Epicareer Might not Working Properly
Learn More
T

NDR Architect

Salary undisclosed

Apply on

Availability Status

This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.


Original
Simplified

Herndon, VA Hybrid

Please find below :

Citizenship required and able to clear secret clearance.

Comprehensive Network Detection and Response (NDR) Architect/Engineer Role Description

Role Overview

The Network Detection and Response (NDR) Architect/Engineer is a crucial cybersecurity professional responsible for designing, implementing, and maintaining advanced network security solutions. This role combines deep network expertise with cutting-edge security knowledge to protect organizations from sophisticated cyber threats

## Primary Objectives

  1. Enhance network visibility and threat detection capabilities
  2. Reduce mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents
  3. Improve overall network security posture and resilience against cyber attacks

## Key Responsibilities

Solution Design and Implementation

  1. Architect comprehensive NDR solutions tailored to organizational needs
  2. Implement and configure NDR platforms like ExtraHop Reveal(x), Darktrace, or Vectra Cognito
  3. Integrate NDR solutions with existing security infrastructure (SIEM, SOAR, etc.)
  4. Design and implement network segmentation strategies to minimize attack surface

Network Traffic Analysis

  1. Analyze network traffic patterns to identify anomalies and potential threats
  2. Develop custom detection rules and algorithms for identifying sophisticated attacks
  3. Utilize machine learning and AI capabilities of NDR tools for advanced threat detection
  4. Perform regular network behavior analysis to establish baselines and detect deviations

Incident Response and Forensics

  1. Lead incident response efforts for network-related security events
  2. Conduct in-depth forensic analysis of security incidents
  3. Develop and maintain incident response playbooks
  4. Coordinate with other security teams during major security events

Continuous Improvement and Optimization

  1. Regularly assess and optimize NDR tool configurations
  2. Stay updated on emerging threats and adjust detection capabilities accordingly
  3. Conduct periodic security assessments and penetration tests
  4. Identify and implement new NDR technologies and methodologies

Reporting and Communication

  1. Generate comprehensive reports on network security status and incidents
  2. Present findings and recommendations to both technical and non-technical stakeholders
  3. Develop and deliver training sessions on NDR tools and best practices
  4. Collaborate with cross-functional teams to align NDR strategies with business objectives

Compliance and Governance

  1. Ensure NDR practices align with relevant regulatory requirements (e.g., GDPR, HIPAA, PCI DSS)
  2. Develop and maintain documentation for audits and compliance checks
  3. Contribute to the development of security policies and procedures

Required Skills and Knowledge

Technical Expertise

  1. Deep understanding of network protocols (TCP/IP, DNS, HTTP, etc.) and OSI model
  2. Proficiency in network security architectures and best practices
  3. Strong knowledge of common attack vectors and techniques (e.g., APTs, malware, DDoS)
  4. Expertise in one or more NDR platforms (ExtraHop, Darktrace, Vectra, etc.)
  5. Familiarity with SIEM and SOAR technologies
  6. Understanding of encryption technologies and PKI
  7. Knowledge of cloud security principles and practices

Programming and Scripting

  1. Proficiency in at least one scripting language (Python, PowerShell, Bash)
  2. Experience with API integration and automation
  3. Ability to develop custom tools and scripts for security analysis

Analytical and Problem-Solving Skills

  1. Strong analytical thinking and problem-solving abilities
  2. Experience in interpreting complex data sets and identifying patterns
  3. Ability to think like an attacker to anticipate and mitigate threats

Soft Skills

  1. Excellent written and verbal communication skills
  2. Strong leadership and team collaboration abilities
  3. Ability to explain complex technical concepts to non-technical audiences
  4. Proactive and self-motivated with a passion for cybersecurity

Preferred Qualifications

  1. Bachelor's or Master's degree in Computer Science, Cybersecurity, or related field
  2. 5+ years of experience in network security or related roles
  3. Relevant certifications such as:

- ExtraHop Certified Professional

- Certified Information Systems Security Professional (CISSP)

- GIAC Security Expert (GSE)

- Certified Ethical Hacker (CEH)

- Cisco Certified Network Professional (CCNP) Security

  1. Experience with threat hunting and advanced persistent threat (APT) detection
  2. Familiarity with regulatory compliance standards (GDPR, HIPAA, PCI DSS, etc.)

Tools and Technologies

  1. NDR Platforms: ExtraHop Reveal(x), Darktrace, Vectra Cognito
  2. Network Analysis Tools: Wireshark, tcpdump, Netflow analyzers
  3. SIEM Systems: Splunk, IBM QRadar, LogRhythm
  4. SOAR Platforms: Palo Alto Cortex XSOAR, Swimlane, Phantom
  5. Firewalls and IPS/IDS systems
  6. Endpoint Detection and Response (EDR) solutions
  7. Cloud Platforms: AWS, Azure, Google Cloud
  8. Virtualization Technologies: VMware, Hyper-V
  9. Containerization and Orchestration: Docker, Kubernetes

Key Performance Indicators (KPIs)

  1. Reduction in mean time to detect (MTTD) and mean time to respond (MTTR)
  2. Number of true positive alerts generated by NDR systems
  3. Reduction in false positive rates
  4. Improvement in overall network visibility and coverage
  5. Successful integration of NDR with other security tools and processes
  6. Timely resolution of critical security incidents
  7. Compliance with relevant regulatory standards
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job