Senior Cyber Defense Engineer

Jobtailor

Colorado

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Arrow is seeking a senior security professional to lead complex cyber incident investigations across enterprise environments, including cloud and on-premises. You will perform end-to-end incident response, preserve forensic evidence, and deliver actionable remediation recommendations.

You will mentor SOC staff and contribute to playbooks and detection engineering initiatives. You will leverage SIEM/EDR tools (e.g., Microsoft Sentinel, Splunk, Defender XDR) and scripting (PowerShell, Python) to

Qualifications

  • 5–10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, SOAR, or related fields.
  • Proven experience leading enterprise-level cyber incident investigations.
  • Hands-on digital forensics, evidence collection, malware analysis, and reporting.
  • Experience across cloud, hybrid, identity, endpoint, network, and on-prem environments.
  • Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions.
  • Strong understanding of Microsoft Entra ID, AD, Azure, M365, identity security, and enterprise authentication.
  • Knowledge of Windows forensic artifacts, event logs, and persistence techniques.
  • Knowledge of cloud security across Azure, AWS, GCP, SaaS, logging, and monitoring.

Responsibilities

  • Lead complex cyber incident investigations across multiple environments.
  • Oversee end-to-end incident response: triage, containment, eradication, recovery, reporting.
  • Preserve evidence and maintain chain of custody for forensic investigations.
  • Produce executive summaries, root cause analyses, and remediation recommendations.
  • Develop detections, automation, and threat-hunting workflows to improve SIEM efficacy.
  • Mentor SOC Leads, Analysts, and Engineers; contribute to playbooks and standards.
  • Communicate findings to technical teams, leadership, Legal, and stakeholders.

Skills

Cybersecurity
Incident Response
Threat Hunting
Scripting
PowerShell
Python
KQL
SQL
Automation
Leadership
Mentoring
Communication

Education

Bachelor's degree in Cyber Security/CS/IT

Tools

Microsoft Sentinel
Splunk
Microsoft Defender XDR
CrowdStrike
SentinelOne
Azure
AWS
GCP
SOAR

Job description

  • Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments
  • Conduct end-to-end incident response including triage, scoping, containment, eradication, recovery, and post-incident reporting
  • Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat activity
  • Preserve evidence and maintain chain of custody for forensic, legal, compliance, and regulatory investigations
  • Produce investigative findings, root cause analyses, executive summaries, and remediation recommendations
  • Perform DFIR across Windows, cloud, identity, endpoint, network, and application environments
  • Conduct forensic examinations, artifact analysis, timeline analysis, and evidence collection
  • Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise
  • Conduct proactive threat hunting and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows
  • Support security tool engineering, administration, optimization, log onboarding, data normalization, telemetry validation, and use-case development
  • Build scripts, queries, automation, dashboards, and technical workflows to improve investigation speed and quality
  • Support AI-assisted security workflows, automation, agents, scripting, prompt testing, and operational governance
  • Support threat emulation and purple team activities to validate detections, controls, and response procedures
  • Serve as a senior technical lead during significant investigations and incident response efforts
  • Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers
  • Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation
  • Communicate with technical teams, leadership, Legal, HR, Compliance, and business stakeholders

Requirements

  • 5–10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines
  • Proven experience leading enterprise-level cyber incident response investigations
  • Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting
  • Experience across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments
  • Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions
  • Strong understanding of Microsoft Entra ID, Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication
  • Strong understanding of Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms
  • Knowledge of cloud security across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments
  • Knowledge of incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense
  • Knowledge of enterprise security operations including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent
  • Hands-on experience with EDR/XDR platforms such as Microsoft Defender XDR, Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or equivalent
  • Experience with digital forensic tools, forensic imaging, artifact collection, timeline analysis, endpoint investigation, and evidence handling
  • Scripting, querying, and automation using PowerShell, Python, Kusto Query Language, SQL, APIs, or equivalent
  • Experience with detection engineering, threat hunting, malware triage, alert tuning, dashboards, correlation rules, and response workflows
  • Experience performing artifact-based investigations across endpoint, identity, email, cloud, and network data sources
  • Knowledge of Windows forensic artifacts, registry analysis, event logs, authentication patterns, persistence techniques, and attacker behaviors
  • Ability to analyze phishing, credential theft, lateral movement, privilege escalation, command execution, and data access
  • Ability to produce forensic timelines, investigative findings, executive summaries, and remediation recommendations
  • Ability to operate independently during urgent or high-impact incidents while maintaining accuracy, documentation, and evidence integrity
  • Bachelor’s degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, or related field is preferred; equivalent experience considered
  • Preferred certifications include GCFA, GCFE, GCIH, GCIA, GREM, GCFR, GNFA, GCTI, OSCP, CEH, CISSP, Microsoft Security Operations Analyst, Microsoft Cybersecurity Architect, or other relevant certifications
  • Must be able to travel to an Arrow office location as requested by Arrow leadership

Core Competencies

Demonstrates expertise in leading complex cyber incident investigations and incident response across diverse environments, including cloud and on-premises. Proficient in digital forensic analysis, threat hunting, and developing automation solutions to enhance security operations.

Highest-signal resume keywords

  • Cyber Incident Response
  • Digital Forensic Analysis
  • Threat Hunting
  • SIEM Platforms
  • Scripting and Automation

ATS Optimization Keywords

Hard Skills

  • Digital Forensic Analysis
  • Incident Response
  • Threat Hunting
  • Malware Analysis
  • Evidence Collection
  • Detection Engineering
  • Automation
  • Kusto Query Language
  • PowerShell
  • SQL

Soft Skills

  • Mentoring
  • Communication
  • Leadership

Certifications & Qualifications

  • GCFA
  • GCFE
  • GCIH
  • GCIA
  • GREM
  • GCFR
  • GNFA
  • GCTI
  • OSCP
  • CEH

Industry Keywords

  • Cyber Security
  • DFIR
  • Incident Response Frameworks
  • MITRE ATT&CK
  • Enterprise Security Operations
  • Network Security
  • Email Security
  • Cloud Security
  • Compliance
  • Regulatory Investigations

Tools & Technologies

  • Microsoft Sentinel
  • Splunk
  • Microsoft Defender XDR
  • CrowdStrike
  • SentinelOne
  • Azure
  • AWS
  • GCP
  • SOAR
  • EDR
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Manager II
Information Technology Manager II

Jobtailor • Colorado

On-site
USD 140,000 - 190,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Digital Forensics and Incident Analyst
Digital Forensics and Incident Analyst

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Associate Director, Threat Management Center
Associate Director, Threat Management Center

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Senior Cyber Defense Engineer
Senior Cyber Defense Engineer

Arrow Electronics • Englewood (CO)

On-site
USD 121,000 - 193,000
Medical, Dental, Vision Insurance
401k with Matching
Paid Time Off
+2
Network Security Engineer
Network Security Engineer

Jobtailor • New Jersey

On-site
USD 110,000 - 140,000
Engineer II – Cyber Incident Response
Engineer II – Cyber Incident Response

Jobtailor • Pennsylvania

On-site
USD 70,000 - 100,000
Investigation & Forensic Analyst
Investigation & Forensic Analyst

Jobtailor • San Diego (CA)

On-site
USD 70,000 - 100,000
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Jobtailor • Washington

On-site
USD 140,000 - 190,000
Director – Security Remediation Operations
Director – Security Remediation Operations

Jobtailor • Arizona

On-site
USD 180,000 - 280,000