An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Optiv + ClearShark is seeking a Darktrace Cybersecurity Engineer to design, deploy, configure, and operate Darktrace Cyber AI capabilities across enterprise networks, endpoints, email, cloud, SaaS, identity, and other environments.
You will translate detections and AI-assisted investigations into actionable security outcomes while working with SOC, network, cloud, and identity teams in regulated environments.
Optiv + ClearShark is looking for a Darktrace Cybersecurity Engineer is responsible for the design, deployment, configuration, integration, tuning, and operational support of Darktrace Cyber AI capabilities across enterprise networks, endpoints, email, cloud, SaaS, identity, and other supported environments. The engineer will work closely with security operations, network engineering, cloud engineering, identity, incident response, and customer stakeholders to improve threat detection, investigation, and response. This position requires a technically strong cybersecurity professional with experience in network detection and response, security monitoring, incident triage, packet and log analysis, security-tool integration, and operational security engineering. The successful candidate will be comfortable working in regulated or federal environments and will translate Darktrace detections, behavioral analytics, and AI-assisted investigations into actionable security outcomes. Darktrace capabilities may encompass network, endpoint, email, cloud, SaaS, and identity telemetry, with AI-assisted investigation workflows and integrations to SIEM, SOAR, EDR/XDR, cloud, and log-management technologies.
Design, deploy, configure, administer, and maintain Darktrace platform components within on-premises, hybrid-cloud, and cloud-hosted enterprise environments.
Configure and tune Darktrace detections, behavioral models, alerting thresholds, autonomous-response policies, and investigative workflows to align with the organization’s threat model, risk tolerance, architecture, and security operations processes.
Lead or support implementation of applicable Darktrace capabilities, including network, email, endpoint, cloud, SaaS, and identity-security use cases.
Perform ongoing platform health checks, capacity planning, sensor or collector placement assessments, system upgrades, configuration validation, and technical troubleshooting.
Analyze Darktrace model breaches, alerts, anomalies, incident investigations, device behavior, network traffic, and related security telemetry to identify malicious activity, suspicious behavior, false positives, and opportunities for tuning.
Collaborate with SOC analysts, incident responders, threat hunters, network engineers, cloud teams, system administrators, and identity teams to investigate and contain security events.
Develop and maintain use cases for threat detection, triage, investigation, enrichment, and escalation across enterprise security domains.
Configure, test, and maintain integrations between Darktrace and enterprise security technologies, including SIEM, SOAR, EDR/XDR, ticketing, vulnerability-management, threat-intelligence, identity, cloud-security, and log-management platforms.
Use APIs, syslog, webhooks, automation, and scripting to exchange security events, enrich detections, automate workflows, and support incident-response processes.
Support security monitoring and incident-response activities by providing deep technical analysis of network, endpoint, email, cloud, SaaS, and identity-related telemetry.
Develop standard operating procedures, implementation guides, architecture diagrams, operational runbooks, escalation procedures, and knowledge-base articles.
Produce clear technical reports and briefings that describe detected activity, risk, root cause, response actions, platform health, tuning recommendations, and security trends.
Participate in security architecture reviews and advise stakeholders on telemetry coverage, sensor placement, segmentation, visibility gaps, logging requirements, and detection strategy.
Support validation of Darktrace response actions and ensure automated or semi-automated response capabilities are appropriately governed, tested, approved, and documented before production use.
Maintain awareness of emerging threats, attacker techniques, security-tool capabilities, AI-assisted defense concepts, and relevant MITRE ATT&CK techniques.
Support compliance and audit activities by maintaining security documentation, evidence, configuration records, operating procedures, and implementation artifacts required for the environment.
Optiv + ClearShark is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.
Optiv + ClearShark respects your privacy. By providing your information through this page or applying for a job at Optiv + ClearShark, you acknowledge that Optiv + ClearShark will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv + ClearShark’s selection and recruitment activities. For additional details on how Optiv + ClearShark uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.
We work alongside clients to manage cyber risk and equip them with perspectives and programs to accelerate business progress. Our real-world experience, deep vertical expertise and diverse teams enable us to face any challenge with confidence. We put you at the center of our unmatched ecosystem of people, products, partners and programs to design and implement agile solutions. Our adaptive approach continually assesses risk in the context of cyber and broader objectives to secure today's business and fortify it for the future. At Optiv, we manage cyber risk so you can secure your full potential.