1

Security Onion Jobs (NOW HIRING)

... as Security Onion • Experience with threat emulation using frameworks such as Caldera • Experience with datacenter operations like planning and physically connecting network devices • ...

Experience with operating network sensor technologies such as Security Onion * Experience with threat emulation using frameworks such as Caldera * Experience with datacenter operations like planning ...

Senior Network Engineer

San Diego, CA · On-site

$110K - $151K/yr

... Security Onion • Deep understanding of IPSEC and 802.1X • Familiarity with Virtualization platforms involving Network Function Virtualization and VMware ESXi or Microsoft Hyper-V • Should be ...

IT Security Analyst

San Antonio, TX · On-site

$87K - $157K/yr

Hands-on experience with a Security Information and Event Management tool (ArcSight, Security Onion, etc.) * Fluent in computer network Packet Capture (PCAP) analysis * DoD 8570 IAT-II and CSSP ...

next page

Showing results 1-20

Security Onion information

See salary details

$13

$25

$52

How much do security onion jobs pay per hour?

As of Jun 8, 2026, the average hourly pay for security onion in the United States is $25.98, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $29.33 per hour, depending on experience, location, and employer.

What are some common challenges faced by professionals working with Security Onion in a security operations center (SOC)?

Professionals using Security Onion in a SOC often encounter challenges such as tuning detection rules to minimize false positives and keeping up with evolving threat landscapes. Managing large volumes of network data and ensuring the scalability of the deployment can also be demanding, especially in enterprise environments. Collaboration with incident response and IT teams is crucial for effective threat triage and remediation. Regular maintenance, updates, and integration with other security tools are key responsibilities that require both technical expertise and proactive communication.

What is the difference between Security Onion vs Network Security Analyst?

AspectSecurity OnionNetwork Security Analyst
CertificationsCompTIA Security+, CEH, CISSP (optional)CompTIA Security+, CISSP, GIAC certifications
Work EnvironmentSecurity-focused teams, cybersecurity operations centersCorporate IT departments, security teams
Industry UsageCybersecurity monitoring, intrusion detectionSecurity monitoring, incident response, risk assessment

Security Onion is an open-source platform primarily used for intrusion detection and network security monitoring, often managed by cybersecurity teams. A Network Security Analyst focuses on analyzing security data, responding to threats, and implementing security measures within organizations. While both roles require cybersecurity knowledge and certifications, Security Onion is a technical tool, whereas a Network Security Analyst is a professional role that utilizes such tools to protect networks.

What is Security Onion?

Security Onion is a free and open-source Linux distribution designed for network security monitoring, intrusion detection, and log management. It integrates a variety of tools, such as Zeek, Suricata, Wazuh, and the Elastic Stack, to provide comprehensive visibility into network and host activity. Security Onion simplifies the deployment and management of these tools, offering a unified platform for security analysts to detect, investigate, and respond to threats. It is widely used by security professionals to monitor enterprise networks and respond to incidents effectively.

What are the key skills and qualifications needed to thrive as a Security Onion Analyst, and why are they important?

To thrive as a Security Onion Analyst, you need a solid understanding of network security, intrusion detection, and incident response, often supported by experience in cybersecurity or relevant certifications. Familiarity with Security Onion tools such as Snort, Zeek, Suricata, and ELK stack is crucial, as well as experience with Linux systems and scripting. Strong analytical thinking, problem-solving skills, and effective communication help analysts interpret data and coordinate with IT teams. These skills are vital for quickly detecting, analyzing, and responding to security threats to protect organizational assets.

Sr. Cyber Range Engineer - Annapolis Junction, MD - Top Secret with Security Clearance

SOC/Day & Zimmermann Federal Services

Bethesda, MD

$165K/yr

Other

Posted 16 days ago


Job description

Sr. Cyber Range Engineer needed for aDirect Hireopportunity with SOC's client to work onsite inAnnapolis Junction, MD. *Candidate must have an active Top Secret clearance to be considered for this role.

Job Summary: The senior cyber range engineer will be a part of the event and mission rehearsal team and responsible for defining and executing event objectives. The engineer will provide expert guidance on cyber range development and execution, systems administration, cybersecurity, and account management support for the Joint Cyber Training Enterprise (JCTE). Essential Job Functions: As a senior cyber range engineer, provide leadership and technical (back end) expertise to support large scale cyber exercises and multi-spectrum cyber operations.

Principal advisor for cyber range operations in support of DCO/OCO activities for the US Cyber Command (USCC). Lead a team of cyber engineers and provide cyber range expertise to enable DCO and OCO operations, and day-to-day management of the separate programs coming through JCTE. Required Skills: • Intermediate knowledge of the Joint Events Life Cycle (JELC) • Intermediate knowledge of defensive and offensive cyber tools • Expert working knowledge of networking, to include: DNS, routing, basic to advanced TCP/IP skills and troubleshooting.

• Background in MS, AD, Security Onion, and VMWare • Demonstrated an understanding of Red Hat Enterprise Linux (RHEL) Identity Management (IdM) and Single Sign On (SSO) using Lightweight Directory Access Protocol (LDAP). • Translating cyber mission force training and mission rehearsal goals into actionable event environments. • Support cyber range event design and execution • Drive continuous process improvement across all event activities.

• Provides expert-level IT, virtual environment, and network support functions. • Must be a self-starter in a fast-paced environment and able to work with a range of engineers holding a diverse set of skills at differing levels of experience. • Be sensitive and flexible to the needs and requirements of the customer.

Desired Skills: • Intermediate to advanced knowledge of DNS: Authoritative vs. Recursive servers, SOA, NS, MX, A, and CNAME records. • Intermediate to advanced knowledge of routing: OSPF static, BGP, route maps, access lists, prefix lists, advertise maps, and route weights.

• Intermediate to advanced knowledge of exchange: Edge servers, recipient e-mail addressing, mailboxes, auto-configuration for Exchange clients. • Intermediate knowledge of Security Onion or SPLUNK: interface requirements, scalability landmines, Enterprise configurations (sensor and master). VMWare port properties and how they are tied to sensor ports and promiscuous modes.

• Excellent communications skills and the ability to work well in a team environment. • Prioritize multiple tasks, projects, and demands. • Interact with vendors/users/customers and developers to understand needs and operational requirements changes that will impact the production environment.

• Ability to solve technical problems involving a variety of integrated software and hardware platforms. Required Education/Experience: • 8+ years of experience with CNO/CNE/CND platforms • 5+ years of experience with cyber training, validation exercises, and working with cyber protection teams (CPTs), including planning, coordinating, and execution. • Current DoD 8570 IAT Level II or greater certification such as Security+, CCNA, CISSP or other equivalent certification.

• Associates degree in a technical discipline such as information technology, computer science, systems or software engineering from an accredited college or university. Employment Prerequisites The following requirements must be met to be eligible for this position: successful completion of a background investigation and drug urinalysis. SOC, a Day & Zimmermann company, is an Equal Opportunity Employer, EOE AA M/F/Vet/Disability.

Note: Any pay ranges displayed are estimations, which may have been provided by job boards. Actual pay is determined by an applicant's experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply.

Estimated Min Rate: $115500.00 Estimated Max Rate: $165000.00 #INDSOC