Vectra Detection Engineer
About GuidePoint Security
GuidePoint Security is a leading cybersecurity solutions and services firm enabling federal government organizations to make smarter security decisions that minimize risk. With more than 800 vetted technology vendor partnerships and deep practitioner expertise across every major cybersecurity domain, GuidePoint serves more than half of the U.S. Government’s cabinet-level agencies across Civilian, DoD, and Intelligence Community segments, as well as Federal System Integrators and major defense prime contractors. We are growing our federal Presales engineering team and looking for technically exceptional engineers who thrive at the intersection of federal mission and cybersecurity technology.
This role supports Vectra's Attack Signal Production Group, which builds core threat detection technology using AI and other methods for networks, cloud, and hybrid environments.
Key Responsibilities
Implement and maintain architecture
Analyze network traffic to identify and document threat patterns.
Develop and maintain network-based security signatures (e.g., in Suricata).
Use offensive security tools and techniques to simulate attacks and generate sample network traffic for testing detections.
Collaborate with data scientists and security researchers to support AI-driven detection efforts and improve accuracy.
Continuously monitor and tune the effectiveness of network detections, adjusting as needed.
Contribute to threat hunting by identifying new attacker tactics, techniques, and procedures (TTPs).
Participate in incident response activities when required.
Required Skills
Active TS/SCI Clearance
Strong background in network traffic analysis and threat detection.
Hands-on experience with tools like Suricata for signature-based detection.
Knowledge of offensive security (e.g., simulating attacks).
Familiarity with MITRE ATT&CK framework and real-world attacker behaviors (lateral movement, C2, etc.).
Collaboration skills for working with data scientists and researchers.
Understanding of networking protocols, OSI layers, and security concepts (often L3-L7).
Education/Certifications (often preferred or optional):
Relevant experience in cybersecurity (typically several years).
Certifications such as OSCP, GCIA, GCDA, GSEC, or similar (optional but valued).
“Applicants selected will be subject to a security investigation and must meet eligibility requirements for access to classified information.”