The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones, threat hunting, and security content development to help protect the Arctic Wolf enterprise. Lead Cyber Operations Engineer will leverage their cross-domain expertise to fulfill these key responsibilities: SOC/DFIR Analyze incoming security events based on different data points, network, endpoint, and log sources expediently, consistently, and accurately Prioritize incoming events exceptionally well Perform assessment of cybersecurity incidents to identify the root cause, respond, and recover the environment. Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately Lead Security Incident Response activities across the organization as an Incident commander and responder Perform digital forensic functions including but not limited to host-based analysis through investigating Unix, Linux, and Windows systems to identify Indicators of Compromise (IOCs) Process collected data and conduct data acquisitions through in-depth analysis Preserve and analyze data from electronic data sources and systems including laptop and desktop computers, servers, and cloud services (Azure, AWS, etc.) Examine firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity Build and tune threat detections within a SIEM solution related to current threat landscape Threat Hunting Use threat reporting and/or the hypothesis-driven method to create, scope and execute threat hunts. Search for, identify and document cyber threats and risks hidden from our existing detection logic, analytics, and machine learning, before an attack can occur. Analyze and catalogue findings with respect to tactics, tools, and procedures (TTPs), behaviors, goals, and methods. Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends. Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security teams) Mentor junior Cyber Operations Engineers to support their professional growth. Knowledge in building and leveraging SIEM dashboards for threat hunt engagements The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Responder, Security Engineer, Data Scientist, and Threat Hunter. A successful Lead Cyber Operations Engineer possesses a strong ability to communicate, educate, and share information effectively with variety of technical and non-technical people.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
Associate degree