Corelight · 1 month ago
Senior Forward Deployed Engineer, Investigator
Corelight is a leading company in cybersecurity, focused on transforming network footprints into actionable insights. The Senior Forward Deployed Engineer will bridge the engineering organization and enterprise customers, deploying and optimizing Corelight’s Open NDR SaaS platform, while ensuring customer success through technical expertise and leadership.
AnalyticsCyber SecurityNetwork SecuritySecuritySoftware
Responsibilities
Lead the deployment and configuration of Corelight Investigator, including sensor setup, data ingestion pipelines, and integration with SOC tools (e.g., Splunk, Elastic)
Customize and optimize detection rules (e.g., Suricata, YARA, Zeek queries) and machine learning-driven analytics for threat detection, ransomware analysis, and encrypted traffic inspection
Develop and implement custom scripts (e.g., Python) to extend Investigator’s capabilities, tailoring solutions to unique customer requirements
Provide hands-on support for customer SOC teams during proof-of-concept investigations, demonstrating rapid triage, host isolation, and policy enforcement workflows
Augment the development team by contributing to product development activities as necessary
Troubleshoot and resolve complex deployment issues in diverse environments (on-premises, cloud, hybrid), ensuring high availability, scalability, and compliance (e.g., GDPR, FedRAMP)
Collaborate with product and engineering teams to relay customer feedback, influencing the roadmap for Investigator features like behavioral analytics and cloud security
Create deployment documentation, conduct training sessions, and contribute to customer success metrics by meeting deployment SLAs and satisfaction goals
Mentor junior engineers and evangelize best practices for deployment, performance optimization, and customer engagement
Qualification
Required
Strong appreciation and support for our core values: low ego results, tireless service, and applied curiosity
7+ years of experience in software deployment, systems engineering, or solutions engineering, with at least 2 years in a customer-facing role
Proficiency in Linux/Unix systems, cloud platforms (AWS, Azure, GCP), distributed computing, SQL and NoSQL databases, and scripting (Python, Bash)
Experience with network security tools (e.g., Zeek/Bro, Suricata, Wireshark) and NDR/SIEM integrations
Knowledge of APIs (REST/GraphQL) and containerization (Docker, Kubernetes)
Familiarity with cybersecurity concepts like encrypted traffic analysis, threat hunting, and behavioral detection
Excellent communication skills, with the ability to collaborate with technical and non-technical stakeholders and influence solution design
Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent experience
Preferred
Experience deploying Corelight products or open-source NDR tools (e.g., Zeek, Suricata)
Background in SOC operations, incident response, or threat hunting
Familiarity with AWS services (e.g., Lambda, API Gateway, S3) or equivalent cloud technologies
Certifications such as CISSP, GIAC, or AWS Certified Solutions Architect
Experience in developing and deploying SAAS applications is a huge plus
Experience with analytics tools like Splunk or Elasticsearch
Benefits
Equity
Discretionary bonus
Company
Corelight
Corelight is a cybersecurity company specializing in network traffic analysis (NTA) solutions.
H1B Sponsorship
Corelight has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (13)
2024 (9)
2023 (1)
2022 (10)
2021 (6)
2020 (5)
Funding
Current Stage
Late StageTotal Funding
$309.2MKey Investors
AccelEnergy Impact PartnersGeneral Catalyst
2024-04-30Series E· $150M
2021-09-02Series D· $75M
2019-10-17Series C· $50M
Recent News
2025-12-09
2025-11-05
Help Net Security
2025-11-01
Company data provided by crunchbase