Lead Cyber Operations Engineer
Pleasant Grove, OH - USA
Job Summary
At Arctic Wolf youwontjust watch the cybersecurity industry evolve youllhelp lead the change. Our global Pack is made up of people who thrive on solving hard problems moving fast and building technology that protects organizations around the to be recognized by Forbes CNBC Fortune CRN Bartner PeerInsightsand IDCMarketScape but what matters most is the work behind it: delivering real outcomes for customers through award winning innovation like our AuroraPlatform.
Ifyourelooking for meaningful work smartteammatesand the chance to make a real impact in a high-growth companythatsredefining security operationsArctic Wolf is the right place for you!
Our mission is simple: End Cyber Risk. Were looking for a Lead Cyber Operations Engineer to be part of making this happen.
About the Role
The Lead Cyber Operations Engineer provides proactive cyber defense and response services through incident repones threat hunting and security content development to help protect the Arctic Wolf enterprise. Lead Cyber Operations Engineer will leverage their cross-domain expertise to fulfill these key responsibilities:
SOC/DFIR
Analyze incoming security events based on different data points network endpoint and log sources expediently consistently and accurately
Prioritize incoming events exceptionally well
Perform assessment of cybersecurity incidents to identify the root cause respond and recover the environment.
Steer complex investigations within your area of expertise and leverage your security knowledge to engage the other experts within other disciplines appropriately
Lead Security Incident Response activities across the organization as an Incident commander and responder
Perform digital forensic functions including but not limited to host-based analysis through investigating Unix Linux and Windows systems to identify Indicators of Compromise (IOCs)
Process collected data and conduct data acquisitions through in-depth analysis
Preserve and analyze data from electronic data sources and systems including laptop and desktop computers servers and cloud services (Azure AWS etc.)
Examine firewall web database and other log sources to identify evidence and artifacts of malicious and compromised activity
Build and tune threat detections within a SIEM solution related to current threat landscape
Threat Hunting
Use threat reporting and/or the hypothesis-driven method to create scope and execute threat hunts.
Search for identify and document cyber threats and risks hidden from our existing detection logic analytics and machine learning before an attack can occur.
Analyze and catalogue findings with respect to tactics tools and procedures (TTPs) behaviors goals and methods.
Assist in organizing findings into reports with the goal of identifying and informing readers of environmental and organizational threat trends.
Assist and review in the creation of predictions for the future of the threat landscape and goals and methods of threat actors
Proactively interact and communicate with internal customer stakeholders (Internal Security Operations Center and AWN corporate security teams)
Mentor junior Cyber Operations Engineers to support their professional growth.
Knowledge in building and leveraging SIEM dashboards for threat hunt engagements
The Lead Cyber Operations Engineer role combines aspects of a Digital Forensics Incident Responder Security Engineer Data Scientist and Threat Hunter. A successful Lead Cyber Operations Engineer possesses a strong ability to communicate educate and share information effectively with variety of technical and non-technical people.
About You
You thrive in fast-paced environments and have a positive can-do attitude. You are a critical thinker that continually learns and can navigate uncertainty. You enjoy working with internal partners and in a team are an excellent communicator and are able easily interact with a variety of people personalities and technical skill levels. Above all your passion for cybersecurity and partnering with variety of organizational groups shows in everything you do!
Required Skills and Experience
8years of experience in a hands-on security role with a strong knowledge of security operations cloud security network engineering network and endpoint security data analysis and forensics
Strong understanding of all phases of Incident response.
Experience in scripting languages (python Bash and Power Shell) with the ability to parse logs analyze raw data and automate tasks
Familiarity with and understanding of the inner workings of network protocols and operating systems to include Windows Linux and Unix
Workingexperiencewithand understanding of enterprise IT operations including Networking SSO Server Administration Containerization SaaS and Cloud Infrastructure.
Strong understanding of adversary tactics techniques and procedures using the Mitre ATT&CK framework other adversary attack methodologies and current and past attack trend
Degreeor diplomain a relevant fieldor certifications and experience equivalent
Strongpartnering and relationship building skills in a professional context
Strong communication skills both written and verbal
Clear understanding of enterprise IT security solutions including Security Information Event Management (SIEM) Intrusion Detection Systems (IDS/IPS) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Network Security Monitoring (NSM) Firewalls Content Filtering and Proxies and Cyber Threat Intelligence (CTI) tools to protect the enterprise.
General foundational knowledge with leveraging agentic AI in supporting a security operations platform
Strong Analytical and problem-solving skills
Additional skills and experience
Malware reverse engineering
Malware analysis
Authentication and identity management
Risk management assessment and common compliance frameworks
Penetration testing and attack simulation
Ability to break down complex situations in understandable pieces
Leveraging Agentic AI solutions to improve security operations and incident response processes
Experience with technical writing
On-Camera Policy
To support a fair transparent and engaging interview experience candidates interviewing remotely are expected to be on camera during all video interviews. Being on camera fosters authentic connection improves communication and allows for full engagement from both candidates and interviewers. We understand that technical bandwidth or location-related challenges may occasionally prevent video use. If this applies candidates are required to notify us in advance so we can explore appropriate accommodations.
About Arctic Wolf
At Arctic Wolf we foster a collaborative and inclusive work environment that thrives on diversity of thought background and culture. This is reflected in our multiple awards including Top Workplace USA (2021-2024) Best Places to Work USA (2021-2024) Great Place to Work Canada (2021-2024) Great Place to Work UK (2024) and Kununu Top Company Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction with over 7000 customers worldwide and more than 2000 channel partners globally. As we continue to expand globally and enhance our technology Arctic Wolf remains the most trusted name in the industry.
Our Values
Arctic Wolf recognizes that success comes from delighting our customers so we work together to ensure that happens every day. We believe in diversity and inclusion and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate thatby protecting peoples and organizations sensitive data and seeking to end cyber risk we get to work in an industry that is fundamental to the greater good.
We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here.
We also believe and practice corporate responsibility and have recently joined the Pledge 1% Movement ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.
All wolves receive compelling compensation and benefits packages including:
Equity for all employees
Flexible time off and paid volunteer days
RRSP and 401k match
Training and career development programs
Comprehensive private benefits plan including medical mental health dental disability life and AD&D and value-added services
Robust Employee Assistance Program (EAP) with mental health services
Fertility support and paid parental leave
Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race color religion sex orientation national origin age disability genetics or any other basis forbidden under federal provincial or local law. Arctic Wolf is committed to fostering a welcoming accessible respectful and inclusive environment ensuring equal access and participation for people with disabilities. As such we strive to make our entireemployeeexperience as accessible as possible and provideaccommodationsas required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodations by emailing
Security Requirements
Conducts duties and responsibilities in accordance with AWNs Information Security policies standards processes and controls to protect the confidentiality integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
Background checks are required for this position.
This position may require access to information protected under U.S. export control laws and regulations including the Export Administration Regulations (EAR). Please note that if applicable an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.
Required Experience:
IC
About Company
Arctic Wolf delivers dynamic, 24x7 AI-driven cybersecurity protection tailored to the needs of your organization. Ready to boost your cyber resilience?