Information Technology Manager II
Listed on 2026-08-18
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
• Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments
• Conduct end-to-end incident response, including triage, scoping, containment, eradication, recovery, and post-incident reporting
• Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat activity
• Preserve evidence and maintain chain of custody for forensic, legal, compliance, and regulatory investigations
• Produce investigative findings, root cause analyses, executive summaries, and remediation recommendations
• Perform digital forensics and incident response across Windows, cloud, identity, endpoint, network, and application environments
• Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection
• Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise
• Conduct proactive threat hunting and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows
• Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage
• Partner with SOC, Threat Intelligence, Engineering, Platform, Infrastructure, Cloud, Identity, Application, and Security Operations teams
• Support engineering, administration, optimization, log onboarding, data normalization, telemetry validation, and use-case development for security platforms
• Build scripts, queries, automation, dashboards, and technical workflows to improve investigation speed and quality
• Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis
• Support threat emulation and purple team activities and assist with attack path, lateral movement, persistence, and detection validation analysis
• Serve as senior technical lead during significant cybersecurity investigations and incident response efforts
• Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers
• Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation
• Communicate with technical teams, leadership, Legal, HR, Compliance, and business stakeholders
- 5–10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines
- Proven experience leading enterprise-level cyber incident response investigations
- Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting
- Experience across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments
- Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions that improve security outcomes
- Strong understanding of Microsoft Entra , Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication concepts
- Strong understanding of Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms
- Knowledge of cloud security across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments
- Knowledge of incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense
- Knowledge of enterprise security operations, including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent
- Hands-on experience with EDR/XDR platforms such as Microsoft Defender XDR, Microsoft Defender for Endpoint, Crowd Strike, Sentinel One, or equivalent
- Experience with digital forensic tools, forensic imaging, artifact collection, timeline analysis, endpoint investigation, and evidence handling
- Scripting, querying, and automation using Power Shell, Python, Kusto Query Language, SQL, APIs, or equivalent
- Experience with detection engineering, threat hunting, malware triage, alert tuning, dashboards, correlation rules, and response…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).