security Engineer (ISSE) Mid Location: Washington DC (on-site) Salary Range: $130K - $145K  based on experience Position Description... 
    Full time

    Redtrace Technologies

    Washington DC
    2 hours ago
  •  ...Mid-Level InfoSec Threat Intelligence Engineer Consultant ProSidian seeks a Mid-Level InfoSec...  ...Engineer Consultant focusing on Cyber-Security/Information Security (...  ...Prevention Systems (IPS) and Intrusion Detection...  ...security systems including IDS and firewalls; Monitoring... 
    For contractors
    Work experience placement
    Internship
    Work at office
    Monday to Friday
    Shift work

    ProSidian Consulting

    Washington DC
    4 days ago
  • $105.1k - $164.13k

     ...architecture, design, and security - individuals who are...  ...traditional network engineering roles to take ownership...  ...technical bridge between FAA cyber stakeholders and...  ...configurations, firewalls, VPNs, IDS/IPS, and load balancing....  ...FAA Public Trust. Mid-level ~ Bachelor's... 
    Permanent employment
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Noblis

    Washington DC
    5 days ago
  • $62k - $141k

     ...Penetration Tester and Operator, Mid page is loaded## Enterprise...  ...left to apply)job requisition id: R0238924Enterprise Cybersecurity...  ...penetration assessments to identify security risks within applications,...  ...technology solutions using AI, cyber, and other cutting-edge technologies... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Mc Lean, VA
    3 days ago
  •  ...Description Join the Nalley Consulting team as a Cyber Analyst. Position: Cyber Analyst LCAT: Mid Location : Joint Base Anacostia-Bolling Shift...  ...interpret, forecast, and explain a range of national security issues and developments specific to the cyber... 
    Temporary work
    Flexible hours
    Shift work

    Nalley Consulting

    Washington DC
    13 days ago
  •  ...Celestial Innovations Group (CIG) is seeking a Mid Zero Trust Engineer to support federal agency clients in...  ...understands that Zero Trust is a security philosophy and architectural strategy,...  ...Microsoft Zero Trust: Microsoft Entra ID (Azure AD), Conditional Access, Intune/... 
    Work from home
    Flexible hours

    CELESTIAL INNOVATIONS GROUP LLC

    Washington DC
    5 days ago
  •  ...design, development and programming, software engineering, systems development, testing,...  ...information, brand and intellectual property (IP), networks, systems and applications. Principal...  ...be exploited and introduce risk to the security of the client. Continually assesses and... 

    Atria Group LLC

    Washington DC
    1 day ago
  •  ...application scanning, phishing campaigns, cloud access security broker, and other cross functional security tools....  ...various information security technologies (i.e., IDS/IPS, HIPS, DLP, firewalls, network engineering, database, etc.). In-depth experience with cybersecurity... 

    Software Technology Inc

    Washington DC
    4 days ago
  • A defense contractor is looking for an experienced Firewall Engineer Level 3 in Suitland, MD. You will design and maintain firewall architecture, implement security measures, and ensure compliance with standards. Ideal candidates have a background in DoD communication... 
    For contractors

    CACI International Inc.

    Suitland, MD
    1 day ago
  • Nalley Consulting is seeking a Cyber Analyst at Joint Base Anacostia-Bolling. This mid-level position requires a TS/SCI clearance and involves conducting intelligence analysis on national security issues. Candidates should have at least 3 years of relevant experience in... 

    Nalley Consulting

    Washington DC
    2 days ago
  •  ...Cyber Security Engineer Abacus Technology is seeking a Cyber Security Engineer to provide security support for the Federal Aviation Administration (FAA). This is a full-time position. Responsibilities Design and implement security architecture that addresses... 
    Full time

    Abacus Technology

    Washington DC
    5 days ago
  • $131.3k - $237.35k

     ...seeking an experienced SME Cybersecurity Engineer to support the delivery, enhancement,...  ...delivering capabilities with real-world national security outcomes. Primary Responsibilities:...  ...certification appropriate for Advanced Cyber Defense Analyst roles (e.g., GCFA or... 
    Local area
    Immediate start

    Leidos

    Alexandria, VA
    1 day ago
  •  ..., and trusted results to enable national security missions worldwide. Job Description...  ...SOSi is seeking a Cybersecurity Security Engineer III to support cybersecurity engineering...  ...modernization initiatives across enterprise cyber defense environments, including Zero Trust... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IDS/IPS Cyber Security Engineer, Mid. Be the first to apply!