1

Malware Suricata Jobs (NOW HIRING)

Splunk, Suricata, Zeek, Full Packet Capture, Network Forensics, Endpoint Detection and Response, Corelight, Elastic Experience with malware analysis concepts and methods Unix/Linux command line ...

Splunk, Suricata, Zeek, Full Packet Capture, Network Forensics, Endpoint Detection and Response,Corelight, Elastic. * Experience with malware analysis concepts and methods. * Unix/Linux command line ...

New

Malware Triage and Forensic Systems: * Knowledge of how to use structured queries to pull data from logs and be able to formulate signatures such as YARA, Snort, Suricata, Bro/Zeek successfully

Detection Engineering Lead

Mclean, VA · On-site

$103K - $136K/yr

... rules for malware and network-based threats * Building, testing, and tuning security analytics ... Experience with YARA, Snort, Suricata, or other signature-based detection technologies * Experience ...

Detection Engineering Lead

Mclean, VA · On-site

$103K - $136K/yr

... rules for malware and network-based threats * Building, testing, and tuning security analytics ... Experience with YARA, Snort, Suricata, or other signature-based detection technologies * Experience ...

... Suricata, and ability to perform analysis of associated network logs * Reverse Engineering: ability to understand the capabilities of static and dynamic malware analysis * Incident Remediation ...

Security Engineer - Threat Intel

New York, NY · On-site +1

$320K - $405K/yr

Perform technical analysis of malware, phishing infrastructure, and attacker tooling to extract ... Have experience authoring detection logic (YARA, Sigma, Snort/Suricata, or SIEM-native queries) and ...

... Suricata, and ability to perform analysis of associated network logs * Reverse Engineering: ability to understand the capabilities of static and dynamic malware analysis * Incident Remediation ...

next page

Showing results 1-20

Malware Suricata information

See salary details

$5

$47

$62

How much do malware suricata jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for malware suricata in the United States is $47.06, according to ZipRecruiter salary data. Most workers in this role earn between $39.18 and $52.88 per hour, depending on experience, location, and employer.

What is a malware Suricata analyst?

A Malware Suricata analyst is a cybersecurity professional who specializes in using Suricata, an open-source network threat detection engine, to identify and analyze malware threats within network traffic. Their responsibilities include configuring Suricata rules, monitoring alerts, and investigating suspicious activities that may indicate malware infections. They play a key role in incident response by providing actionable intelligence about threats detected in real time. Additionally, they often collaborate with other security teams to improve detection capabilities and help protect an organization's digital assets.

What are the key skills and qualifications needed to thrive as a malware Suricata analyst?

To thrive as a Malware Analyst with a focus on Suricata, you need a solid foundation in cybersecurity principles, malware analysis, and network protocols, often supported by a degree in computer science or related certifications like GIAC or CEH. Hands-on experience with Suricata IDS/IPS, packet analysis tools (e.g., Wireshark), and scripting languages such as Python is typically required. Strong analytical thinking, attention to detail, and effective problem-solving skills set top performers apart in this role. These competencies are critical for identifying, analyzing, and mitigating threats in complex network environments to maintain organizational security.

What are some common challenges faced by professionals working with Suricata for malware detection?

Professionals using Suricata for malware detection often encounter challenges such as managing large volumes of network traffic, fine-tuning rules to minimize false positives, and staying updated with emerging threats. Integrating Suricata with other security tools and SIEM platforms can require significant technical expertise. Additionally, regularly updating rule sets and maintaining performance while ensuring thorough detection are key aspects that require continuous attention.

What is the difference between Malware Suricata vs Malware Analyst?

AspectMalware SuricataMalware Analyst
CertificationsNetwork security, IDS/IPS certificationsMalware analysis, cybersecurity certifications
Work EnvironmentNetwork security teams, intrusion detection systemsMalware labs, cybersecurity teams
Industry UsageNetwork monitoring, intrusion detectionMalware research, threat analysis

Malware Suricata focuses on network-based intrusion detection using tools like Suricata, while Malware Analysts specialize in examining malicious software to understand its behavior. Both roles are vital in cybersecurity but differ in their primary focus: network security versus malware research.

What other helpful pages are available for Malware Suricata?

Other pages related to Malware Suricata:

Infographic showing various Malware Suricata job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 93% Full Time, 1% Part Time, and 5% Contract. Highlights an 77% Physical, 7% Hybrid, and 16% Remote job distribution, with an average salary of $97,888 per year, or $47.1 per hour.

Cyber Security Analyst with Security Clearance

Arlington, VA • On-site

Other

Posted 5 days ago


Job description

We are seeking a Cyber Security Analyst to support the DISA GSMO-II program in the Washington, DC area. This position provides 24x7 cybersecurity monitoring and analysis services for Department of Defense networks above the SECRET level, including real-time cyber threat intelligence analysis, correlation of actionable security events, network traffic analysis using raw packet data, and participation in the coordination of resources during the incident response process. Qualifications
Bachelor's Degree and 4+ years of prior relevant experience; additional work experience or cyber courses/certifications may be substituted in lieu of a degree
Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, the OSI model, defense-in-depth, and common security elements
Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings
DoD 8570 IAT Level II or higher certification (such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC) prior to starting
DoD 8570 CSSP-A level certification (such as CEH, CySA+, or GCIA) or other qualifying certification required within 180 days of hire
Demonstrated commitment to training, self-study, and maintaining proficiency in the technical cybersecurity domain, with the ability to think and work independently
Strong analytical and troubleshooting skills
Willingness to perform shift work
U.S. Citizenship required
Active DoD TOP SECRET clearance with SCI eligibility required
Preferred Qualifications CND experience (Protect, Detect, Respond, and Sustain) within a Computer Incident Response organization
Demonstrated understanding of the life cycle of network threats, attacks, attack vectors, and methods of exploitation, with an understanding of intrusion set tactics, techniques, and procedures (TTPs)
Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, the OSI model, defense-in-depth, and common security elements
Experience with development and incorporation of AI and automation tools into incident response processes
Demonstrated hands-on experience analyzing high volumes of logs and network data (e.g., Splunk, Suricata, Zeek, Full Packet Capture) and other attack artifacts in support of incident investigations
In-depth knowledge of the architecture, engineering, and operations of at least one enterprise SIEM platform (e.g., Splunk ES, Elastic)
Experience and proficiency with any of the following: Splunk, Suricata, Zeek, Full Packet Capture, Network Forensics, Endpoint Detection and Response, Corelight, Elastic
Experience with malware analysis concepts and methods
Unix/Linux command line experience
Scripting and/or programming experience to write Suricata and Zeek rule sets
Familiarity or experience with Intelligence Driven Defense, MITRE ATT&CK, and/or the Cyber Kill Chain methodology