Information Technology Manager II
Job in
Englewood, Arapahoe County, Colorado, 80151, USA
Listed on 2026-08-22
Listing for:
Arrow Electronics
Full Time
position Listed on 2026-08-22
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
- Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments.
- Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting.
- Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat actor activity.
- Preserve evidence and maintain chain-of-custody procedures for forensic, legal, compliance, and regulatory investigations.
- Produce clear investigative findings, root cause analysis, executive summaries, and remediation recommendations.
Information Technology Manager II
Job Description What You'll Be Doing Incident Response & Investigations- Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments.
- Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting.
- Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat actor activity.
- Preserve evidence and maintain chain-of-custody procedures for forensic, legal, compliance, and regulatory investigations.
- Produce clear investigative findings, root cause analysis, executive summaries, and remediation recommendations.
- Perform DFIR activities across Windows, cloud, identity, endpoint, network, and application environments.
- Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection.
- Collect, analyze, and interpret host, network, cloud, email, identity, and application artifacts.
- Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise.
- Support sensitive investigations involving Legal, HR, Compliance, Insider Risk, and business stakeholders.
- Conduct proactive threat hunting to identify adversary behaviors, emerging threats, and control gaps.
- Develop, tune, and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows.
- Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage.
- Partner with SOC, Threat Intelligence, Engineering, and Platform teams to validate visibility and improve response outcomes.
- Support continuous improvement of threat detection, alert quality, incident workflows, and security monitoring use cases.
- Support the engineering, administration, and optimization of cyber security tools and platforms.
- Assist with log source onboarding, data normalization, telemetry validation, and use‑case development.
- Partner with Infrastructure, Cloud, Identity, Application, and Security Operations teams to improve visibility and response capability.
- Build scripts, queries, automation, dashboards, and technical workflows that improve investigation speed and quality.
- Help mature enterprise security capabilities across SIEM, EDR, NDR, SOAR, cloud security, identity security, and forensic tooling.
- Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis.
- Demonstrate curiosity and willingness to learn emerging AI, automation, and agent-assisted security operations capabilities.
- Contribute to team initiatives involving AI-assisted workflows, personal security agents, team-developed agents, and operational automation.
- Show evidence of hands-on experimentation through lab work, scripting, automation, prompt testing, AI tools, or practical tinkering.
- Understand the security considerations of AI usage, including data protection, responsible use, prompt safety, and operational governance.
- Apply an offensive security mindset during investigations to better understand attacker behavior, objectives, and tradecraft.
- Support threat emulation and purple team activities that validate detections, controls, and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×