Lead Cyber Operations Engineer

Arctic Wolf

$63K — $240K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of hands-on security experience with strong knowledge in security operations and cloud security.
  • Solid understanding of all phases of incident response.
  • Proficient in scripting languages (Python, Bash, PowerShell) for log parsing and automation.
  • Familiar with network protocols and operating systems, including Windows, Linux, and Unix.
  • Experience with enterprise IT operations, networking, SSO, and cloud infrastructure.
  • Deep knowledge of adversary tactics using the Mitre ATT&CK framework and attack methodologies.
  • Degree or equivalent certifications in relevant field.
  • Strong communication skills and relationship-building abilities.
  • Understanding of enterprise IT security solutions and technologies.

Responsibilities

  • Analyze incoming security events using data from network and endpoint sources.
  • Prioritize security events effectively to address threats promptly.
  • Assess cybersecurity incidents to determine root causes and response strategies.
  • Lead complex investigations and collaborate with multidisciplinary teams.
  • Act as incident commander during security incidents, directing response activities.
  • Conduct digital forensics on various operating systems to identify indicators of compromise.
  • Preserve and analyze data from electronic sources, including cloud services and servers.
  • Build and tune threat detection capabilities within a SIEM, adapting to current threats.
  • Proactively hunt for cyber threats that bypass existing detection mechanisms.

Benefits

  • Comprehensive benefits package including health and wellness plans.
  • Opportunity for new hire equity grants.
  • Flexible remote work policies with support for video interviews.
  • Professional development and mentoring opportunities.
  • Engagement in a fast-paced, collaborative work environment.
Full Job Description

About the Role

The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones, threat hunting, and security content development to help protect the Arctic Wolf enterprise. Lead Cyber Operations Engineer will leverage their cross-domain expertise to fulfill these key responsibilities:

SOC/DFIR

  • Analyze incoming security events based on different data points, network, endpoint, and log sources expediently, consistently, and accurately

  • Prioritize incoming events exceptionally well

  • Perform assessment of cybersecurity incidents to identify the root cause, respond, and recover the environment.

  • Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately

  • Lead Security Incident Response activities across the organization as an Incident commander and responder

  • Perform digital forensic functions including but not limited to host-based analysis through investigating Unix, Linux, and Windows systems to identify Indicators of Compromise (IOCs)

  • Process collected data and conduct data acquisitions through in-depth analysis

  • Preserve and analyze data from electronic data sources and systems including laptop and desktop computers, servers, and cloud services (Azure, AWS, etc.)

  • Examine firewall, web, database, and other log sources to identify evidence and artifacts of malicious and compromised activity

  • Build and tune threat detections within a SIEM solution related to current threat landscape

Threat Hunting

  • Use threat reporting and/or the hypothesis-driven method to create, scope and execute threat hunts.

  • Search for, identify and document cyber threats and risks hidden from our existing detection logic, analytics, and machine learning, before an attack can occur.

  • Analyze and catalogue findings with respect to tactics, tools, and procedures (TTPs), behaviors, goals, and methods.

  • Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends.

  • Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors

  • Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security teams)

  • Mentor junior Cyber Operations Engineers to support their professional growth.

  • Knowledge in building and leveraging SIEM dashboards for threat hunt engagements

The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Responder, Security Engineer, Data Scientist, and Threat Hunter.  A successful Lead Cyber Operations Engineer possesses a strong ability to communicate, educate, and share information effectively with variety of technical and non-technical people. 

About You

You thrive in fast-paced environments and have a positive can-do attitude.  You are a critical thinker that continually learns and can navigate uncertainty.  You enjoy working with internal partners and in a team, are an excellent communicator, and are able easily interact with a variety of people, personalities, and technical skill levels.  Above all, your passion for cybersecurity and partnering with variety of organizational groups shows in everything you do!

Required Skills and Experience

  • 8+ years of experience in a hands-on security role with a strong knowledge of security operations, cloud security, network engineering, network and endpoint security, data analysis and forensics

  • Strong understanding of all phases of Incident response.

  • Experience in scripting languages (python, Bash and Power Shell) with the ability to parse logs, analyze raw data and automate tasks

  • Familiarity with, and understanding of the inner workings of, network protocols and operating systems to include Windows, Linux and Unix

  • Working experience with and understanding of enterprise IT operations, including Networking, SSO, Server Administration, Containerization, SaaS and Cloud Infrastructure.

  • Strong understanding of adversary tactics, techniques, and procedures using the Mitre ATT&CK framework, other adversary attack methodologies and current and past attack trend

  • Degree or diploma in a relevant field, or certifications and experience equivalent  

  • Strong partnering and relationship building skills in a professional context 

  • Strong communication skills, both written and verbal 

  • Clear understanding of enterprise IT security solutions, including Security Information Event Management (SIEM), Intrusion Detection Systems (IDS/IPS), Endpoint Detection and Response (EDR), Security Orchestration, Automation, and Response (SOAR), Network Security Monitoring (NSM), Firewalls, Content Filtering, and Proxies, and Cyber Threat Intelligence (CTI) tools to protect the enterprise. 

  • General foundational knowledge with leveraging agentic AI in supporting a security operations platform

  • Strong Analytical and problem-solving skills 

Additional skills and experience

  • Malware reverse engineering

  • Malware analysis 

  • Authentication and identity management 

  • Risk management, assessment, and common compliance frameworks 

  • Penetration testing and attack simulation 

  • Ability to break down complex situations in understandable pieces

  • Leveraging Agentic AI solutions to improve security operations and incident response processes

  • Experience with technical writing

On-Camera Policy
To support a fair, transparent, and engaging interview experience, candidates interviewing remotely are expected to be on camera during all video interviews. Being on camera fosters authentic connection, improves communication, and allows for full engagement from both candidates and interviewers. We understand that technical, bandwidth, or location-related challenges may occasionally prevent video use. If this applies, candidates are required to notify us in advance so we can explore appropriate accommodations.

The base salary range for this job family is 63,000 to 240,000 USD annually. This range reflects the base pay the company reasonably expects to offer for this position, aligned to the broader job family base pay structure. Actual base pay may vary based on skills, experience, and location, including job family level. In addition to base pay, Arctic Wolf offers variable incentive compensation, new hire equity grants, and a comprehensive benefits package.

Similar Jobs

More Jobs at Arctic Wolf

More Information Technology Jobs

Find similar Lead Cyber Operations Engineer jobs: