Senior Cyber Defense Engineer
Job in
Lakewood, Jefferson County, Colorado, USA
Listed on 2026-08-17
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-17
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Job Description & How to Apply Below
- Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments
- Conduct end-to-end incident response including triage, scoping, containment, eradication, recovery, and post-incident reporting
- Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat activity
- Preserve evidence and maintain chain of custody for forensic, legal, compliance, and regulatory investigations
- Produce investigative findings, root cause analyses, executive summaries, and remediation recommendations
- Perform DFIR across Windows, cloud, identity, endpoint, network, and application environments
- Conduct forensic examinations, artifact analysis, timeline analysis, and evidence collection
- Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise
- Conduct proactive threat hunting and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows
- Support security tool engineering, administration, optimization, log onboarding, data normalization, telemetry validation, and use-case development
- Build scripts, queries, automation, dashboards, and technical workflows to improve investigation speed and quality
- Support AI-assisted security workflows, automation, agents, scripting, prompt testing, and operational governance
- Support threat emulation and purple team activities to validate detections, controls, and response procedures
- Serve as a senior technical lead during significant investigations and incident response efforts
- Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers
- Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation
- Communicate with technical teams, leadership, Legal, HR, Compliance, and business stakeholders
Requirements
- 5–10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines
- Proven experience leading enterprise-level cyber incident response investigations
- Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting
- Experience across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments
- Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions
- Strong understanding of Microsoft Entra , Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication
- Strong understanding of Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms
- Knowledge of cloud security across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments
- Knowledge of incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense
- Knowledge of enterprise security operations including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent
- Hands-on experience with EDR/XDR platforms such as Microsoft Defender XDR, Microsoft Defender for Endpoint, Crowd Strike, Sentinel One, or equivalent
- Experience with digital forensic tools, forensic imaging, artifact collection, timeline analysis, endpoint investigation, and evidence handling
- Scripting, querying, and automation using Power Shell, Python, Kusto Query Language, SQL, APIs, or equivalent
- Experience with detection engineering, threat hunting, malware triage, alert tuning, dashboards, correlation rules, and response workflows
- Experience performing artifact-based investigations across endpoint, identity, email, cloud, and network data sources
- Knowledge of Windows forensic artifacts, registry analysis, event logs, authentication patterns, persistence techniques, and attacker behaviors
- Ability to analyze phishing, credential theft, lateral movement, privilege escalation, command execution, and data access
- Ability to produce forensic timelines, investigative…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×