Lead Cyber Operations Engineer
Listed on 2026-08-04
-
IT/Tech
Cybersecurity
At Arctic Wolf, youwon’tjust watch the cybersecurity industry evolve –you'llhelp lead the change. Our global Pack is made up of people who thrive on solving hard problems, moving fast, and building technology that protects organizations around the world.
We’reproud to be recognized by Forbes, CNBC, Fortune, CRN, Bartner Peer Insight sand IDCMarket
Scape– but what matters most is the work behind it: delivering real outcomes for customers through award winning innovation like our Aurora Platform.
Ifyou’relooking for meaningful work, smartteammatesand the chance to make a real impact in a high-growth company that’sredefining security operations,Arctic Wolf is the right place for you!
Our mission is simple:
End Cyber Risk. We’re looking for a Lead Cyber Operations Engineer to be part of making this happen.
The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones, threat hunting, and security content development to help protect the Arctic Wolf enterprise. Lead Cyber Operations Engineer will leverage their cross-domain expertise to fulfill these key responsibilities:
SOC/DFIR- Analyze incoming security events based on different data points, network, endpoint, and log sources expediently, consistently, and accurately
- Prioritize incoming events exceptionally well
- Perform assessment of cybersecurity incidents to identify the root cause, respond, and recover the environment.
- Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately
- Lead Security Incident Response activities across the organization as an Incident commander and responder
- Perform digital forensic functions including but not limited to host-based analysis through investigating Unix, Linux, and Windows systems to identify Indicators of Compromise (IOCs)
- Process collected data and conduct data acquisitions through in-depth analysis
- Preserve and analyze data from electronic data sources and systems including laptop and desktop computers, servers, and cloud services (Azure, AWS, etc.)
- Examine firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity
- Build and tune threat detections within a SIEM solution related to current threat landscape
- Use threat reporting and/or the hypothesis-driven method to create, scope and execute threat hunts.
- Search for, identify and document cyber threats and risks hidden from our existing detection logic, analytics, and machine learning, before an attack can occur.
- Analyze and catalogue findings with respect to tactics, tools, and procedures (TTPs), behaviors, goals, and methods.
- Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends.
- Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors
- Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security teams)
- Mentor junior Cyber Operations Engineers to support their professional growth.
- Knowledge in building and leveraging SIEM dashboards for threat hunt engagements
The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Responder, Security Engineer, Data Scientist, and Threat Hunter. A successful Lead Cyber Operations Engineer possesses a strong ability to communicate, educate, and share information effectively with variety of technical and non-technical people.
About YouYou thrive in fast-paced environments and have a positive can-do attitude. You are a critical thinker that continually learns and can navigate uncertainty. You enjoy working with internal partners and in a team, are an excellent communicator, and are able easily interact with a variety of people, personalities, and technical skill levels. Above all, your passion for cybersecurity and partnering with variety of organizational groups shows in everything you do!
RequiredSkills and Experience
- 8+years of experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).