Lead Cyber Operations Engineer

Arctic WolfPleasant Grove, UT
$63,000 - $240,000

About The Position

The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones, threat hunting, and security content development to help protect the Arctic Wolf enterprise. Lead Cyber Operations Engineer will leverage their cross-domain expertise to fulfill these key responsibilities: SOC/DFIR Analyze incoming security events based on different data points, network, endpoint, and log sources expediently, consistently, and accurately Prioritize incoming events exceptionally well Perform assessment of cybersecurity incidents to identify the root cause, respond, and recover the environment. Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately Lead Security Incident Response activities across the organization as an Incident commander and responder Perform digital forensic functions including but not limited to host-based analysis through investigating Unix, Linux, and Windows systems to identify Indicators of Compromise (IOCs) Process collected data and conduct data acquisitions through in-depth analysis Preserve and analyze data from electronic data sources and systems including laptop and desktop computers, servers, and cloud services (Azure, AWS, etc.) Examine firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity Build and tune threat detections within a SIEM solution related to current threat landscape Threat Hunting Use threat reporting and/or the hypothesis-driven method to create, scope and execute threat hunts. Search for, identify and document cyber threats and risks hidden from our existing detection logic, analytics, and machine learning, before an attack can occur. Analyze and catalogue findings with respect to tactics, tools, and procedures (TTPs), behaviors, goals, and methods. Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends. Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security teams) Mentor junior Cyber Operations Engineers to support their professional growth. Knowledge in building and leveraging SIEM dashboards for threat hunt engagements The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Responder, Security Engineer, Data Scientist, and Threat Hunter. A successful Lead Cyber Operations Engineer possesses a strong ability to communicate, educate, and share information effectively with variety of technical and non-technical people.

Requirements

  • 8+ years of experience in a hands-on security role with a strong knowledge of security operations, cloud security, network engineering, network and endpoint security, data analysis and forensics
  • Strong understanding of all phases of Incident response.
  • Experience in scripting languages (python, Bash and Power Shell) with the ability to parse logs, analyze raw data and automate tasks
  • Familiarity with, and understanding of the inner workings of, network protocols and operating systems to include Windows, Linux and Unix
  • Working experience with and understanding of enterprise IT operations, including Networking, SSO, Server Administration, Containerization, SaaS and Cloud Infrastructure.
  • Strong understanding of adversary tactics, techniques, and procedures using the Mitre ATT&CK framework, other adversary attack methodologies and current and past attack trend
  • Degree or diploma in a relevant field, or certifications and experience equivalent
  • Strong partnering and relationship building skills in a professional context
  • Strong communication skills, both written and verbal
  • Clear understanding of enterprise IT security solutions, including Security Information Event Management (SIEM), Intrusion Detection Systems (IDS/IPS), Endpoint Detection and Response (EDR), Security Orchestration, Automation, and Response (SOAR), Network Security Monitoring (NSM), Firewalls, Content Filtering, and Proxies, and Cyber Threat Intelligence (CTI) tools to protect the enterprise.
  • General foundational knowledge with leveraging agentic AI in supporting a security operations platform
  • Strong Analytical and problem-solving skills
  • Conducts duties and responsibilities in accordance with AWN’s Information Security policies, standards, processes and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
  • Background checks are required for this position.
  • This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (“EAR”). Please note that, if applicable, an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.

Nice To Haves

  • Malware reverse engineering
  • Malware analysis
  • Authentication and identity management
  • Risk management, assessment, and common compliance frameworks
  • Penetration testing and attack simulation
  • Ability to break down complex situations in understandable pieces
  • Leveraging Agentic AI solutions to improve security operations and incident response processes
  • Experience with technical writing

Responsibilities

  • Analyze incoming security events based on different data points, network, endpoint, and log sources expediently, consistently, and accurately
  • Prioritize incoming events exceptionally well
  • Perform assessment of cybersecurity incidents to identify the root cause, respond, and recover the environment.
  • Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately
  • Lead Security Incident Response activities across the organization as an Incident commander and responder
  • Perform digital forensic functions including but not limited to host-based analysis through investigating Unix, Linux, and Windows systems to identify Indicators of Compromise (IOCs)
  • Process collected data and conduct data acquisitions through in-depth analysis
  • Preserve and analyze data from electronic data sources and systems including laptop and desktop computers, servers, and cloud services (Azure, AWS, etc.)
  • Examine firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity
  • Build and tune threat detections within a SIEM solution related to current threat landscape
  • Use threat reporting and/or the hypothesis-driven method to create, scope and execute threat hunts.
  • Search for, identify and document cyber threats and risks hidden from our existing detection logic, analytics, and machine learning, before an attack can occur.
  • Analyze and catalogue findings with respect to tactics, tools, and procedures (TTPs), behaviors, goals, and methods.
  • Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends.
  • Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors
  • Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security teams)
  • Mentor junior Cyber Operations Engineers to support their professional growth.
  • Knowledge in building and leveraging SIEM dashboards for threat hunt engagements

Benefits

  • Equity for all employees
  • Flexible time off and paid volunteer days
  • RRSP and 401k match
  • Training and career development programs
  • Comprehensive private benefits plan including medical, mental health, dental, disability, life and AD&D, and value-added services
  • Robust Employee Assistance Program (EAP) with mental health services
  • Fertility support and paid parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service