Senior Network detection and Response Engineer

UnitedHealth Group•Plymouth, MN
•$91,700 - $163,700•Remote

About The Position

The Senior Network Detection & Response Engineer supports the operational health, visibility, and performance of the enterprise NDR platform, combining security operations expertise, strong networking fundamentals, and the ability to build modern monitoring and observability tooling. This engineer serves as a platform owner and builder, delivering a reliable, well-instrumented NDR platform to Security Operations, Incident Response, and Detection Engineering teams. You’ll enjoy the flexibility to telecommute from anywhere within the U.S. as you take on some tough challenges.

Requirements

  • High School Diploma/GED
  • 4+ years of combined experience in network engineering and/or information security, with a primary focus on network traffic analysis, network security monitoring, or threat detection
  • 3+ years of hands-on engineering and administration experience with enterprise NDR technologies (e.g., Corelight, Zeek, Suricata, ExtraHop, Darktrace, or similar tools)
  • 3+ years of hands-on experience with network protocols and architecture, including TCP/IP, UDP, VLANs, routing and switching, packet-level traffic analysis, and working directly on enterprise network device CLIs (e.g., Cisco, Arista, Juniper)
  • 1+ years of hands-on experience administering and troubleshooting Linux systems from the command line

Nice To Haves

  • Bachelor's degree
  • Experience with tap/SPAN architectures and packet broker platforms (e.g., Ixia, Gigamon, Arista)
  • Experience developing Zeek scripts and Suricata rules in a production environment
  • Experience integrating security telemetry with SIEM or log aggregation platforms (e.g., Splunk, Elastic)
  • Experience with network traffic visibility in a cloud environment (e.g., Azure, AWS, GCP), including VPC/VNet traffic mirroring
  • Nice to have knowledge on Rest API: (GET, POST, PUT, DELETE, JSON payloads, OAuth, Bearer tokens)

Responsibilities

  • Design, deploy, configure, and maintain enterprise Network Detection & Response (NDR) sensors, appliances, and Zeek-based detection pipelines, ensuring alert and log data delivered to SOC and Incident Response teams is complete, accurate, and timely
  • Proactively identify and root-cause network visibility gaps — including incomplete tap/SPAN coverage, asymmetric routing, redundant HA links, and one-sided flows — using Zeek/Suricata log analysis, traffic volume baselines, synthetic traffic validation, and monitoring dashboards
  • Partner with Network Engineering, Packet Broker, and application teams to validate tap/SPAN placement, remediate traffic engineering issues, and onboard new network segments into the NDR architecture
  • Build and maintain platform observability using Python, REST APIs, and time series databases to monitor sensor health, data ingestion, packet throughput, and drop rates
  • Create and modify Zeek scripts, Suricata rules, and associated detection content packs in response to customer and stakeholder requests, collaborating with Detection Engineering on broader rule strategy and coverage
  • Define and maintain SLIs/SLOs for platform reliability and data quality, and develop technical documentation, standard operating procedures, and operational guides for NDR administration
  • Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement
  • Participate in an on-call rotation supporting platform availability and incident response escalations

Benefits

  • comprehensive benefits package
  • incentive and recognition programs
  • equity stock purchase
  • 401k contribution
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service