Optiv + ClearShark is looking for a Darktrace Cybersecurity Engineer is responsible for the design, deployment, configuration, integration, tuning, and operational support of Darktrace Cyber AI capabilities across enterprise networks, endpoints, email, cloud, SaaS, identity, and other supported environments. The engineer will work closely with security operations, network engineering, cloud engineering, identity, incident response, and customer stakeholders to improve threat detection, investigation, and response. This position requires a technically strong cybersecurity professional with experience in network detection and response, security monitoring, incident triage, packet and log analysis, security-tool integration, and operational security engineering. The successful candidate will be comfortable working in regulated or federal environments and will translate Darktrace detections, behavioral analytics, and AI-assisted investigations into actionable security outcomes. Darktrace capabilities may encompass network, endpoint, email, cloud, SaaS, and identity telemetry, with AI-assisted investigation workflows and integrations to SIEM, SOAR, EDR/XDR, cloud, and log-management technologies.
How you’ll make an impact- Design, deploy, configure, administer, and maintain Darktrace platform components within on-premises, hybrid-cloud, and cloud-hosted enterprise environments.
- Configure and tune Darktrace detections, behavioral models, alerting thresholds, autonomous-response policies, and investigative workflows to align with the organization’s threat model, risk tolerance, architecture, and security operations processes.
- Lead or support implementation of applicable Darktrace capabilities, including network, email, endpoint, cloud, SaaS, and identity-security use cases.
- Perform ongoing platform health checks, capacity planning, sensor or collector placement assessments, system upgrades, configuration validation, and technical troubleshooting.
- Analyze Darktrace model breaches, alerts, anomalies, incident investigations, device behavior, network traffic, and related security telemetry to identify malicious activity, suspicious behavior, false positives, and opportunities for tuning.
- Collaborate with SOC analysts, incident responders, threat hunters, network engineers, cloud teams, system administrators, and identity teams to investigate and contain security events.
- Develop and maintain use cases for threat detection, triage, investigation, enrichment, and escalation across enterprise security domains.
- Configure, test, and maintain integrations between Darktrace and enterprise security technologies, including SIEM, SOAR, EDR/XDR, ticketing, vulnerability-management, threat-intelligence, identity, cloud-security, and log-management platforms.
- Use APIs, syslog, webhooks, automation, and scripting to exchange security events, enrich detections, automate workflows, and support incident-response processes.
- Support security monitoring and incident-response activities by providing deep technical analysis of network, endpoint, email, cloud, SaaS, and identity-related telemetry.
- Develop standard operating procedures, implementation guides, architecture diagrams, operational runbooks, escalation procedures, and knowledge-base articles.
- Produce clear technical reports and briefings that describe detected activity, risk, root cause, response actions, platform health, tuning recommendations, and security trends.
- Participate in security architecture reviews and advise stakeholders on telemetry coverage, sensor placement, segmentation, visibility gaps, logging requirements, and detection strategy.
- Support validation of Darktrace response actions and ensure automated or semi-automated response capabilities are appropriately governed, tested, approved, and documented before production use.
- Maintain awareness of emerging threats, attacker techniques, security-tool capabilities, AI-assisted defense concepts, and relevant MITRE ATT&CK techniques.
- Support compliance and audit activities by maintaining security documentation, evidence, configuration records, operating procedures, and implementation artifacts required for the environment.
What we’re looking for
- Active Secret clearance required at time of hire.
- Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline; equivalent combination of education, military training, certifications, and relevant experience may be considered.
- At least 5 years of relevant cybersecurity engineering, security operations, network-security, threat-detection, incident-response, or security-platform administration experience.
- At least 5 years of experience with Darktrace or comparable technologies in one or more of the following categories: Network Detection and Response (NDR), Extended Detection and Response (XDR), Endpoint Detection and Response (EDR), Network Security Monitoring (NSM), Security Information and Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Security Orchestration, Automation, and Response (SOAR)
- Email security, cloud security, or identity-threat detection.
- Demonstrated hands-on experience deploying, configuring, tuning, administering, and troubleshooting Darktrace or similar enterprise cybersecurity platforms.
- Strong knowledge of enterprise networking and network-security concepts, including TCP/IP, OSI model, DNS, DHCP, HTTP/S, SMTP, TLS, VPNs, routing, switching, VLANs, firewalls, proxies, network segmentation, and packet capture/analysis.
- Experience analyzing network traffic, packet captures, security logs, endpoint telemetry, authentication events, and cloud audit data to support incident detection and investigation.
- Experience with security operations processes, including alert triage, investigation, threat hunting, incident escalation, containment, evidence collection, reporting, and post-incident lessons learned.
- Experience integrating security tools with SIEM and SOAR platforms, such as Microsoft Sentinel, Splunk, IBM QRadar, Elastic, ServiceNow, Microsoft Defender, Palo Alto Cortex XSOAR, or similar platforms.
- Working knowledge of API-based integrations, REST APIs, JSON, webhooks, syslog, authentication methods, and log-forwarding concepts.
- Experience with Linux administration and command-line troubleshooting; familiarity with virtual machines, virtualization platforms, and common enterprise operating systems.
- Ability to develop basic automation or integration scripts using Python, PowerShell, Bash, or a comparable scripting language.
- Strong written and verbal communication skills, including the ability to document technical designs, explain investigation findings, and brief technical and nontechnical stakeholders.
- Current Darktrace certification, particularly the Darktrace Cyber Engineer Professional certification or equivalent Darktrace training.
- Experience with Darktrace / NETWORK, / EMAIL, / ENDPOINT, / CLOUD, and / IDENTITY; Cyber AI Analyst investigations; Threat Visualizer; and autonomous-response capabilities and policy governance.
- Experience with Microsoft security technologies, including Microsoft Defender XDR, Microsoft Defender for Endpoint, Defender for Office 365, Entra ID, Microsoft Sentinel, Azure, and Microsoft 365.
- Experience with cloud-security monitoring and engineering in AWS, Azure, Azure Government, AWS GovCloud, Google Cloud Platform, or hybrid-cloud environments.
- Familiarity with identity-security technologies and authentication telemetry, including Active Directory, Microsoft Entra ID, privileged access management, SSO, MFA, federation, conditional access, and identity threat detection.
- Experience working in Department of Defense, intelligence community, federal civilian, defense-industrial-base, or other regulated environments.
- Knowledge of NIST RMF, NIST SP 800-53, NIST SP 800-171, NIST Cybersecurity Framework, DoD STIGs, CMMC, FedRAMP, FISMA, DFARS, or other federal cybersecurity requirements.
- Experience supporting classified, air-gapped, disconnected, constrained-connectivity, or highly segmented environments.
- Familiarity with the MITRE ATT&CK framework, cyber threat intelligence, threat hunting methodologies, intrusion analysis, and adversary tactics, techniques, and procedures.
- Relevant certifications such as CISSP, CISM, Security+, CySA+, CEH, GCIH, GCIA, GCED, CCNA, CCNP, PCNSE, AWS Security Specialty, Azure Security Engineer Associate, SC-200, SC-100, Splunk Core Certified Power User, or comparable credentials.
- Strong analytical judgment and ability to distinguish normal business activity from potentially malicious or anomalous behavior.
- Ability to explain AI-assisted or behavior-based detections in understandable operational and risk-based terms.
- Ability to work independently while coordinating effectively across SOC, infrastructure, cloud, identity, network, and leadership stakeholders.
- Strong attention to detail in configuration management, change control, evidence collection, documentation, and production implementation.
- Ability to manage competing priorities, support time-sensitive incidents, and maintain disciplined escalation procedures.
- Commitment to secure engineering, operational rigor, continuous improvement, and customer mission success.
What you can expect from Optiv
Work/life balance
Professional training resources
Creative problem-solving and the ability to tackle unique, complex projects
Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
The ability and technology necessary to productively work remotely/from home (where applicable)
EEO Statement
Optiv + ClearShark is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.
Optiv + ClearShark respects your privacy. By providing your information through this page or applying for a job at Optiv + ClearShark, you acknowledge that Optiv + ClearShark will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv + ClearShark’s selection and recruitment activities. For additional details on how Optiv + ClearShark uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.
Skills Required
- Active Secret security clearance at the time of hire
- Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related discipline, or equivalent education, military training, certifications, and experience
- At least 5 years of relevant cybersecurity engineering, security operations, network security, threat detection, incident response, or security-platform administration experience
- At least 5 years of experience with Darktrace or comparable NDR, XDR, EDR, NSM, SIEM, UEBA, or SOAR technologies
- Hands-on experience deploying, configuring, tuning, administering, and troubleshooting Darktrace or similar enterprise cybersecurity platforms
- Strong knowledge of enterprise networking and network-security concepts, including TCP/IP, DNS, DHCP, HTTP/S, SMTP, TLS, VPNs, routing, switching, VLANs, firewalls, proxies, segmentation, and packet analysis
- Experience analyzing network traffic, packet captures, security logs, endpoint telemetry, authentication events, and cloud audit data
- Experience with alert triage, investigation, threat hunting, incident escalation, containment, evidence collection, reporting, and post-incident lessons learned
- Experience integrating security tools with SIEM and SOAR platforms
- Working knowledge of APIs, REST APIs, JSON, webhooks, authentication methods, syslog, and log forwarding
- Experience with Linux administration and command-line troubleshooting
- Ability to develop automation or integration scripts using Python, PowerShell, Bash, or a comparable scripting language
- Strong written and verbal communication and technical documentation skills
- Current Darktrace certification, particularly Darktrace Cyber Engineer Professional certification, or equivalent Darktrace training
- Experience with Darktrace network, email, endpoint, cloud, identity, Cyber AI Analyst, Threat Visualizer, and autonomous-response capabilities
- Experience with Microsoft Defender XDR, Microsoft Defender for Endpoint, Defender for Office 365, Entra ID, Microsoft Sentinel, Azure, and Microsoft 365
- Experience with cloud-security monitoring in AWS, Azure, Azure Government, AWS GovCloud, Google Cloud Platform, or hybrid-cloud environments
- Familiarity with identity-security technologies, including Active Directory, Entra ID, privileged access management, SSO, MFA, federation, and conditional access
- Experience working in Department of Defense, intelligence community, federal civilian, defense-industrial-base, or other regulated environments
- Knowledge of federal cybersecurity requirements including NIST RMF, NIST SP 800-53, NIST SP 800-171, DoD STIGs, CMMC, FedRAMP, FISMA, or DFARS
- Experience supporting classified, air-gapped, disconnected, constrained-connectivity, or highly segmented environments
- Familiarity with MITRE ATT&CK, cyber threat intelligence, threat hunting, intrusion analysis, and adversary tactics, techniques, and procedures
- Relevant certifications such as CISSP, CISM, Security+, CySA+, CEH, GCIH, GCIA, GCED, CCNA, CCNP, PCNSE, AWS Security Specialty, Azure Security Engineer Associate, SC-200, SC-100, or Splunk Core Certified Power User
- Ability to explain AI-assisted and behavior-based detections in operational and risk-based terms
- Ability to work independently across SOC, infrastructure, cloud, identity, network, and leadership stakeholders
- Ability to manage competing priorities, support time-sensitive incidents, and follow disciplined escalation procedures
Optiv Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Optiv and has not been reviewed or approved by Optiv.
-
Retirement Support — Immediate vesting with a clear 401(k) match and a solid retirement setup are emphasized in official materials. This positions retirement benefits as a dependable part of the total package.
-
Leave & Time Off Breadth — A flexible, no‑accrual “Recharge” policy for eligible exempt roles and traditional PTO for non‑exempt roles are highlighted. Hybrid/remote flexibility also appears frequently across role descriptions.
-
Healthcare Strength — Comprehensive medical, dental, and vision options with FSA/HSA (including a company HSA contribution) are described. Company‑paid life, AD&D, and short‑/long‑term disability further strengthen core protections.
Optiv Insights
What We Do
Optiv is a security solutions integrator – “one-stop” trusted partner with a singular focus on cybersecurity. Our end-to-end cybersecurity capabilities span risk management and transformation, cyber digital transformation, threat management, security operations, identity and data management, and integration and innovation, helping organizations realize stronger, simpler and more cost-efficient cybersecurity programs that support business requirements and outcomes. At Optiv, we are modernizing cybersecurity to enable clients to innovate their consumption models, integrate infrastructure and technology to maximize value, achieve measurable outcomes, and realize complete solutions and business alignment.


.png)





