We are seeking a skilled Network Detection & Visibility Specialist to enhance our network security posture by monitoring Network Detection and Response (NDR) alerts, detecting anomalies, analyzing traffic patterns, and supporting incident response through deep packet analysis. The role focuses on ensuring network visibility, optimizing detection models, and maintaining high-fidelity data distribution through Packet Broker technologies.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Key Responsibilities:
- Network Detection & Response (NDR): Monitor NDR alerts to detect insider threats, suspicious command-and-control (C2) activity, and abnormal network behavior. Establish baseline network traffic patterns to improve accuracy of anomaly detection and fine-tune detection models for improved visibility and reduced false positives.
- Packet Broker & Traffic Engineering: Configure, optimize, and maintain Packet Broker (Ixia) policies for efficient data distribution to security and monitoring tools. Ensure reliable packet aggregation, filtering, slicing, and forwarding for visibility solutions.
- Deep-Dive Network Analysis: Perform forensic packet capture and deep packet inspection (DPI) during security incidents. Support incident response teams by providing detailed packet-level insights and evidence.
- Reporting & Visibility: Prepare and deliver quarterly anomaly detection reports highlighting traffic behavior, deviations from baselines, and detection improvements. Maintain network visibility dashboards and documentation.
Required Skills & Experience:
- Strong experience with NDR platforms (preferably Vectra NDR).
- Hands-on experience with Ixia Packet Broker or similar technologies (Gigamon/Arista/Garland).
- Proficiency in packet capture tools (Wireshark, tcpdump, Zeek, etc.).
- Strong understanding of network protocols, C2 detection, baseline analysis, and anomaly identification.
- Experience working with SOC/Incident Response teams.
- Solid foundation in switches, routers, VLANs, firewalls, and L2/L3 network behavior.