Suricata Engineer with TS Clearance (R-00058)

Las Vegas, NV

True Zero Technologies

True Zero specializes in creating cybersecurity programs and software solutions that enable agency leaders to run a proactive defense, with better intelligence and more efficient collaboration.

View all jobs at True Zero Technologies

Apply now Apply later

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that said outcomes begin and end with our people, and that is what we have built, a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top tier services to our customers. In 2023, True Zero was recognized as a “Best Places to Work” in two categories ("Prosperous and Thriving" ($5MM – $50MM in gross revenue) and "Mid-Atlantic Region" (DC, DE, MD, NC, VA, WV)) and in 2022, was recognized as one of Inc. Magazine’s Top 5000 Fastest Growing Companies.
True Zero Technologies is seeking a Senior Suricata Engineer to lead the deployment, tuning, and optimization of Suricata-based intrusion detection systems (IDS/IPS). This engineer will play a critical role in designing scalable detection architectures, integrating telemetry with SIEMs and observability pipelines, and supporting real-time threat hunting and incident response. Experience with Cribl is a strong plus.

As a TZT consultant, the candidate will receive access to the full knowledge base which is driven by the True Zero community as well as the technical backing of the entire PS team. True Zero encourages collaboration and growth through information sharing and knowledge workshops. The candidate will also have access to our internal Slack channel to stay connected with the team as well as the necessary tools to train, demo, test and grow their professional skills.

Qualifications - Required

  • Key Responsibilities:
  • Design and deploy Suricata IDS/IPS in high-performance, secure network environments.
  • Tune and maintain custom rule sets (ET Open, ET Pro, custom rules).
  • Integrate Suricata output with SIEMs (e.g., Splunk, Elastic) and Cribl Stream for log routing and transformation.
  • Optimize performance of Suricata on high-throughput networks, including hardware offloading and multithreading.
  • Collaborate with SOC analysts, incident responders, and threat intel teams to provide actionable network visibility.
  • Support structured detection mapping to frameworks like MITRE ATT&CK and integrate detection into analytics pipelines.
  • Ensure systems comply with DoD and IC standards (e.g., STIGs, RMF).
  • Provide guidance and mentorship to junior engineers and analysts.


  • Required Qualifications:
  • Active Top Secret Clearance (SCI eligibility strongly preferred).
  • 5+ years of cybersecurity engineering or network security experience.
  • Hands-on expertise in deploying and tuning Suricata IDS/IPS.
  • Strong understanding of packet analysis, network protocols, and threat detection methodologies.
  • Experience working with Linux systems, system hardening, and automation tools (e.g., Ansible, Terraform).
  • Proficiency in scripting (e.g., Python, Bash) for automation and data parsing.
  • Experience integrating Suricata with SIEM platforms (Splunk, Elastic, Graylog, etc.).

Qualifications - Preferred

  • Experience with Cribl Stream or Edge for data pipeline management.
  • Exposure to Corelight, Zeek, or other network security tools.
  • Familiarity with cloud-based deployments (AWS, Azure).
  • Understanding of Zero Trust architecture and NIST 800-207.
  • Certifications: GIAC GCIA, GSEC, Cribl Certified Admin, or similar.


We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:
- Competitive salary, paid twice per month- Best in class medical coverage- 100% of medical premiums covered by True Zero- Company wide new business incentive programs- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)- 3 weeks of PTO starting + 11 Paid Holidays Annually- 401k Program with 100% company match on the first 4%- Monthly reimbursement of Cell Phone and Home Internet costs- Paternity/Maternity Leave- Investment in training and certifications to broaden and deepen your technical skills
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  2  0  0

Tags: Analytics Ansible Automation AWS Azure Bash Clearance Cloud DoD GCIA GIAC GSEC IDS Incident response Intrusion detection IPS Linux MITRE ATT&CK Network security NIST Python RMF Scripting SIEM SOC Splunk STIGs Terraform Threat detection Top Secret Top Secret Clearance Zero Trust

Perks/benefits: 401(k) matching Competitive pay Health care Medical leave Startup environment

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.