Cyber Defense Engineer

Arrow Electronics
Colorado City, CO, United States
1 day ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$121,000.0 - $193,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Agile Methodology Artificial Intelligence Amazon Web Services Software System Penetration Testing User Authentication Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security
+38 more
Cyber Security Data Normalization Data Security Digital Forensics Emulators Event Logging Identity and Access Management Intrusion Detection and Prevention Information Systems Security Architecture Professional Python (Programming Language) Network Security Microsoft Security Essentials Network Forensics Windows PowerShell Azure Active Directory Phishing Red Team (Cyber Security) Kusto Query Language Reverse Engineering Security Information and Event Management SQL Databases Data Logging Scripting Google Cloud Mitre Att&ck QRadar Malware Cyber Threat Analysis Azure Security Center Falcon Platform Information Technology Cybercrime Microsoft Sentinel Purple Team (Cyber Security) Splunk SentinelOne Expertise Blue Team (Cyber Security) Security Orchestration, Automation & Response

Job description

  • Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments.
  • Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting.
  • Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat actor activity.
  • Preserve evidence and maintain chain-of-custody procedures for forensic, legal, compliance, and regulatory investigations.
  • Produce clear investigative findings, root cause analysis, executive summaries, and remediation recommendations.

Digital Forensics & Malware Analysis

  • Perform DFIR activities across Windows, cloud, identity, endpoint, network, and application environments.
  • Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection.
  • Collect, analyze, and interpret host, network, cloud, email, identity, and application artifacts.
  • Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise.
  • Support sensitive investigations involving Legal, HR, Compliance, Insider Risk, and business stakeholders.

Threat Hunting & Detection Engineering

  • Conduct proactive threat hunting to identify adversary behaviors, emerging threats, and control gaps.
  • Develop, tune, and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows.
  • Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage.
  • Partner with SOC, Threat Intelligence, Engineering, and Platform teams to validate visibility and improve response outcomes.
  • Support continuous improvement of threat detection, alert quality, incident workflows, and security monitoring use cases.

Security Engineering & Platform Support

  • Support the engineering, administration, and optimization of cyber security tools and platforms.
  • Assist with log source onboarding, data normalization, telemetry validation, and use-case development.
  • Partner with Infrastructure, Cloud, Identity, Application, and Security Operations teams to improve visibility and response capability.
  • Build scripts, queries, automation, dashboards, and technical workflows that improve investigation speed and quality.
  • Help mature enterprise security capabilities across SIEM, EDR, NDR, SOAR, cloud security, identity security, and forensic tooling.

AI, Security Automation & Emerging Technologies

  • Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis.
  • Demonstrate curiosity and willingness to learn emerging AI, automation, and agent-assisted security operations capabilities.
  • Contribute to team initiatives involving AI-assisted workflows, personal security agents, team-developed agents, and operational automation.
  • Show evidence of hands-on experimentation through lab work, scripting, automation, prompt testing, AI tools, or practical tinkering.
  • Understand the security considerations of AI usage, including data protection, responsible use, prompt safety, and operational governance.

Threat Emulation, Red Teaming & Purple Team Support, Preferred

  • Apply an offensive security mindset during investigations to better understand attacker behavior, objectives, and tradecraft.
  • Support threat emulation and purple team activities that validate detections, controls, and response procedures.
  • Use knowledge of penetration testing, red teaming, adversary simulation, or ethical hacking to strengthen blue team defenses.
  • Assist with threat actor tracking, attack path analysis, lateral movement analysis, persistence review, and detection validation.
  • Preferred experience with MITRE ATT&CK, Atomic Red Team, adversary emulation, detection testing, BAS tools, or offensive security labs.

Leadership & Mentorship

  • Serve as a senior technical lead during significant cyber security investigations and incident response efforts.
  • Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers on investigative and forensic methodologies.
  • Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation.
  • Help mature the organization’s DFIR, Incident Response, Detection Engineering, Threat Hunting, and Security Automation capabilities.
  • Communicate effectively with technical teams, leadership, Legal, HR, Compliance, and business stakeholders., Maintain and improve GameChanger’s backend API server and SDK. Implement API/SDK changes, improve developer ergonomics, optimize performance and scalability, design critical systems, document and mentor teammates, and participate in on-call rotation., Artificial Intelligence * Healthtech * Machine Learning * Natural Language Processing * Software * Generative AI Sell AKASA’s AI-native revenue cycle management solutions to health systems. Build C-level relationships, drive business development, lead full sales cycle from prospecting to close, deliver consultative presentations, work with BDRs, attend industry events, and collaborate cross-functionally. Travel domestically up to 60%. DraftKings

Requirements

  • 5-10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines.
  • Proven experience leading enterprise-level cyber incident response investigations.
  • Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting.
  • Experience working across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments.
  • Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions that improve security outcomes.

Technical Skills

Strong understanding of:

  • Microsoft Entra ID, Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication concepts.
  • Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms.
  • Cloud security concepts across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments.
  • Incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense.
  • Enterprise security operations including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security.

Hands-On Experience With

  • SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent technologies.
  • EDR and XDR platforms such as Microsoft Defender XDR, Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or equivalent solutions.
  • Digital forensic tools, forensic imaging, artifact collection, timeline analysis, endpoint investigation, and evidence handling.
  • Scripting, querying, and automation using PowerShell, Python, Kusto Query Language, SQL, APIs, or equivalent technologies.
  • Detection engineering, threat hunting, malware triage, alert tuning, dashboards, correlation rules, and response workflows.

DFIR Technical Capabilities

  • Experience performing artifact-based investigations across endpoint, identity, email, cloud, and network data sources.
  • Knowledge of Windows forensic artifacts, registry analysis, event logs, authentication patterns, persistence techniques, and attacker behaviors.
  • Ability to analyze attacker activity including phishing, credential theft, lateral movement, privilege escalation, command execution, and data access.
  • Experience producing forensic timelines, investigative findings, executive summaries, and remediation recommendations.
  • Ability to operate independently during urgent or high-impact incidents while maintaining accuracy, documentation, and evidence integrity.

Preferred Qualifications

  • Bachelor’s degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, or related field; equivalent experience considered.
  • Experience supporting legal, compliance, HR, fraud, insider risk, or regulatory investigations.
  • Experience conducting malware analysis, threat hunting, detection engineering, red teaming, penetration testing, or purple team exercises.
  • Experience experimenting with AI-assisted security tools, copilots, automation workflows, security agents, scripting, or personal lab environments.
  • Experience in Microsoft-focused enterprise environments, including Microsoft Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, and KQL.

Preferred Certifications

  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Cloud Forensics Responder (GCFR)
  • GIAC Network Forensic Analyst (GNFA)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Offensive Security Certified Professional (OSCP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • Microsoft Security Operations Analyst
  • Microsoft Cybersecurity Architect
  • Other relevant DFIR, Incident Response, Cloud Security, Red Team, Purple Team, or Security Engineering certifications

Work Arrangement: Fully Remote - Must be able to travel to an Arrow office location as requested by Arrow leadership.

Benefits & conditions

At Arrow, we recognize that financial rewards and great benefits are important aspects of an ideal job. That’s why we offer competitive financial compensation, including various compensation plans and a solid benefits package.

  • Medical, Dental, Vision Insurance
  • 401k, With Matching Contributions
  • Short-Term/Long-Term Disability Insurance
  • Health Savings Account (HSA)/Health Reimbursement Account (HRA) Options
  • Paid Time Off (including sick, holiday, vacation, etc.)
  • Tuition Reimbursement
  • Growth Opportunities
  • And more!

Are you being referred to one of our roles? If so, ask your connection at Arrow about our Employee Referral Process!, Remote or Hybrid United States 82K-102K Annually Senior level 82K-102K Annually Senior level Digital Media * Gaming * Information Technology * Software * Sports * Esports * Big Data Analytics Lead delivery across multiple engineering and product teams, plan and track key initiatives, surface risks and dependencies, strengthen Agile practices, use metrics and OKRs to improve predictability, and communicate status to stakeholders to ensure on-time launches. Top Skills: AirtableChatgptClaudeGeminiGoogle WorkspaceJIRAJpd

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

About the company

Arrow Electronics, Inc. Centennial, Colorado, USA Office

Our offices are approximately 15 miles south of Downtown Denver. Employees enjoy the easy access to the light rail station and I-25.

Arrow Electronics, Inc. Denver, Colorado, USA Office

9151 E Panorama Cir, The Arrow Building, Centennial, CO, Denver, United States, 80112

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all