Job Description
Hi,
This is Sam Simadri from Ursi Technologies Inc. We have a very urgent opening with one of our premier clients and an immediate interview schedule for qualified resources, based on their availability. We are looking for someone who can start this project immediately. Please go through the below requirement and let me know your concern.
Since this is an urgent business requirement, I’d appreciate a prompt response on this
Title: Zeek Administrator
Location: CA (Remote)
Duration: 12 Months (C2C)
Job Description:
A Zeek Administrator is responsible for deploying, configuring, and managing the Zeek Network Security Monitor (formerly known as Bro).
Zeek is an open-source network monitoring framework that analyzes network traffic for detailed visibility, intrusion detection, and security monitoring.
As a Zeek Administrator, your role involves configuring Zeek for optimal performance, integrating it with other security tools, and maintaining its operations for network defense.
Key Responsibilities:
* Deployment and Configuration:
Install and configure Zeek on servers or network sensors. Set up network taps or packet captures to feed network traffic data into Zeek for analysis.
Fine-tune Zeek scripts to customize network traffic analysis based on organizational needs.
Optimize performance by adjusting configurations related to logging, packet processing, and resource allocation.
* Network Monitoring and Traffic Analysis:
Use Zeek to monitor network traffic, including HTTP, DNS, FTP, SSH, and other protocols.
Analyze Zeek logs and events for anomalies, suspicious activity, and possible security breaches.
Investigate network behavior and identify potential threats like intrusions, malware, or data exfiltration based on Zeek data.
Use Zeek logs to gather in-depth metadata and behavior patterns for threat analysis, such as communication flows, DNS queries, or encrypted traffic.
* Security Event Detection and Incident Response:
Configure Zeek for intrusion detection by implementing detection logic and writing custom detection scripts.
Set up alerts and notifications to identify security incidents, anomalies, or threats in real time.
Integrate Zeek with SIEM (Security Information and Event Management) systems like Splunk or Elastic Stack for centralized log management and correlation.
Perform threat hunting by using Zeek logs to analyze historical network activity and identify threat actors or patterns.
Collaborate with security teams to respond to incidents detected through Zeek.
* Customization and Scripting:
Write and modify Zeek scripts using Zeek s scripting language to extend detection capabilities or automate specific network traffic analysis.
Implement custom detection policies for industry-specific threats, compliance monitoring, or advanced persistent threats (APTs).
Customize logging formats and output options to tailor how network data is logged and stored.
* Integration with Security Ecosystem:
Integrate Zeek with other network security tools, such as IDS/IPS systems (Snort, Suricata), threat intelligence platforms, and endpoint protection solutions.
Leverage Zeek plugins to extend functionality or integrate with third-party tools (e.g., exporting logs to Kafka or Elastic Stack).
Set up and manage Zeek clusters for high-performance environments, balancing network traffic load and managing multiple Zeek nodes.
Integrate with packet capture tools such as PCAP, Wireshark, or tcpdump for deeper packet-level analysis.
* Maintenance and Performance Monitoring:
Regularly update Zeek and its packages to ensure the latest features, bug fixes, and security patches.
Monitor the performance of Zeek, ensuring it scales efficiently with increasing network traffic.
Ensure logs are archived, stored securely, and managed properly for compliance and forensic purposes.
Perform troubleshooting on issues related to traffic analysis, logging, or Zeek’s performance.
Monitor disk usage and optimize log retention policies to balance the availability of historical data and storage capacity.
* Collaboration and Documentation:
Collaborate with network and security teams to ensure Zeek is aligned with broader network security strategies.
Document Zeek configurations, custom scripts, and incident response procedures for the organization.
Train and support security operations teams in using Zeek and understanding its output for monitoring and detection purposes.
Key Skills and Tools:
Zeek Framework Expertise: Strong knowledge of installing, configuring, and managing Zeek in various environments. Network Traffic
Note: If you are not comfortable with the requirement, I’d appreciate your help. Please take a look and forward this job on to anyone you think would be interested in the position, or anyone else who could help me find a candidate.
Thanks & Regards
Sam Pariga
Sr. Recruitment & Talent Acquisition | Ursi Technologies Inc
Direct No: / Extn – 843
E-mail: OR
Website:
5440 McGinnis Village Place, Suite 102. Alpharetta, GA, 30005
<img id="x_image_0_0" class="Do8Zj" tabindex="0" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAu4AAAC4CAYAAAC8VWkJAAAAAXNSR0IArs4c6QAAIABJREFUeF7snQe4HFXZx//nTNmd3b01vZAAqSYQei+GIghSxBAIgggqiBASOiIgERABUSAUAVGa8kkHBUFqaAIGCIQQUkkICam3b51yzve8s7sQQsruvVvvPfM8+4SHe+aU/zkz85t33vO+DOpQCigFlAJKAaWAUkApoBRQCigFKl4BVvE9VB1UCigFlAJKAaWAUkApoBRQCigFoMBdLQKlgFJAKaAUUAooBZQCSgGlQBUooMC9CiZJdVEpoBRQCigFlAJKAaWAUkApoMBdrQGlgFJAKaAUUAr0HAXouS97znA7NVKlUadkUyeVQgEF7qVQWbWhFFAKKAWUAkoBpYBSQCmgFOiiApsE997H9z4iMCawu2h349B6qC8840yr0QItL7X8N/ZK7D9d1LpEp0/jw3cM/YTr1mBXekkO1iNfzhiYJmEbtrvi4WUf3vhxicTfoJnGWis89aeM9Q0xFrVR1LngZEHTJKsx3ORDj9r2i5+UZ8w9u9VAzbSRmmw4njHPAYQovhoB7knXEPYnj9j2XfNybU8Pfu8A0zx2fybbkoCrrK+5CldV5QIAOuC6nzhgdQld3y3qeqvXGExf4Zl92xLNjWuBw1NVNaSid/ZOIxTS+7i8vY7L+EDNHNffdRaG4c0McT7a4LyRAUqyok9DlxvQOcCl5zz9cDL5/JKuVSdZsPaGE7kIbMuYEwck71p9Wzrbk1L2DQn3zdeTybtf3ljpTULdkOuH/K32gJoT7TU2mN7z2I8xBuEJaH05Oh6JPrD82hUnb0nuSvj7LqdLw1wWna1HI6NdHWA99JHMGX0LttEaf/2Uj/938H3lmZvRW0caHlii6dtAylYAxbzefW4H1wYh1vbjHzvJB+8vz5h7dquRxpnHct7/EYCY3SuyGBKMWZAyBSf50gmJ6M/+kWuDgdBFf7IiV50h5GpAurmepspVlQLpe4KE6a9FKdoypoOkLWViNRBc4iXf+Bis/XWh1b+bap+6sKqGV6DOBusu20Z4zm6arN9HMw/eXiK+DWOh/oyFglI6AAuDsTAAG8y/pnseDxVI6hJWY4DxMKJtp37PSz317641LFltn4VvMoT2kjJZ5Oc49dQB50PhJB+8Odb+k3PyAveBlw68pWbvmslukwOm9ZyFKiHBOIN0JZJtSQw/djhan2qb/uHPP5zatckvzdkTJz6sLeq154vG+/XjPREDM7Ue6M1IQBOCRByx5Ms/+OT9E54ojfobtjJyULj+pre5NmSwlG1FvuCz4N4PsbZzJ3j2E4+XZ8w9u9Vw49OHMvR7Lg3uxTa40zoPQkobwn39iHj7hc/kqr4Z+sVVwdBFlwmxtgQvGLn2SpUrrAJ0T6Bnd9ZgQP/qYIws8TqkjILxOv/vUqxcDdn2AWP9nncTNz2USNy/orB9qazawuF7+gsNEzmvO4TxfjszPmggPSjJwMJAkO5BIglIAvXsCzjp2UMtYZU1fTn0RgfjIZGInnewm/zPKzmcsNkikYY3nmTcOro04O6C84Fw7SeujLdfcEV+4P7rgbfW7l1zltPDwJ0s7QTv8XVx9N+hP7bfZ3vMuv2D6bPPml0l4C61RSNWvawvqt0fC9qBMFlbetrNJmOJRBwdqZcnzJs5qUwQS+B+yztcGzKodODeH7G2cyZ49qNlGnNXb5HVfX648bnvMvR9Nn3NlcLingF3580j4x3nPJ2remZo8tXB0MWXCrGmBP3MtVeqXHEUyAI81Z6Fz/SLfhrsGRgzAWYBMkFAv8ZzFv7Vw8z77I5bc3a/Kk7fC1troGbqKI3teKKmj/kJYA0Cj2TGTJZU0iT7pSxrrEzro45qU4As7pZIRM8/2E0+UwBwf/MpxsNHlQ7cB8G1H7sy3n6eAvdcl16iJYHGYY0Y/Z3RCCCAd2+cNX3eeXOrB9wHffGyZvbfH/9bB9bOgZDvN9KDDgXuCtzLs9wVuJdHd9VqVxXIPiAI4oMAq6EXuqTrvHqb5s28Phq9g97wqvYIh6f2E/p2F2rGgb9goM+x7f6Xqq8ejArOq3ZyN9pxBe49w1Umc93Gm+Ko36Yeow8d7b9o69Ax58aPp8+tJnDv+/nLemir/b2mKLSPYoBu0D6N7nVdbnY0CtwVuJdnuStwL4/uqtVCKUAPwozVmUXAeQOk1/Kp57zyu3jH1LsL1Uop6wnV3nGmpu9zAdPqtpGiBVLGMu5D9MWhJz0XS6l6udtS4N7twZ0RoWtAojmBSP8IRh06CnpAhy1shHkIs2+cU13g3m/5y7o2eH/PlOCLmsGWCiCsA7LYPrflvliz7StwV+BenrWowL08uqtWi6FA+nnBeB9/A7PnvvFnk7Vf1Np6Lu20r/gjEvl9X6mNuJnrIyelffpbMqBezCABFS9LD+mgAvfuD+6c+RtRA7UBjD1yLAzLQMpLgfzdLW7ho2oEdz54f49TAEIbfGYzkNSBIAdkT7AwKHBX4F6e55MC9/LorlotpgIeGG1q1fpDeMtnS/n5SbGW4z4qZotdrduquXUv3djvPsbrR6T3cVDkJLKwq6NnKKDAvVuDO0WQIZ/2QE0AY44cg0AkgKRIgkny9atycHclWJgB6zrAZ5PLjAnoCtxLd+NSm1NLp3VltKTAvTLmQfWi0AqkN1szVg8wo9lO/P3EVGzac4VupRD1heruOY1rO9zEeF1IilUAjEJUq+qoKgUUuHdbcOcah91ugxkMo747CrV9ahH34rTHPv2JsOrBXYBpHNKSYB83gX8hgFBPsDooi7uyuJfnKaPAvTy6q1ZLoUAmIg2rBWNawk488P1U7OrnS9Fyrm1YtfedbZjjp0vZASnb/bCX6uiJCihw75bgTrHpnZgDIQS+dcS3UNenDgmR+NpelaoHd0+kX0IMBngp8FmtgG3Az8fRrV1mFLgrcC/Pw0qBe3l0V62WUgGyvNcCLNLhJO89Ohm9osvh9grR+3D9c+dr+sgbyJfdT5xU1IR3heixqqN4Cihw73bgTu4xdsyGFBIjDh2BxkGNSIkU5AYw2y3AnWXC5VBIyJVt4HOSgGV085SqCtwVuBfvkbC5mhW4l0d31WqpFXDTbjO8sd1zHfb50yq9Q9WL+9UN1fTteNA+8UlKFapjL+7D3BLbScqldy2wrcuxW4E7S7KRdOwsG247fFgBEDfPeYjR3dCtwp+63pgc9uAtZSbPfuvFFVgbsC9/I8VBS4l0d31Wo5FBBgrAYcfE6b99B+aJ1WlmgzwcjpB5jWZS8L0eInU1KW9nKshUprU4F7twF3gnbP8fwIMsMOGoYBIwcgKZOQntxocrRuBe6CARaAVBx8Zgcg9LTLTLc8FLgrcC/PwlbgXh7dVavlUCCdaZTxwfCctx6Ptx03odS9CNY9tq1h7PAGZHIA+bWryDGlnoFKbU+Be7cAd4JwL+UhFUth6L5DMXi7wX70mA3dY9Zfht0K3GlgdJ+lKDPLWsAXOEBQ76YuMwrcFbiX54GiwL08uqtWy6mABOP9IJzXfxlr+9F1pevJeD3S8Lu3mdZ/l3T0GNqIqtxjSqd/JbekwL3qwZ0AnPzZ481xDNptELbdbVvf0u4Klz7zbXL1dUtw1xik4YLPbgFr5mkrfLe71ylwV+BenoeKAvfy6K5aLacCGZcZFk64iSf3jMXOmV2K3gRr/nCtGZx0sfC+6I4PsVJI2I3bUOBe1eBO8E1HbF0MA3YagG332hYppCBcutlkNm5uYvl2O3DPjtNikB1xaO+2Z2K7d7coMwrcFbiX55mkwL08uqtWy62AC84HQIpVMzuaJ+8DvEdhXYp2BCPT9jetya8Kb4kfX175tRdN6iqtWIF79YI7cbmAn2Cp97d6Y8T4EfDgwfGcL2O1b25VdltwpxCRYQCLm8EXuUC4u31iVOCuwL08zxsF7uXRXbVabgXSMd4ZHwjPfnNyvP2E24rXo6Nqwg1T32B80DjIZhWrvXhCV3HNCtyrE9wJ2hmQWJdAwzYNfoIlCQnbs3OCdlqx3Rbc6R5Lsd11B3xmM9CRjTJTxdfp17quwF2Be3nWsgL38uiuWq0EBTyA1UHKjlWx5AU7I/76ymL0Klh762VmYOJVaWv7pl1di9G2qrNaFFDgXn3gztLQHW+Jo25QHUZ9ZxSYyfKC9m4N7jQ4ASDEIJs7oM2OAYaR3pDfLfzdFbgrcC/PA0aBe3l0V61WggJkLfPA+bZw7SdvjbeffnbBexXZu28keNcCBqNOUvhHBe4Fl7h7VKjAverAnaA90ZpAqE8IY743BpqpIeWlcra0Zxdut7W4ZwdIkB4CsKgZfKmXdpnpFhlVFbgrcC/P40eBe3l0V61WigJ0762FhGh3ohfsnEo9u7iQPbPq779Z1w+eIsUyBe2FFLbb1aXAvarAnWnM92kP1AQw9oixMCMmkl4yb2jv9hZ3GiCBe4ABwk67zNgGEOgOVncF7grcy/MkUuBeHt1Vq5WkgADXhsFJ/v33iY5zLipYz4IHD4mEb/uQQdRLypDqfyJWh1JgYwoocK8acCdoT7WnoAd1jD5sNMINYSTcxBajx2xq4Xd7i7sP7wwyDLDV7eAfxQHTBLRq95dR4K7AvTyPMwXu5dFdtVpJCnhgvBFSeE3R5kljgNlrCtE7q+a3F+uBn1wrxae0SasQVao6uq0CCtyrAtwpK6rdYYPpDKOPGI3axlokPEp/3PmjR4C7Lw8DQhJsThPYFwIIV7slQ4G7AvfOX/ddOVOBe1fUU+d2DwUyGVW1rWHHpp+Riv/uzq6P65BwpPE3s8BqR0C2K2t71wXt5jUocK94cPehPWZDehKjDhuFhoENXYZ2H2cZg8UtfHTjnOlzz5s7tRpW+sSJUlvUb/nLOh+8v+dtOVa9PybaqBpkQCoJPqsV8EzAlOn/X5WHAncF7uVZuArcy6O7arXSFHDAeF8Ib9HrsZbD9u9q78zItGPNwA8fgWzrDr6cXZVDnb9FBRS4VzS4E7S7KRdO0sHIQ0ai95DeSIhEQaKj9Bhwp4tAZmK7r2gFn5sCQgbAZEF03OI1VvACCtwVuBd8UeVUoQL3nGRShXqEAhoYiyARv2gfN/HUf7syZKvu/n8YxsHHC/F5+guxOpQCm1VAgXvFgjv5tLsJF07cwbCDh6Hfs+tEspO7UZdcN10KPAnQbPGWB6YLObwNZyIMyrNMqMAncF7uV5rilwL4/uqtVKVECC863hpP52faLj/Is73cPaQxsj2iUfMD5oK+knXFLg3mkte8yJCtwrE9wZ4Dke7KiNofsOxeCxg5GSKQhROP+OHgfu5JpILjPJBPhM+iRpVOkeIAXuCtzL84RS4L4l3en+TDcaBV9bUqowf89kIixMZXnWQuA+AJ774cxY65F7dNbHJRA+87sB67JnhVgFwM2zD4UqrtZtoZQsTT0E7kGRiJ5/kJt8bkZX24w0vPkU4+GjpEyWIAypC84HwbUfuzLeft4VG+v7Ju+eA3898NbavWvOcpqcigN3AmoCdAr7uNUeW2HozkORRBKCfLoL+EDoceDurxDaqAqwJS1gi+y0y0zVZWVS4K7Avau36s6dr8B9U7oRrHMwFsxEBKFHT7VHr+rcGinNWWl906BBv3IAvARYBEy60VT06j1s+5G5nRl7IPz7603r+AulWF2GNUPAzsBYOLNu1ZrtzByW/hwTjIcQbz/tUDf1r+e72r4C9y4qSD7t0pV+gqVBuwzC0N2HwpY2POEVFNp9hO0pm1PXnxO6L2kMUnfBP2oCa9YBi1WZy4wCdwXuXbzRdPJ0Be6bFa5DMmMuvFYOblN+606qrE7bsgISTLIwY32HMF4XFjIG0C9rnNlyBQUqoYFpg+F0XHJqMvnXe/OvdJoeqd/nBaYNHi/9jak8/yo6dUY6Mg7n/QHo8LwlK8FiKyA0Se+fnapSnVQ6BaSfCt61k7ef5ST+8U5XG64acB982eBba/aJnJVqSYHzUl0sW5CX+FFIJFuS6Putvhg+fjhcuHA8p+DQ3mPBnQbuZ1RlkK1RaO9HAcME9GraqKrAXYF7V2/VnTtfgfvGdWO8AcL54NVY22uHAh8x4JNqjznbuQVSkrOyiTiSuml+ayvD+vFR3Dj452AYKj2yWtPzvFTsSe4yQ+A6D/8l3jb1Z3kPP3TogEjwt+8yVjdQynUlCgNJD0APnA+F8D6d56Ye+0My/ubTAPmPDgbgVAgQ5a1mDzpBZBb4WooJ7nV14FUF7o17NJxlN9mQhoSndXnsXdMuMw2JpgQahzVi9HdGw2EOXM8tCrT3aHDPWGUkucwsbAJf4gFhvQyfKTu7ZBS4K3Dv7Nrp2nkK3DemnwTXBsO1Z7wYbzvxO11TWJ3dGQUs64xBLHDQPZqx93ek95lvRS7NQQA8AMKZ91a07eYDgGdT+bRrWOfuHgyd6ltMpYyXyOJOCaT6Q3gL34u1nHkYsGhtPn1WZbufAlUD7tbN1q3W/tZZocUWAl4AuquDCw7JJAQX/q9kh/9RlSHeHEfjto0YftBwP9txsSzt2XH1SFeZ7ODJ6GAwgDvg77UAUZ7euFoVhwJ3Be7lWagK3DcF7gPh2G/OSLRNOqA8M6NaBcYHw41XvqrxobsLsaJE8E65RBogWWKdG71y12TycXpryPkI1v7+JMM4+oG0m0wp/MvTzw7wXk1Ox5Tdk8nHKE2rOnq4AlUD7trt/Fbve+Is9gVgSANWwvJ/oXgIpm2S/9zXIJ6Anv5fMQ4CaNqIGuobwpjvjYFu6kh6yaJZ2hW4ZxSgd7MwA1vbATYnDpDbFzbOrq0iBuwL3rq6hzp2vwF2Be+dWTmnOMqyzdw+Gzvwv4GhSkhdBcZ7ZX42G7sUmgTASLRP2cd2ZecVzN8O/vCRgnX2NFKX6SkD97QfhffyXWOv38nftKc00qlZKrEDVgLsxXbsVh/Gz5GoBYZKFPQ1smsdhJS1Y8TTEB5NB3xJP0E7uNIV2qaHNqATtVoOFMUeMgW7psF27+Pebnro5dcMLgjHAEmDzmsGWSyCkVcFGVQXuCtxLfGfPNKfAXYF7eVZe7q2G6h58XDfGH1OaZEZpbqANqsmOK37sJO++P/eeAlbtX27WzfFT0hFlSuHew8F5PyTbL/i+bT/0VD59VWW7rwJVB+5YJf3r5WsWdk34H624YL71/UuITwVhOIZfVjAByaVvladfZw6C9mR7EoHaAEYfNhrBSBBJN+lHeynF0aNdZdYX2GSAmwJ7twXMNgCK6Na5KS3FtPmdo8+dEnF0pF6eMG/mpMdL1PAGzYwcFK6/5R2uDRlU/IgIfjggcK0/Ym3nTFDgXp4ZV+CuwL08Ky/3Vq3av56gGbs/CN/iXoobuQvGt0Iqce+v7Njlv8u9p4BV/9QDujbyJClbS7AxlcJXhgBEm6NNZ+4MzMrLrSefcamy1aVA1YJ7VuasO0zW193TRNr6LQDT+cqlhmA+YAd8azz5w1N5ssbn6lJDkWxS0ZTvyz72iLGINEYQ9+JFd49ZfzkpcM+oQW5RYYCtagP/KAkE9dJF5erU9a3AXYF7pxZOl09S4K7AvcuLqNgVhI4aGAme8yFY397pEJHFNoQ5fkIZJ/n0LYno5Cn5DC/c67//5AgfmXbrKXYwF/LHb4QU89+Othy5byGikeQzVlW2chWoenDflLRfbVqV/m2AexoCqQDCsRBCsRCCdhCap1FKCB/gN7u5lQFOzIGUEqOPGo263nVIuImSWdq/fEnpiXHcN/7cTcd2J5eZ2U3g9BUmTC4zlXqhKXBX4F6etanAXYF7eVZefq1GGl7+D+P9DpGyvQSWbAL3/nCctx9MtJ14Yu49lSzS+NYLjIUPKg2405eBfvDs//0z3n7C0bn3U5Xs7gp0W3Bf3yL/NWt8xqXGsE2EMn7xZIknlxpNaL5LTdYi71vjNeZDOyVUGnnwSPTaqhfiIl60ja+bW3DK4r6eOrRRNcAAOwE+qx3wdKBik6oqcFfgXp5HiQJ3Be7lWXn5tRqpe+RP3Nj+DCGaS+A7TkDcC54z79l429GH597Th7VI48CXGavZv3Tg3hvCfv+hWPukSbn3U5Xs7gp0e3D/CuDpv9KRZ8idJmthJ3d3gnba1BpKhHz/ePKTJ5ca+hKWchzYqQSGHzwc/bYdgISI+5b3chwK3DeieoSBfdYG9kkSCFcquStwV+BejjsGoMBdgXt5Vl5+rQYjV/7aCJ76GymWUdzf/E7OuzTFRe8F4c57LdZ61IG5u6D44D6DsZp9Swnunj3r/nj78T/Oe5jqhG6rQI8B903N4PouNVSGotSQSw1FqAm1BZHqCGDwPttixOgGJJCE8MoD7f5rh3KV+eY0agzQBdiH68CaWYVGmV Zeek Administrator::CA (Remote)::12 Months (C2C)