Lead Cyber Operations Engineer

Arctic Wolf
Pleasant Grove, UT, USA
Remote
Full-time

Arctic Wolf, with its unicorn valuation, is the leader in security operations in an exciting and fast-growing industry cybersecurity.

We have won countless awards for our excellence in security operations and remain dedicated to providing an industry-leading customer and employee experience.

Our mission is simple : End Cyber Risk. We’re looking for a Lead Cyber Operations Engineer to be part of making that happen.

The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones, threat hunting, and security content development to help protect the Arctic Wolf enterprise.

Responsibilities : SOC / DFIR :

SOC / DFIR :

  • Analyze incoming security events based on different data points, network, endpoint, and log sources expediently, consistently, and accurately
  • Prioritize incoming events exceptionally well
  • Perform assessment of cybersecurity incidents to identify the root cause, respond, and recover the environment.
  • Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately
  • Perform digital forensic functions including but not limited to host-based analysis through investigating Unix, Linux, and Windows systems to identify Indicators of Compromise (IOCs)
  • Process collected data and conduct data acquisitions through in-depth analysis
  • Preserve and analyze data from electronic data sources and systems including laptop and desktop computers, servers, and cloud services (Azure, AWS, etc.)
  • Examine firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity

Threat Hunting :

  • Use threat reporting and / or the hypothesis-driven method to create, scope and execute threat hunts.
  • Search for, identify and document cyberthreats and risks hidden from our existing detection logic, analytics, and machine learning, before an attack can occur.
  • Analyze and catalogue findings with respect to tactics, tools, and procedures (TTPs), behaviors, goals, and methods.
  • Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends.
  • Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors
  • Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security team)
  • Mentor junior Cyber Operations Engineers to support their professional growth.

The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Responder, Security Engineer, Data Scientist, and Threat Hunter.

A successful Lead Cyber Operations Engineer possesses a strong ability to communicate, educate, and share information effectively with variety of technical and non-technical people.

Who You Are :

You thrive in fast-paced environments and have a positive can-do attitude. You are a critical thinker that continually learns and can navigate uncertainty.

You enjoy working with internal partners and in a team, are an excellent communicator, and are able easily interact with a variety of people, personalities, and technical skill levels.

Above all, your passion for cybersecurity and partnering with variety of organizational groups shows in everything you do!

Required Skills and Experience :

  • 8+ years of experience in a hands-on security role with a strong knowledge of security operations, network engineering, network and endpoint security, data analysis and forensics
  • Strong understanding of all phases of Incident response.
  • Experience in scripting languages (python, Bash and Power Shell) with the ability to parse logs, analyze raw data and automate tasks
  • Familiarity with, and understanding of the inner workings of, network protocols and operating systems to include Windows, Linux and Unix
  • Working experience with and understanding of enterprise IT operations, including : Networking, SSO, Server Administration, Containerization, SaaS and Cloud Infrastructure.
  • Strong understanding of adversary tactics, techniques, and procedures using the Mitre ATT&CK framework, other adversary attack methodologies and current and past attack trend
  • Degree or diploma in a relevant field, or certifications and experience equivalent
  • Strong partnering and relationship building skills in a professional context
  • Strong communication skills, both written and verbal
  • Clear understanding of enterprise IT security solutions, including : Security Information Event Management (SIEM), Intrusion Detection Systems (IDS / IPS), Endpoint Detection and Response (EDR), Security Orchestration, Automation, and Response (SOAR), Network Security Monitoring (NSM), Firewalls, Content Filtering, and Proxies, and Cyber Threat Intelligence (CTI) tools to protect the enterprise.
  • Strong Analytical and problem-solving skills

Additional Skills and Experience :

  • Malware reverse engineering
  • Malware analysis
  • Authentication and identity management
  • Risk management, assessment, and common compliance frameworks
  • Penetration testing and attack simulation
  • Experience with compiled programing languages (C, C++, Java, etc.)
  • Ability to break down complex situations in understandable pieces
  • Experience with technical writing

About Arctic Wolf :

At Arctic Wolf we’re cultivating a collaborative and productive work environment that welcomes a diversity of backgrounds, cultures, and ideas to make our teams even stronger as we grow globally.

We’ve been named one of the 50 Most Innovative Companies in the world for 2022 (Fast Company) and the 2 nd Most Innovative Security Company .

This is in addition to consecutive awards from Top Workplace USA (2021, 2022), Best Places to Work - USA (2021, 2022) and Great Place to Work - Canada (2021, 2022).

Our Values

Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day.

We believe in diversity and inclusion, and truly value the unique qualities and unique perspectives all employees bring to the organization.

And we appreciate that by protecting people’s and organizations’ sensitive data and seeking to end cyber risk we get to work in an industry that is fundamental to the greater good.

We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance.

See more about our Pack Unity .

We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community.

We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.

All wolves receive compelling compensation and benefits packages, including :

  • Equity for all employees
  • Bonus or commission pay based on role
  • Flexible time off, paid volunteer days and paid parental leave
  • 401k match
  • Medical, Dental, and Vision insurance
  • Health Savings and Flexible Spending Agreement
  • Voluntary Legal Insurance
  • Training and career development programs

Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law.

Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment ensuring equal access and participation for people with disabilities.

As such, we strive to make our entire employee experience as accessible as possible and provide accommodations as required for candidates and employees with disabilities and / or other specific needs where possible.

Please let us know if you require any accommodations by emailing .

Security Requirements :

  • Conducts duties and responsibilities in accordance with AWN’s Information Security policies, standards, processes and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
  • Background checks are required for this position.
  • 30+ days ago
Related jobs
Arctic Wolf
Pleasant Grove, Utah
Remote

The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones, threat hunting, and security content development to help protect the Arctic Wolf enterprise. The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Re...

Promoted
PointClickCare
South Jordan, Utah

The Data Governance Analyst will improve the integrity, discoverability, and accessibility of shared data assets by leading the integration and enterprise-wide use of Data Governance Tools and Technologies to improve data value creation across the enterprise. Collaborate with other data analysts fro...

Promoted
ROCKY MTN UNIVERSITY OF HEALTH
Provo, Utah

A minimum of three (3) years of experience in web systems engineering, web systems administration, cloud engineering, or equivalent is required. Ensure staff understand and are proficient in using the myriads of software systems. Provide insight into best practices for the use of software systems. A...

Promoted
IXOPAY
Lehi, Utah

Trouble-shooting skills that span systems, network, and code Strong understanding of network infrastructure and network hardware. As an SRE Network Engineer, you will be responsible for applying development skills and mindset to IT operations, with the goal of improving the reliability of IXOPAY’s s...

Promoted
Boccard
Riverton, Utah

When large-scale projects, manage a functional team to perform the following phases or in smaller projects, perform the following phases:. The incumbent will be responsible for managing the planning, organizing, and staffing of the EIA phase of projects. Ability to work on collaborative multi-discip...

Promoted
Executech
South Jordan, Utah

Proactive Engineers provide remote and onsite expertise on a technical support team. They proactively serve as network administrators on a Service Delivery Team, partnering with the Service Delivery Manager and Senior Engineer in ensuring Executech’s products and services satisfy clients. Proa...

Promoted
Tekgence Private Ltd
Sandy, Utah

POSITION / TITLE : Systems Engineer (Mainframe). Troubleshoots systems to increase quality of systems. Develops, tests, and modifies software to improve efficiency of internal operating systems. Mainframe Systems Programmer to maintain vendor software and work cooperatively to keep the overall mainf...

Promoted
jub.com
Riverton, Utah

Within the TSG, the Project Manager role is a key leadership position and the hub of our ability to win and execute projects. Transportation Project Manager (P. Work very closely with technical staff assigned to projects including drafters, EIT's, and project. Transportation Engineering experience i...

Promoted
Ezarc Solutions
Lindon, Utah

Assistant Project Managers (APM's) manage construction projects to make sure they run smoothly, safely, and effectively. Review all project related documentation prior to project starting. Set up, organize, and maintain drawings and project documents in project folder, keeping all current docume...

Promoted
Ladders
Lehi, Utah

LendingClub Bank's Compliance Department is seeking an experienced and qualified compliance professional to fill the role of Sr Data Analyst. The Sr Data Analyst will partner with the credit risk teams and compliance leadership to ensure compliance with all fair lending laws and regulations. This ro...