×
Register Here to Apply for Jobs or Post Jobs. X

Senior Cyber Defense Engineer

Job in Lakewood, Jefferson County, Colorado, USA
Listing for: Jobtailor
Full Time position
Listed on 2026-08-17
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below
  • Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments
  • Conduct end-to-end incident response including triage, scoping, containment, eradication, recovery, and post-incident reporting
  • Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat activity
  • Preserve evidence and maintain chain of custody for forensic, legal, compliance, and regulatory investigations
  • Produce investigative findings, root cause analyses, executive summaries, and remediation recommendations
  • Perform DFIR across Windows, cloud, identity, endpoint, network, and application environments
  • Conduct forensic examinations, artifact analysis, timeline analysis, and evidence collection
  • Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise
  • Conduct proactive threat hunting and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows
  • Support security tool engineering, administration, optimization, log onboarding, data normalization, telemetry validation, and use-case development
  • Build scripts, queries, automation, dashboards, and technical workflows to improve investigation speed and quality
  • Support AI-assisted security workflows, automation, agents, scripting, prompt testing, and operational governance
  • Support threat emulation and purple team activities to validate detections, controls, and response procedures
  • Serve as a senior technical lead during significant investigations and incident response efforts
  • Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers
  • Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation
  • Communicate with technical teams, leadership, Legal, HR, Compliance, and business stakeholders

Requirements

  • 5–10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines
  • Proven experience leading enterprise-level cyber incident response investigations
  • Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting
  • Experience across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments
  • Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions
  • Strong understanding of Microsoft Entra , Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication
  • Strong understanding of Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms
  • Knowledge of cloud security across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments
  • Knowledge of incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense
  • Knowledge of enterprise security operations including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent
  • Hands-on experience with EDR/XDR platforms such as Microsoft Defender XDR, Microsoft Defender for Endpoint, Crowd Strike, Sentinel One, or equivalent
  • Experience with digital forensic tools, forensic imaging, artifact collection, timeline analysis, endpoint investigation, and evidence handling
  • Scripting, querying, and automation using Power Shell, Python, Kusto Query Language, SQL, APIs, or equivalent
  • Experience with detection engineering, threat hunting, malware triage, alert tuning, dashboards, correlation rules, and response workflows
  • Experience performing artifact-based investigations across endpoint, identity, email, cloud, and network data sources
  • Knowledge of Windows forensic artifacts, registry analysis, event logs, authentication patterns, persistence techniques, and attacker behaviors
  • Ability to analyze phishing, credential theft, lateral movement, privilege escalation, command execution, and data access
  • Ability to produce forensic timelines, investigative…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary