1

Security Onion Jobs (NOW HIRING)

Senior Network Engineer

San Diego, CA · On-site

$110K - $151K/yr

Familiarity with Cyber Security Tools like Splunk, Vectra Networks, Security Onion * Deep understanding of IPSEC and 802.1X * Familiarity with Virtualization platforms involving Network Function ...

Senior Network Engineer

San Diego, CA · On-site

$110K - $151K/yr

Familiarity with Cyber Security Tools like Splunk, Vectra Networks, Security Onion * Deep understanding of IPSEC and 802.1X * Familiarity with Virtualization platforms involving Network Function ...

Cyber Security Analyst

San Antonio, TX · On-site

$87K - $157K/yr

Hands-on experience with a Security Information and Event Management tool (ArcSight, Security Onion, etc.) * Fluent in computer network Packet Capture (PCAP) analysis * DoD 8570 IAT-II and CSSP ...

DevOps Engineer

Columbia, MD · On-site

$135K - $160K/yr

Familiarity with cybersecurity tooling or security operations platforms such as Elastic, Splunk, or Security Onion. * Experience working in Federal or DoD environments, including STIG compliance and ...

Cyber Security Analyst

San Antonio, TX · On-site

$87K - $157K/yr

Hands-on experience with a Security Information and Event Management tool (ArcSight, Security Onion, etc.) * Fluent in computer network Packet Capture (PCAP) analysis * DoD 8570 IAT-II and CSSP ...

Systems Engineer

Laurel, MD · On-site

$112K - $150K/yr

Experience with operating network sensor technologies such as Security Onion * Experience with threat emulation using frameworks such as Caldera * Experience with datacenter operations like planning ...

next page

Showing results 1-20

Security Onion information

See salary details

$13

$25

$52

How much do security onion jobs pay per hour?

As of Jun 9, 2026, the average hourly pay for security onion in the United States is $25.98, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $29.33 per hour, depending on experience, location, and employer.

What are some common challenges faced by professionals working with Security Onion in a security operations center (SOC)?

Professionals using Security Onion in a SOC often encounter challenges such as tuning detection rules to minimize false positives and keeping up with evolving threat landscapes. Managing large volumes of network data and ensuring the scalability of the deployment can also be demanding, especially in enterprise environments. Collaboration with incident response and IT teams is crucial for effective threat triage and remediation. Regular maintenance, updates, and integration with other security tools are key responsibilities that require both technical expertise and proactive communication.

What is the difference between Security Onion vs Network Security Analyst?

AspectSecurity OnionNetwork Security Analyst
CertificationsCompTIA Security+, CEH, CISSP (optional)CompTIA Security+, CISSP, GIAC certifications
Work EnvironmentSecurity-focused teams, cybersecurity operations centersCorporate IT departments, security teams
Industry UsageCybersecurity monitoring, intrusion detectionSecurity monitoring, incident response, risk assessment

Security Onion is an open-source platform primarily used for intrusion detection and network security monitoring, often managed by cybersecurity teams. A Network Security Analyst focuses on analyzing security data, responding to threats, and implementing security measures within organizations. While both roles require cybersecurity knowledge and certifications, Security Onion is a technical tool, whereas a Network Security Analyst is a professional role that utilizes such tools to protect networks.

What is Security Onion?

Security Onion is a free and open-source Linux distribution designed for network security monitoring, intrusion detection, and log management. It integrates a variety of tools, such as Zeek, Suricata, Wazuh, and the Elastic Stack, to provide comprehensive visibility into network and host activity. Security Onion simplifies the deployment and management of these tools, offering a unified platform for security analysts to detect, investigate, and respond to threats. It is widely used by security professionals to monitor enterprise networks and respond to incidents effectively.

What are the key skills and qualifications needed to thrive as a Security Onion Analyst, and why are they important?

To thrive as a Security Onion Analyst, you need a solid understanding of network security, intrusion detection, and incident response, often supported by experience in cybersecurity or relevant certifications. Familiarity with Security Onion tools such as Snort, Zeek, Suricata, and ELK stack is crucial, as well as experience with Linux systems and scripting. Strong analytical thinking, problem-solving skills, and effective communication help analysts interpret data and coordinate with IT teams. These skills are vital for quickly detecting, analyzing, and responding to security threats to protect organizational assets.
Cyber Range Event Lead

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 12 days ago


Job description

  • Working with Event Designers and End Users to create technical tasking for proposed cyber events. Details the technologies and tools needed to accomplish those goals
  • Managing risk and requirements alongside Lead Engineers to ensure that difficult tasks are surfaced to program leadership
  • Splitting complex instantiations into manageable pieces and tracking tasks alongside a team of engineers under your supervision
  • Supporting medium to large system deployments, including planning, designing, and evaluating software options, selecting operating systems and protocol suites, configuring media, and deriving requirements
  • Designing, implementing, and troubleshooting elements of system networking, including routing and switching, and supporting special communicate methods such as VPN
  • Seeking optimum design within customer specifications, quality standards, schedule, & funding limitations
  • Working with site users to deploy and integrate their solutions. Offering assistance to participants during initial integration stages or when integration fails. Assisting in documenting changes
  • Assisting with briefing senior management and customer personnel on technical matters, technical research studies, and applications and in developing technical presentations
  • Working within established configuration and change management policies to ensure awareness, approval and success of changes made to system infrastructure
  • Assisting in selecting and implementing security tools, policies, and procedures
  • Liaising with vendors and other IT personnel for problem resolution in fielded environments
  • Working inside classified and unclassified environments to accomplish government goals

#LI-DH1


  • Bachelor's degree in computer science, Engineering or related technical field and eight (8) or more years work-related experience or a Master's degree and work-related experience in a relevant technical discipline or an equivalent combination of education and experience
  • Ability to obtain and hold a security clearance
  • Ability to apply comprehensive technical knowledge across key tasks and high impact assignments
  • Ability to work and collaborate effectively with others as well as experience working independently
  • Possess a high level of proficiency of systems administration and/or information technology concepts
  • Strong communication, team building, craft, and vocational skills to include writing acumen for manuals, technical reports, and procedures.
  • Experience leading small teams (3-10 engineers), delegating tasking, and tracking progress
  • Experience deriving technical tasks from mission requirements

  • Experience working in a cyber range environment as an operator or administrator
  • Experience configuring and installing various network devices and services (e.g., routers, switches, firewalls, load balancers, VPN)
  • Experience building and deploying software (from internal and external parties), troubleshooting vendor solutions with outside assistance
  • Extensive experience leading small teams (3-10 engineers), delegating tasking, and tracking progress.
  • Experience deriving technical tasks from mission requirements in cyber events and customer operations
  • Experience with VMware virtualization tools, to include vSphere, and their interoperability with networks
  • Experience performing system maintenance and system upgrades including service packs, patches, hot fixes and security configurations (e.g., STIGs)
  • Experience with logical isolation of virtual enclaves to support isolated test environments
  • Experience with configuring/administering NetApp storage networks
  • Experience with various DoD-standard endpoint toolsets for OCO and DDCO efforts (e.g., Kali Linux, VyOS, Security Onion, pfSense)
  • Military experience or experience as a DoD contractor a plus
  • CCNA or similar networking certificate
  • VMware Certified Professional desired
  • Microsoft Certified Solutions or similar Windows systems certificate

SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE SECRET LEVEL WITH TOP SECRET / SCI ELIGIBILITY

 


  • Only as needed and very minimal.

Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.

SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals starting at 10 days of vacation and 5 days of sick leave annually, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.


Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment. All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.

Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.