Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Arkime Engineer - Active TS/SCI with CI Poly image - Rise Careers
Job details

Arkime Engineer - Active TS/SCI with CI Poly

We are seeking a highly skilled Arkime (formerly Moloch) Implementation & Sustainment Engineer to design, deploy, operate, and enhance our enterprise packet-capture and deep network visibility capability. The ideal candidate combines hands-on Arkime expertise with strong Zero Trust engineering principles to support threat detection, forensics, segmentation, and continuous monitoring across a complex, distributed environment. You will directly improve the organization’s ability to detect threats early, respond faster, and understand network behavior at scale—ensuring that identity-driven, least-privilege policies are backed by deep telemetry and forensic depth

This role will drive full lifecycle engineering—from architecture and deployment to tuning, integrations, sustainment, and long-term optimization—while partnering with cross-functional security, network, and platform teams.

Key Responsibilities:

  • Architect, deploy, and configure Arkime clusters, capture nodes, viewer nodes, and storage subsystems.
  • Design packet capture strategies aligned to network topology, mission requirements, and Zero Trust monitoring needs.
  • Develop and automate deployment workflows using scripts, orchestration tools, and configuration management.
  • Integrate Arkime with SIEM, SOAR, EDR, and threat intel platforms to enrich detection and investigation workflows.
  • Conduct regular tuning of parsers, views, tags, and sessions to support detection engineering and threat hunting.
  • Perform version upgrades, patching, configuration changes, data lifecycle management, and log retention optimization.
  • Align Arkime data capture with Zero Trust Architecture (ZTA) telemetry requirements.
  • Support development of visibility baselines, identity-aware policies, and segmentation enforcement strategies.
  • Work with network engineering, cloud engineering, and security operations to ensure end-to-end telemetry coverage.
  • Develop dashboards, queries, workflows, and documentation for SOC, detection engineers, and incident responders.
  • Provide training, playbooks, and technical expertise to internal engineering and operations teams.
  • 5+ years of experience in cybersecurity, network security engineering, or security operations.
  • Strong background in packet analysis, PCAP management, DPI technologies, and network protocols (TCP/IP, DNS, TLS, HTTP, etc.).
  • Familiarity with Suricata, Zeek, or other packet/flow analysis platforms.
  • Experience engineering within a Zero Trust Architecture (ZTA), including segmentation, continuous verification, and identity-centric access.
  • Proficiency with Linux systems administration, containers, and distributed systems.
  • Experience leveraging SIEM/SOAR platforms and integrating packet telemetry with detection workflows.
  • Familiarity with automation tools (Ansible, Terraform, scripts) and infrastructure-as-code concepts.
  • Active TS/SCI clearance; willingness to take a polygraph exam
  • Associate’s degree and 5+ years of experience supporting IT projects and activities, Bachelor’s degree and 3+ years of experience supporting IT projects and activities, or Master’s degree and 1+ year of experience supporting IT projects and activities. Years of experience may be accepted in lieu of degree.
  • DoD 8570.01-M Information Assurance Technician (IAT) Level II Certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification
  • Ability to obtain a DoD 8570.01-M Cybersecurity Service Provider - Infrastructure Support Certification, including CEH, CHFI, CFR, Cloud+, or CND certification within 30 days of start date

Additional Qualifications:

  • Hands-on experience implementing and maintaining Arkime/Moloch in production environments.
  • Experience with cloud networking and traffic inspection in AWS/Azure/GCP.
  • Experience with Elastic Stack or similar search/index pipelines.
  • Background supporting regulated or high-security environments (FedRAMP, DoD, IC, PCI, etc.).
  • Security certifications (e.g., CISSP, GCIH, GCIA, GNFA, GCED).
  • Strong analytical and problem-solving skills.
  • Ability to translate technical findings into clear operational guidance.
  • Comfortable leading discussions with engineers, analysts, architects, and leadership.

Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients.

Why ENS?

  • Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS
  • 401k Contribution from Day 1
  • PTO + 11 Paid Federal Holidays
  • Long & Short Term Disability Insurance
  • Group Term Life Insurance
  • Tuition, Certification & Professional Development Assistance
  • Workers’ Compensation
  • Relocation Assistance

Average salary estimate

$160000 / YEARLY (est.)
min
max
$120000K
$200000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs

Experienced Endace platform engineer with an active TS/SCI (CI poly) is needed to lead enterprise packet-capture architecture, integration, and sustainment across high-security environments.

Lead the engineering, tuning, and operational support of enterprise IDS/IPS systems (Suricata/Snort/Corelight) on RHEL for DoD/IC customers while holding TS/SCI with CI polygraph eligibility.

Photo of the Rise User

Reflect Orbital seeks an IT Systems & Network Engineer to maintain and secure corporate and mission-critical network and IT infrastructure across office, cloud, and ground station environments.

Posted 10 hours ago

StemWave is hiring a Head of IT & Business Systems to lead IT strategy and hands-on systems integrations (Salesforce, NetSuite, website, cloud) from our Boston office.

Avint Hybrid No location specified
Posted 4 hours ago

Avint is hiring a seasoned Database Administrator to secure, optimize, and manage Oracle, SQL Server, and Sybase databases for mission-critical systems.

Photo of the Rise User
NBCUniversal Hybrid 100 Universal City Plaza, Universal City, CALIFORNIA
Posted 16 hours ago

Lead FCAR technology strategy and operations as Senior Manager, Business Solutions at NBCUniversal, driving cross-functional projects and system reliability for Participations and Residuals.

Photo of the Rise User
Guidehouse Hybrid US - TX, San Antonio
Posted 20 hours ago

Guidehouse is hiring an experienced ServiceNow Technical Lead to architect and lead complex ServiceNow implementations supporting federal clients in San Antonio.

Nooks Hybrid San Fransisco
Posted 7 hours ago

Nooks is hiring an IT Engineer to lead internal IT, device and AV operations, SSO/MDM provisioning, and security/compliance support for its San Francisco office.

Serve as the technical architect leading a comprehensive assessment and modernization strategy for a 52-application School Finance portfolio, producing risk-scored evaluations, architecture diagrams, and a phased modernization roadmap.

Posted 18 hours ago

Trase Systems is hiring a Cloud Security Engineer to secure production multi‑cloud infrastructure, implement cloud-native security controls, and partner with engineering teams to ensure systems are secure by design.

Experienced Endace platform engineer with an active TS/SCI (CI poly) is needed to lead enterprise packet-capture architecture, integration, and sustainment across high-security environments.

Photo of the Rise User
Posted 19 hours ago

Rice University seeks a detail-oriented Support Specialist II to provide high-quality, user-focused IT support and contribute to continuous improvement across campus technology services.

Lead the engineering, tuning, and operational support of enterprise IDS/IPS systems (Suricata/Snort/Corelight) on RHEL for DoD/IC customers while holding TS/SCI with CI polygraph eligibility.

Photo of the Rise User

CloudLinux is hiring a Lead Security Operations Engineer to lead detection, incident response, and threat intelligence initiatives across a global remote infrastructure.

Photo of the Rise User
Posted 12 hours ago

Experienced Systems Administrator needed to manage, monitor, and maintain federal IT infrastructure with hands-on endpoint provisioning and troubleshooting responsibilities.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 13, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!