Frontier Airlines

Lead - Cybersecurity Operations

Frontier Airlines$110K — $146K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, technology, or equivalent experience required.
  • 6+ years of relevant IT/Cybersecurity experience required.
  • 3+ years in a Supervisor or Lead Analyst role in Cybersecurity required.
  • 5+ years of security operations experience with enterprise cybersecurity products required.
  • 5+ years of SIEM platform experience required.
  • Industry cybersecurity certification required or must be attained within 3 months.
  • Hands-on cloud infrastructure cybersecurity remediation experience required.

Responsibilities

  • Monitor, investigate, investigate, and report on cyber incidents through detection platforms.
  • Lead support in detecting and responding to cybersecurity alerts and incidents.
  • Engage and escalate incidents to Cyber Operations Management and incident response teams.
  • Actively support incident response and training exercises as the lead incident response analyst.
  • Conduct proactive analysis of network/application logs and vulnerability data to assess breach incidents.
  • Manage and enhance the vulnerability management program, ensuring compliance with SLAs.
  • Oversee security tools, conduct health checks, and maintain cybersecurity product performance.

Benefits

  • Offers a hybrid work environment, with remote work options.
  • Regular status updates with the management team for active engagement.
  • Opportunities for professional development and external certifications.
  • Participation in ongoing cybersecurity awareness training programs.
  • Involvement in significant projects and collaborative engagements with other departments.
Full Job Description
What Will You Be Doing?

The Lead Analyst, Cybersecurity Operations will be part of the Cybersecurity team that analyzes, implements, monitors, troubleshoots, and audits the cybersecurity of the Frontier network infrastructure. The Lead Analyst provides timely and comprehensive updates to the Sr. Manager of Cybersecurity Operations on the intelligence of internal/external threats for detection, monitoring, threat hunting, and incident response. The scope of environment includes system-monitoring platforms, anti-virus, DLP, URL filtering, and PCI environments and any new leading tools that are brought into the network. The Lead Analyst will oversee the SOC team onshore and will be responsible for the Vulnerability Management program, attaining SLA benchmarks, the collection of tools and performance metrics, ensuring SOP's and playbooks are well updated and audited, incident response, digital forensics, and supporting penetration remediation on applications/systems. The Lead Analyst onshore will work closely with the peer Lead Analyst offshore to provide daily handover reports, status of threat intelligence alerts, vulnerability management progress, escalation of issues to the Level 2 team, and will hold daily standup calls between the offshore and onshore teams. The Lead Analyst(s) will meet multiple times per week with the Sr. Manager of Cybersecurity Operations to review ServiceNow tickets, projects, security tool audits, known exploited vulnerabilities and other high priority issues that arise during the week.

Essential Functions

  • Monitor, investigate, analyze, respond, and report to cyber incidents identified through detection/response platforms.
  • Lead support to Management in detecting and responding to cybersecurity alerts and incident activity.
  • Responsible for engaging and escalating incidents to Cyber Operations Management and other Cyber Incident Response Team members.
  • Actively support incident response activities, efforts, and training exercises (e.g., incidents, tabletops, threat simulations) and be the lead incident response analyst.
  • Actively drive risk reduction efforts for known cyber security vulnerabilities and known attack traffic patterns/indicators of compromise (IOC).
  • Actively monitor security threats and risks, provide in-depth incident analysis, evaluate security incidents, provide proactive threat research, and recommend mitigation strategies.
  • Evaluate and determine if/when cybersecurity violations have occurred through examination of network/application logs, open-source research, vulnerability and configuration scan data, and user provided reports.
  • Proactively conduct investigations, analysis, and evaluation of projects to determine cybersecurity risk and feasibility as required.
  • Administer, maintain, tune, and perform heath checks on cybersecurity products and services (such as secure mail gateway, SIEM, EDR, vulnerability management, brand monitoring, threat intelligence, security rating, DDoS, web proxy, file integrity monitoring (FIM), data loss prevention (DLP), User Entity & Behavioral Analytics (UEBA), and other).
  • Provide and implement recommendations for new technical controls to help mitigate security vulnerabilities.
  • Responsible for leading the vulnerability management program functions including hosting weekly meetings with Stakeholders and the operations team, creating and tracking tickets for all vulnerabilities, holding stakeholder teams to meet SLA's, and reporting to the Sr. Manager of Cybersecurity on a weekly basis.
  • Actively perform threat hunting activities in the environment to detect cyber threats in the network.
  • Coordinate and support purple, red, and blue team engagements.
  • Provide cybersecurity technical assistance when needed by system/application owners.
  • Support multiple day-to-day cybersecurity tasks and projects efforts.
  • Provide regular status updates to Management on projects and remediation efforts.
  • Solid understanding of cybersecurity policies and procedures, ability to draft, modify and create standard operating procedures (SOPs) for use of other team members.
  • Support organizational Security Awareness Training efforts (suggest training topics, coordinate phishing campaigns, enable awareness to end-users in support of incidents).
  • Support vulnerability assessments functions (such as: enterprise pen testing, application pen testing, static/dynamic testing, scorecard assessments).
  • Participate and support afterhours/on-call rotation requirements for cybersecurity incidents.
  • Responsible for developing, monitoring, and tracking cyber security metrics on a recurring basis, including creating PowerPoint slide decks for presentations.
  • Coordinate response and remediation efforts across various departments in a cooperative and beneficial manner.
  • Responsible for maintaining Incident Response documentation and auditing member contact information on at least a semi-annual basis or as needed.
  • Responsible for attending all vendor meetings and acts as the point of contact for our Cybersecurity vendors.
  • Demonstrate ownership and understanding of tasks when engaging with other team members.
  • Provide leadership, guidance and partnership to Analyst(s) and Senior Analyst(s).
  • Responsible for the onboarding and training of new analysts to the Cybersecurity Operations team.
  • Provide support to management team.


Qualifications

  • Bachelor's degree in computer science, technology, or equivalent combination of education and relevant experience (required).
  • 6+ years of relevant IT/Cybersecurity experience (required).
  • 3+ years in a Supervisor or Lead Analyst, Cybersecurity role (required).
  • 5+ years in security operations with hands-on experience with enterprise cybersecurity products, such as Qualys, SentinelOne, Proofpoint, Office365, Microsoft Defender for Cloud, Microsoft Defender for Identity (required).
  • 5+ years of SIEM (security information and event management) platform experience (required).
  • 4+ years supporting adversary tactics and techniques based on MITRE attack framework (required).
  • Knowledge of cyber security standards and frameworks such as ISO 27001, NIST CSF, NIST-800-53, PCI DSS ASV (highly desired).
  • Hands-on experience with tools like PowerShell, Vulnerability Management suite, Wireshark, and NMAP (required).
  • Industry cybersecurity certification: CompTIA: Security+ or Pentest+, CEH, CISSP, OCSP, SANS: GCIH or GSEC, CISSP, ISACA: CISA or CISM, Security+, SSCP, or CCNA (required, or willing to attain within 3 months of start date).
  • Hands-on Cloud infrastructure (Azure/AWS/GCP) cybersecurity remediation experience (Microsoft Defender) (required).
  • Hands-on experience with next-gen endpoint detection/response (EDR), Enterprise Firewall, IPS, Log Management, Cisco, and Checkpoint experience (required).
  • URL Filtering (web proxy) and troubleshooting experience (desirable).
  • Solid understanding of a variety of OSINT techniques and digital forensics to aid in proactive Threat Hunting and crown jewel asset protection.
  • Has demonstrable PowerPoint presentations and assists Management with gathering metrics on a routine basis and actively aids in a continual reduction of risk and vulnerabilities resulting in an overall more secure environment quarter-over-quarter.
  • Proactively identifies areas within Frontier that require hardening and protection and deploys solutions with the respective supporting teams.


Knowledge, Skills and Abilities

  • Ability to understand and communicate industry trends, maintain awareness of current vulnerabilities and security concerns, and understand their impact on the organization.
  • Ability to troubleshoot security/network/system-related issues and manage security components in operating environment.
  • Solid understanding of attack vectors, common intrusion techniques, brand intelligence, threat intelligence, application/host/network security hardening, enterprise risk management concepts, and MITRE Attack Framework principles.
  • Knowledge of enterprise risk assessment tools, technologies, and methodologies.
  • Broad and thorough knowledge of enterprise security systems and devices.
  • Knowledgeable in penetration testing, vulnerability assessments, and remediation.
  • Designing and implementing cybersecurity controls in an operating environment.
  • Able to make accurate work estimates and deliver projects within schedule constraints.
  • Proficiency in network traffic analysis and packet analysis.
  • Well-organized with the ability to coordinate and prioritize multiple tasks simultaneously with varying deadlines.
  • Demonstrate understanding and in-depth knowledge of security threats and applying actionable data to processes and procedures.
  • Demonstrate understanding and knowledge correlation analysis, along with an understanding of monitoring programs, such as Splunk and other SIEMs.
  • Understanding of the OSI 7-layer model.
  • Willing to work more than 40 hours and some weekends as needed.
  • Willing to support after-hours and weekend on-call rotation support.
  • Strong written and verbal communication skills.
  • Ability to remain organized and to elicit cooperation from a wide variety of sources including team members and other internal departments.
  • Ability to quickly learn new systems, devices, and methodologies.
  • Able to work independently and with a team of peers and other departments.
  • Proactively identifies and addresses various gaps and solutions within the boundaries of Cybersecurity Operations and deploys these solutions; creates roadmap on these efforts to align with Cyber Operations goals and provides periodic updates as needed.


Equipment Operated

Laptop endpoint running Windows and a variety of cybersecurity applications, commercial and open-source tools.

Work Environment

Denver based employees are required to be in the office 4 days a week, work remote on Friday.This is subject to change at any time. Requires being on-call for after-hours and weekend support.

Physical Effort

Light physical effort required by handling objects up to 20 pounds occasionally and/or up to 10 pounds frequently.

Supervision Received

General Direction: The incumbent normally receives little instruction on day-to-day work and receives general instructions on new assignments.

Salary Range: $110,114 - $146,157 - Please note: this role will close on or before 12/31/26.

Positions Supervised

  • None


Workplace Policies

Disclaimer: The above statements are intended only to describe the general nature and level of work required of the referenced position; they are not intended to be an exhaustive list of all responsibilities, duties, and skills required of individuals in this position. Please be advised that duties and expectations of this position may be subject to change.

About Frontier Airlines

Frontier Airlines is a low-cost airline that operates flights to over 100 destinations in the United States, Mexico, and the Caribbean. The company was founded in 1994 and is headquartered in Denver, Colorado. Frontier Airlines is known for its low fares and customer-friendly policies, such as allowing passengers to bring one personal item and one carry-on bag for free. The airline has a fleet of over 100 aircraft and is constantly expanding its route network.
Learn more about Frontier Airlines
Size
4,000 employees
Industry
Founded
1994

Similar Jobs

More Jobs at Frontier Airlines

More Information Technology Jobs

Find similar Lead - Cybersecurity Operations jobs: