Source description
About the role
6+ years of hands-on experience with ExtraHop Reveal(x) or Reveal(x) 360 in production environments or similar NDR solutions.
Experience deploying and administering ExtraHop Reveal(x) Enterprise or Reveal(x) 360
Demonstrated experience deploying and tuning ExtraHop sensors, recordstores, and packetstores, including sizing, retention configuration, and performance troubleshooting
Strong grasp of wire data analysis: L2-L7 protocol behavior (TCP/IP, DNS, HTTP, etc), TLS/SSL decryption
Experience building custom detections, bundles, and dashboards beyond default configurations
Proficient in JavaScript and Python scripting for automation, customization, and workflow optimization
Working knowledge of at least one major SIEM (Splunk, XSIAM, Crowdstrike or equivalent) and experience integrating ExtraHop as a data source
Experienced in proactive threat hunting and incident investigations using the MITRE ATT&CK framework, Cyber Kill Chain, NIST Cybersecurity Framework (CSF), and CIS Critical Security Controls to identify adversary TTPs and strengthen detection and response capabilities.
Experience with cloud traffic mirroring (AWS VPC Traffic Mirroring, Azure vTAP, or GCP Packet Mirroring) is a strong plus
Solid Understanding of network security, cloud environments, Identity, Linux, Mac and Windows.
Strong analytical and troubleshooting capabilities.
Effective communication skills with the ability to engage with clients and Team members.
ExtraHop certification (ECS or equivalent) preferred or relevant industry certifications ( CISSP, CYSA, CEH, Security+, Pentest+, OSCP) are a plus.
More at AHEAD
Related open roles
Senior Technical Consultant - Enterprise Networking, Wireless
Remote · United States
Identity Application Architect
Remote · United States
Manager Security
Bangalore · Hyderabad · Delhi NCR · Hybrid
Security Analyst
Remote · IN
Senior Technical Consultant - Network Security
Remote · United States
Sr Network Engineer - Palo Alto
Bangalore · Hyderabad · Hybrid
