1

Corelight Jobs (NOW HIRING)

Corelight is looking for a part-time Social Media Contractor to support day-to-day social execution across corporate and employee advocacy channels. This role will focus on content publishing ...

... Corelight or Trellix • Experience deploying platforms across cloud, on-premises and disconnected environments using Kubernetes or OpenShift • Experience working in classified or compartmented ...

... Corelight, or Trellix • Knowledge of deploying platforms across cloud, on-premises, and disconnected environments using Kubernetes or OpenShift • Knowledge of working in classified or ...

... Corelight or Trellix • Experience deploying platforms across cloud, on-premises and disconnected environments using Kubernetes or OpenShift • Experience working in classified or compartmented ...

... Corelight NDR, IDS/IPS, firewalls, and network security tools. • Experience with Cisco Prime, SolarWinds Orion, or comparable configuration management tools. • Experience with Zero Trust Network ...

Cybersecurity Analyst

Woburn, MA · On-site

$104K - $120K/yr

Experience with Corelight Investigator is highly preferred * Technical background with a variety of information security systems and tools including firewalls, intrusion detection systems, intrusion ...

next page

Showing results 1-20

Corelight information

See salary details

$8

$26

$61

How much do corelight jobs pay per hour?

As of Jun 25, 2026, the average hourly pay for corelight in the United States is $26.34, according to ZipRecruiter salary data. Most workers in this role earn between $15.14 and $30.77 per hour, depending on experience, location, and employer.

What jobs make $10,000 a month without a degree?

High-paying jobs that can reach $10,000 a month without a degree include roles like cybersecurity analyst, network administrator, or sales manager, which often require specialized skills, certifications, or experience. These positions typically involve technical knowledge, problem-solving abilities, and sometimes certifications such as CompTIA Security+ or Cisco CCNA. Success in these roles depends on expertise, industry demand, and performance rather than formal education alone.

What does the company Corelight do?

Corelight is a cybersecurity company that provides network detection and response solutions using open-source tools like Zeek. The company helps organizations monitor network traffic, identify threats, and improve security posture through detailed visibility and analysis. Employees in related roles often work with network security protocols, intrusion detection, and security information and event management (SIEM) systems.

What is a Corelight Engineer?

A Corelight Engineer is a professional who specializes in deploying, managing, and maintaining Corelight network security solutions. Corelight is a cybersecurity company known for its network detection and response (NDR) products, built on the open-source Zeek framework. Corelight Engineers typically work with enterprise security teams to monitor network traffic for threats, optimize detection capabilities, and integrate Corelight appliances with other security tools. Their responsibilities may also include troubleshooting issues, performing updates, and providing technical support.

What are some typical challenges faced by security professionals working at Corelight, and how can these be managed effectively?

Security professionals at Corelight often deal with rapidly evolving threat landscapes and the need to analyze large volumes of network data in real time. Balancing proactive threat detection with minimizing false positives can be challenging, especially when customizing solutions for diverse client environments. Effective management involves staying updated on the latest threat intelligence, collaborating closely with engineering and product teams, and leveraging Corelight's robust open-source and commercial tools for continuous improvement. Open communication within the team and ongoing professional development are also key to overcoming these challenges.

What are the key skills and qualifications needed to thrive as a Corelight Security Engineer, and why are they important?

To thrive as a Corelight Security Engineer, you need a solid background in network security, intrusion detection, and experience with network traffic analysis, often supported by a degree in computer science or a related field. Familiarity with Corelight's network sensors, Zeek (formerly Bro), and common SIEM platforms, as well as relevant certifications like CISSP or GIAC, is typically required. Strong analytical thinking, problem-solving ability, and effective communication skills make someone stand out in this position. These skills are crucial for proactively identifying threats, optimizing security infrastructure, and clearly conveying findings to technical and non-technical stakeholders.

Is Corelight a good company to work for?

Corelight is a cybersecurity company known for its network security solutions and open-source tools. Employees often cite a collaborative environment and opportunities to work with advanced security technologies, though experiences can vary by role and team. It is advisable to review specific job roles and company reviews for a comprehensive understanding.

What jobs pay 2000 a day?

High-paying jobs that can pay around $2,000 a day typically include specialized roles such as senior software engineers, management consultants, anesthesiologists, or corporate lawyers. These positions often require advanced skills, extensive experience, and relevant certifications, and may involve consulting, contract work, or high-stakes environments.

What is the difference between Corelight vs Network Security Analyst?

AspectCorelightNetwork Security Analyst
Required CredentialsNetwork certifications (e.g., CompTIA Network+, CISSP), knowledge of network protocolsSecurity certifications (e.g., CISSP, CEH), network knowledge
Work EnvironmentSecurity operations centers, network monitoring environmentsCorporate IT departments, security teams, consulting firms
Employer & Industry UsageCybersecurity firms, large enterprises, government agenciesOrganizations with IT security needs across industries
Comparison IntentUnderstanding technical roles in network securityEvaluating security roles and responsibilities

Corelight specialists focus on deploying and managing network detection tools, analyzing network traffic, and enhancing security infrastructure. Network Security Analysts perform broader security monitoring, incident response, and vulnerability assessments. While both roles require network security knowledge and certifications, Corelight roles are more technical and tool-specific, whereas Network Security Analysts have a wider scope in security operations.

More about Corelight jobs
What states have the most Corelight jobs? States with the most job openings for Corelight jobs include:
Infographic showing various Corelight job openings in the United States as of June 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution, with an average salary of $54,791 per year, or $26.3 per hour.
IDS/IPS Cyber Security Engineer, Mid

IDS/IPS Cyber Security Engineer, Mid

DAn Solutions

Washington, DC

Full-time

Posted 19 days ago


Job description

REQUIRES AN EXISTING/ACTIVE TS/SCI WITH CI POLYGRAPH - NO REMOTE WORK, MUST WORK ON SITE

Job Description:

We are seeking an experienced Network Intrusion Detection Engineer to join our cybersecurity team. The ideal candidate must possess strong Linux engineering expertise with experience managing YAML configuration files, and how these configurations integrate and influence the Intrusion Detection Systems/Intrusion Prevention Systems (IDS/IPS). Highly qualified candidates will have hands-on engineering and O&M experience with Suricata and/or other network-based IDS capabilities such as Snort, VectraAI, Corelight, etc. You will play a critical role in deploying, tuning, and maintaining the IDS within a complex enterprise IT environment, primarily running on Red Hat Enterprise Linux.

What You'll Work On:

Designing, deploying, and maintaining IDS/IPS systems across a large enterprise with multiple networks.

Developing, reviewing, and optimizing YAML configuration files to ensure optimal detection capabilities and minimal false positives.

Understanding and managing the interaction between YAML configuration and its runtime engine, including rule loading, protocol decoding, and logging.

Tuning IDS/IPS for optimal performance with NICs, including configuring Direct Memory Access (DMA), RSS queues, interrupt coalescing, and leveraging any NIC-specific acceleration features.

Collaborating with security teams to integrate IDS/IPS with SIEM and other security monitoring platforms.

Troubleshooting installation and operational issues specific to IDS/IPS on Red Hat Enterprise Linux, addressing compatibility, kernel module requirements, SE-Linux policies, and performance tuning.

Identifying and mitigating common pitfalls encountered when deploying IDS/IPS in large-scale enterprise environments, including package dependencies, system resource constraints, and NIC driver/configuration issues.

Provide detailed documentation and runbooks for Suricata configuration, tuning NICs, and deployment processes.

Staying current with Platform IDS/IPS Software releases, NIC driver updates, and community best practices for network interface tuning and IDS/IPS performance enhancement.

Basic Qualifications:

Proven experience working with Snort, Suricata, Corelight or other network IDS/IPS systems, including hands-on management of its YAML configuration files.

Strong knowledge of configuration structure, syntax, and how it controls detection rules, logging, and output modules.

Extensive experience administering Red Hat Enterprise Linux (RHEL) systems, including package management (yum/dnf), kernel module management, SE-Linux configuration, and system optimization via Unix CLI and other remote shell access vectors (puTTY, SSH, etc.)

Hands-on experience tuning Suricata for high-performance packet capture with Napatech NICs or similar advanced network interface cards.

Familiarity with NIC-specific features such as DMA, Receive Side Scaling (RSS), interrupt moderation, and offload capabilities, and how to configure them for Suricata.

Experience troubleshooting Suricata's interaction with NIC drivers and kernel modules in an enterprise environment.

TS/SCI clearance with the ability to obtain a counter-intelligence polygraph.

Associate's degree and 5+ years of experience supporting IT projects and activities or Bachelor's degree and 3+ years of experience supporting IT projects and activities or Master's degree and 1+ years of experience supporting IT projects and activities. Years of experience may be accepted in lieu of degree.

DoD 8570 IAT Level II Certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification.

Ability to obtain a DoD 8570 Cyber Security Service Provider - Infrastructure Support Certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 60 days of start date.


Additional Qualifications:

Experience with scripting languages (Bash, Python, YAML/Ansible, etc.) to automate Suricata configuration and deployment tasks.

Proficient understanding of network protocols, intrusion detection methodologies, and security event correlation.

Experience integrating Suricata with Splunk, or other SIEM solutions.

Knowledge of containerized deployments of Suricata (Docker/Kubernetes) in enterprise environments.

Detection and Response (NDR) solutions, including Trellix/FireEye, Corelight, Endace, Vectra AI, Dark Trace, Cisco Security Network Analytics, Open XDR, Fortinet FortiNDR, Trend Vision, etc.

Ability to be a self-starter, work without considerable direction, and work with a team.

Possession of excellent verbal and written communication skills, including client briefings and coordinating efforts