Professional Services Engineer
Be part of the team that defends the networks the world depends on
Corelight defends the world’s most sensitive networks—from global commerce to national defense—quietly, relentlessly, and with resolve. As cyber threats grow faster and smarter, we serve as the trusted force behind network resilience, putting elite defense within reach.
By transforming digital footprints from physical, virtual, and cloud networks into actionable insights, we empower defenders to illuminate blind spots and stay ahead of an evolving threat landscape. Built on open-source innovations and fueled by industry leading agentic AI technology, Corelight helps teams to detect advanced threats and close cases with unprecedented clarity and precision.
We are currently seeking a Professional Services Engineer, reporting to the Sr. Manager of Professional Services. In this role, the main focus is to prepare and validate equipment configurations for new installations, develop content for anomaly and hunt detections, assess the overall health of the Corelight infrastructure at the client’s location. You’re the ideal candidate if you are a strategic thinker with a strong networking and security background, work well independently, and are results-driven.
Key Responsibilities:
- Help customers improve their cybersecurity posture, with a particular focus on process
optimization - Help investigate incidents
- Educate on Zeek Log use, including as it relates to Corelight Suricata alerts
- Design and implement technical solutions with ecosystem partners (packet brokers,
asset managers, SOAR systems, etc.) - Implement queries and dashboards in SIEMs - Splunk, Elastic, Humio, etc.
- Influence customers and Corelight teams and be seen as a technical expert
- Conduct network-related testing to ensure Corelight products operate correctly
- Perform validation testing of Corelight products
- Provide ongoing, informal, knowledge transfer
- Collaborate with product management on product features/integrations
- Work with back-end tools like Kafka and Logstash
- Documenting the process for importing of data (MISP, Intel, etc)
- Developing custom content for threat hunting use cases as defined by the customer
- Developing playbooks for SOC/IR workflow automation based on Corelight data
- Ad-hoc (as requested) written summary reports on equipment and security problems
- Technical input to major service outage root cause analysis and corrective action reports
- Leading project status meetings and wrap-up/post-mortem meetings
- Some on-site work required
Minimum Qualifications:
- US Citizen
- 5+ years of experience in cybersecurity (Prior startup experience preferred)
- Extensive experience with a SOC environment
- Zeek/Corelight experience is a plus
- Security and/or Networking related certification(s)
- Demonstrated expertise in Windows/MacOS/Linux/Unix operating systems, IDS/IPS,
- Network administration, firewall configuration, and strong knowledge of TCP/IP
- SIEM experience (Splunk required, others a bonus)
- Scripting in (some of) Zeek, Bash, Python, Perl, Powershell, etc.
- Strong briefing skills; experience interacting with SES/general officer-level management
Notice of Pay Transparency:
The compensation for this position may vary depending on factors such as your location, skills and experience. Depending on the nature and seniority of the role, a percentage of compensation may come in the form of a commission-based or discretionary bonus. Equity and additional benefits will also be awarded.
Why Join Us?
Fueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is one of the fastest growing network detection and response platforms in the industry. Our passionate team thrives in a collaborative, inclusive, and geographically distributed culture. We embrace diverse perspectives, neurodiversity, curiosity and low ego results - fostering an environment where every innovator can solve the toughest challenges in cybersecurity and contribute their best work.
We are looking forward to meeting you. Check us out at www.corelight.com
Senior Manager of Security Intelligence
Be part of the team that defends the networks the world depends on
Corelight defends the world’s most sensitive networks—from global commerce to national defense—quietly, relentlessly, and with resolve. As cyber threats grow faster and smarter, we serve as the trusted force behind network resilience, putting elite defense within reach.
By transforming digital footprints from physical, virtual, and cloud networks into actionable insights, we empower defenders to illuminate blind spots and stay ahead of an evolving threat landscape. Built on open-source innovations and fueled by industry leading agentic AI technology, Corelight helps teams to detect advanced threats and close cases with unprecedented clarity and precision.
As the Senior Manager of Security Intelligence, you will provide strategic leadership, organizational design, and vision for the Security Intelligence function. You will design and champion an automation-first, LLM-driven intelligence strategy across the enterprise, own the global incident response and vulnerability management capabilities, and collaborate with executive leadership to define, measure, and scale Corelight's overall corporate security posture.
Specific Responsibilities:
- Strategic Automation & Modernization Strategy: Define and execute the long-term vision for an automation-first culture, driving the adoption of next-generation security orchestration and LLM-first frameworks to radically compress response times across all enterprise environments.
- Executive Collaboration & Alignment: Partner with the CISO and cross-functional VP-level stakeholders to align security intelligence initiatives with broader business objectives, ensuring seamless integration across Product, Engineering, and Information Security.
- Metrics, Governance & Risk Reporting: Synthesize complex incident, threat, and vulnerability telemetry into strategic, high-impact executive dashboards and board-ready metrics, providing clear visibility into systemic risks and mitigation progress.
- Enterprise Incident Lifecycle Ownership: Serve as the ultimate authority for global security incident response, ensuring the organization maintains world-class readiness, continuous post-mortem evolution, and regulatory/compliance alignment.
- Organizational Design & Talent Cultivation: Lead, scale, and mentor a multi-tiered organization of high-performing security engineers and leads. Drive workforce planning, headcount budgeting, performance cultures, and career paths that attract and retain top-tier technical talent.
Knowledge/Skills/Abilities needed to be successful:
- Transformational Leadership: You view talent management as a strategic differentiator. You excel at building inclusive, high-performance cultures, aligning diverse engineering teams, and developing the next generation of security leaders.
- Strategic and Adaptive Vision: You anticipate market and threat-landscape shifts, proactively pivoting functional strategies to leverage cutting-edge paradigms (like generative AI and automated defense) before they become industry standard.
- Technical Credibility & Governance: While you operate as a strategic executive, you possess the deep technical foundation necessary to evaluate architectural decisions, challenge technical status quos, and champion rigorous engineering standards.
- Enterprise Autonomy: You are adept at operating with ultimate functional autonomy, translating high-level executive goals into clear execution roadmaps, managing operational budgets, and optimizing vendor ecosystems.
- Executive Communication: You possess exceptional communication skills, with a proven ability to translate deeply technical, high-risk security crises into calm, actionable, and risk-mitigated strategies for executive leadership and board members.
Qualifications/Requirements:
- Experience: A Bachelor’s or Master’s degree in Computer Science, Cyber Security, or equivalent; a minimum of 8–10+ years of progressive experience in Security Intelligence, Threat Intel, or Security Operations.
- Leadership: Minimum of 5 years of formal people-management experience, with a proven track record of leading multi-tiered teams or expanding a specialized security function at scale.
- Framework & Compliance Governance: Expert-level understanding of major security frameworks (e.g., NIST, MITRE ATT&CK, SAIF) with demonstrable experience leveraging them to build enterprise risk and defense metrics.
- Program Oversight: Proven experience overseeing enterprise-wide offensive security programs, including comprehensive red-teaming, external penetration testing, and continuous vulnerability disclosure protocols.
- Automation Architecture: Demonstrated success in funding, designing, or implementing advanced automation (SOAR, custom LLM integrations) to optimize large-scale incident workflows.
Notice of Pay Transparency:
The compensation for this position may vary depending on factors such as your location, skills and experience. Depending on the nature and seniority of the role, a percentage of compensation may come in the form of a commission-based or discretionary bonus. Equity and additional benefits will also be awarded.
Why Join Us?
Fueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is one of the fastest growing network detection and response platforms in the industry. Our passionate team thrives in a collaborative, inclusive, and geographically distributed culture. We embrace diverse perspectives, neurodiversity, curiosity and low ego results - fostering an environment where every innovator can solve the toughest challenges in cybersecurity and contribute their best work.
We are looking forward to meeting you. Check us out at www.corelight.com
The full posting opens here — pay, setting and the full description, without leaving the list.