Senior Forward Deployed Engineer Investigator

💰 $153k-$188k

Job description

Towards the end of our interview process is an in-person interview.

Do you want to help make the world safe from cyber attack?

At Corelight, we believe that the best approach to cybersecurity risk starts with the network. Attackers can evade endpoint detection, firewalls and many other technologies - but they can’t avoid leaving digital footprints on the networks they traverse. Built on open-source innovations from Zeek, Suricata and YARA and refined through years of real-world use, Corelight transforms network footprints from physical, virtual and cloud networks into actionable insights. Our customers use these insights to speed incident response and proactively hunt for threats.

Role

As a Senior Forward Deployed Engineer on the Corelight Investigator team, you will be a technical bridge between our engineering organization and enterprise customers, deploying and optimizing Corelight’s Open NDR SaaS platform in client environments. You will lead on-site or remote deployments, customize solutions to enhance threat hunting and incident response, and ensure seamless integration with customer SOC workflows. Collaborating with product, engineering, and sales teams, you’ll drive customer success by delivering scalable, high-impact cybersecurity solutions while providing technical expertise and leadership in high-stakes environments.

Responsibilities

  • Lead the deployment and configuration of Corelight Investigator, including sensor setup, data ingestion pipelines, and integration with SOC tools (e.g., Splunk, Elastic).
  • Customize and optimize detection rules (e.g., Suricata, YARA, Zeek queries) and machine learning-driven analytics for threat detection, ransomware analysis, and encrypted traffic inspection.
  • Develop and implement custom scripts (e.g., Python) to extend Investigator’s capabilities, tailoring solutions to unique customer requirements.
  • Provide hands-on support for customer SOC teams during proof-of-concept investigations, demonstrating rapid triage, host isolation, and policy enforcement workflows.
  • Augment the development team by contributing to product development activities as necessary.
  • Troubleshoot and resolve complex deployment issues in diverse environments (on-premises, cloud, hybrid), ensuring high availability, scalability, and compliance (e.g., GDPR, FedRAMP).
  • Collaborate with product and engineering teams to relay customer feedback, influencing the roadmap for Investigator features like behavioral analytics and cloud security.
  • Create deployment documentation, conduct training sessions, and contribute to customer success metrics by meeting deployment SLAs and satisfaction goals.
  • Mentor junior engineers and evangelize best practices for deployment, performance optimization, and customer engagement.

Minimum Qualifications

  • Strong appreciation and support for our core values: low ego results, tireless service, and applied curiosity.
  • 7+ years of experience in software deployment, systems engineering, or solutions engineering, with at least 2 years in a customer-facing role.
  • Proficiency in Linux/Unix systems, cloud platforms (AWS, Azure, GCP), distributed computing,  SQL and NoSQL databases, and scripting (Python, Bash).
  • Experience with network security tools (e.g., Zeek/Bro, Suricata, Wireshark) and NDR/SIEM integrations.
  • Knowledge of APIs (REST/GraphQL) and containerization (Docker, Kubernetes).
  • Familiarity with cybersecurity concepts like encrypted traffic analysis, threat hunting, and behavioral detection.
  • Excellent communication skills, with the ability to collaborate with technical and non-technical stakeholders and influence solution design.
  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent experience.

Preferred Qualifications

  • Experience deploying Corelight products or open-source NDR tools (e.g., Zeek, Suricata).
  • Background in SOC operations, incident response, or threat hunting.
  • Familiarity with AWS services (e.g., Lambda, API Gateway, S3) or equivalent cloud technologies.
  • Certifications such as CISSP, GIAC, or AWS Certified Solutions Architect.
  • Experience in developing and deploying SAAS applications is a huge plus.
  • Experience with analytics tools like Splunk or Elasticsearch.

Fueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is the fastest growing network detection and response platform in the industry. Our customers trust us to protect mission-critical assets in leading enterprises, government, and research institutions worldwide. We are leading the way with AI-assisted workflows, machine learning models, cloud security and SaaS-based solutions to arm defenders with the tools and knowledge they need to disrupt cyber attacks. Our team of passionate innovators are dedicated to solving some of the toughest challenges in cybersecurity, while fostering a collaborative, inclusive, and growth-oriented culture.

Corelight is committed to a geographically distributed yet connected employee base with employees working from home and office locations around the world.  At Corelight, we take pride in the diversity of our backgrounds and perspectives, and we are committed to fostering an inclusive environment that strengthens our company.

We are looking forward to meeting you.  Check us out at www.corelight.com

Notice of Pay Transparency:

The compensation for this position may vary depending on factors such as your location, skills and experience. Depending on the nature and seniority of the role, a percentage of compensation may come in the form of a commission-based or discretionary bonus. Equity and additional benefits will also be awarded.

Compensation Range

$153,000—$188,000 USD

Share this job:
Please let Corelight know you found this job on Remote First Jobs 🙏

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service 🙏

Apply