Skip to main content
Back to jobs

Lead Cyber Operations Engineer

External
arcticwolf logoArcticwolf · Pleasant Grove, UT
Full-timeOn-site2w ago
AWSAzureBashCloud SecurityData AnalysisForensics
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones, threat hunting, and security content development to help protect the Arctic Wolf enterprise. Lead Cyber Operations Engineer will leverage their cross-domain expertise to fulfill these key responsibilities: SOC/DFIR Analyze incoming security events based on different data points, network, endpoint, and log sources expediently, consistently, and accurately Prioritize incoming events exceptionally well Perform assessment of cybersecurity incidents to identify the root cause, respond, and recover the environment. Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately Lead Security Incident Response activities across the organization as an Incident commander and responder Perform digital forensic functions including but not limited to host-based analysis through investigating Unix, Linux, and Windows systems to identify Indicators of Compromise (IOCs) Process collected data and conduct data acquisitions through in-depth analysis Preserve and analyze data from electronic data sources and systems including laptop and desktop computers, servers, and cloud services (Azure, AWS, etc.) Examine firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity Build and tune threat detections within a SIEM solution related to current threat landscape Threat Hunting Use threat reporting and/or the hypothesis-driven method to create, scope and execute threat hunts. Search for, identify and document cyber threats and risks hidden from our existing detection logic, analytics, and machine learning, before an attack can occur. Analyze and catalogue findings with respect to tactics, tools, and procedures (TTPs), behaviors, goals, and methods. Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends. Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security teams) Mentor junior Cyber Operations Engineers to support their professional growth. Knowledge in building and leveraging SIEM dashboards for threat hunt engagements The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Responder, Security Engineer, Data Scientist, and Threat Hunter. A successful Lead Cyber Operations Engineer possesses a strong ability to communicate, educate, and share information effectively with variety of technical and non-technical people. About You You thrive in fast-paced environments and have a positive can-do attitude. You are a critical thinker that continually learns and can navigate uncertainty. You enjoy working with internal partners and in a team, are an excellent communicator, and are able easily interact with a variety of people, personalities, and technical skill levels. Above all, your passion for cybersecurity and partnering with variety of organizational groups shows in everything you do! Required Skills and Experience 8+ years of experience in a hands-on security role with a strong knowledge of security operations, cloud security, network engineering, network and endpoint security, data analysis and forensics Strong understanding of all phases of Incident response. Experience in scripting languages (python, Bash and Power Shell) with the ability to parse logs, analyze raw data and automate tasks Familiarity with, and understanding of the inner workings of, network protocols and operating systems to include Windows, Linux and Unix Working experience with and understanding of enterprise IT operations, including Networking, SSO, Server Administration, Containerization, SaaS and Cloud Infrastructure. Strong understanding of adversary tactics, techniques, and procedures using the Mitre ATT&C

Benefits

Paid time off

Additional Information

At Arctic Wolf, you won't just watch the cybersecurity industry evolve - you'll help lead the change. Our global Pack is made up of people who thrive on solving hard problems, moving fast, and building technology that protects organizations around the world. We're proud to be recognized by Forbes, CNBC, Fortune, CRN, Bartner Peer Insights and IDC MarketScape - but what matters most is the work behind it: delivering real outcomes for customers through award winning innovation like our Aurora Platform. If you're looking for meaningful work, smart teammates and the chance to make a real impact in a high-growth company that's redefining security operations, Arctic Wolf is the right place for you! Our mission is simple: End Cyber Risk. We're looking for a Lead Cyber Operations Engineer to be part of making this happen.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at arcticwolf? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect