Senior Cyber Defense Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+38 more
Job description
- Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments.
- Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting.
- Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat actor activity.
- Preserve evidence and maintain chain-of-custody procedures for forensic, legal, compliance, and regulatory investigations.
- Produce clear investigative findings, root cause analysis, executive summaries, and remediation recommendations.
Digital Forensics & Malware Analysis
- Perform DFIR activities across Windows, cloud, identity, endpoint, network, and application environments.
- Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection.
- Collect, analyze, and interpret host, network, cloud, email, identity, and application artifacts.
- Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise.
- Support sensitive investigations involving Legal, HR, Compliance, Insider Risk, and business stakeholders.
Threat Hunting & Detection Engineering
- Conduct proactive threat hunting to identify adversary behaviors, emerging threats, and control gaps.
- Develop, tune, and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows.
- Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage.
- Partner with SOC, Threat Intelligence, Engineering, and Platform teams to validate visibility and improve response outcomes.
- Support continuous improvement of threat detection, alert quality, incident workflows, and security monitoring use cases.
Security Engineering & Platform Support
- Support the engineering, administration, and optimization of cyber security tools and platforms.
- Assist with log source onboarding, data normalization, telemetry validation, and use-case development.
- Partner with Infrastructure, Cloud, Identity, Application, and Security Operations teams to improve visibility and response capability.
- Build scripts, queries, automation, dashboards, and technical workflows that improve investigation speed and quality.
- Help mature enterprise security capabilities across SIEM, EDR, NDR, SOAR, cloud security, identity security, and forensic tooling.
AI, Security Automation & Emerging Technologies
- Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis.
- Demonstrate curiosity and willingness to learn emerging AI, automation, and agent-assisted security operations capabilities.
- Contribute to team initiatives involving AI-assisted workflows, personal security agents, team-developed agents, and operational automation.
- Show evidence of hands-on experimentation through lab work, scripting, automation, prompt testing, AI tools, or practical tinkering.
- Understand the security considerations of AI usage, including data protection, responsible use, prompt safety, and operational governance.
Threat Emulation, Red Teaming & Purple Team Support, Preferred
- Apply an offensive security mindset during investigations to better understand attacker behavior, objectives, and tradecraft.
- Support threat emulation and purple team activities that validate detections, controls, and response procedures.
- Use knowledge of penetration testing, red teaming, adversary simulation, or ethical hacking to strengthen blue team defenses.
- Assist with threat actor tracking, attack path analysis, lateral movement analysis, persistence review, and detection validation.
- Preferred experience with MITRE ATT&CK, Atomic Red Team, adversary emulation, detection testing, BAS tools, or offensive security labs.
Leadership & Mentorship
- Serve as a senior technical lead during significant cyber security investigations and incident response efforts.
- Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers on investigative and forensic methodologies.
- Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation.
- Help mature the organization’s DFIR, Incident Response, Detection Engineering, Threat Hunting, and Security Automation capabilities.
- Communicate effectively with technical teams, leadership, Legal, HR, Compliance, and business stakeholders.
Requirements
- 5-10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines.
- Proven experience leading enterprise-level cyber incident response investigations.
- Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting.
- Experience working across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments.
- Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions that improve security outcomes.
Technical Skills
Strong understanding of:
- Microsoft Entra ID, Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication concepts.
- Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms.
- Cloud security concepts across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments.
- Incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense.
- Enterprise security operations including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security.
Hands-On Experience With
- SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent technologies.
- EDR and XDR platforms such as Microsoft Defender XDR, Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or equivalent solutions.
- Digital forensic tools, forensic imaging, artifact collection, timeline analysis, endpoint investigation, and evidence handling.
- Scripting, querying, and automation using PowerShell, Python, Kusto Query Language, SQL, APIs, or equivalent technologies.
- Detection engineering, threat hunting, malware triage, alert tuning, dashboards, correlation rules, and response workflows.
DFIR Technical Capabilities
- Experience performing artifact-based investigations across endpoint, identity, email, cloud, and network data sources.
- Knowledge of Windows forensic artifacts, registry analysis, event logs, authentication patterns, persistence techniques, and attacker behaviors.
- Ability to analyze attacker activity including phishing, credential theft, lateral movement, privilege escalation, command execution, and data access.
- Experience producing forensic timelines, investigative findings, executive summaries, and remediation recommendations.
- Ability to operate independently during urgent or high-impact incidents while maintaining accuracy, documentation, and evidence integrity.
Preferred Qualifications
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, or related field; equivalent experience considered.
- Experience supporting legal, compliance, HR, fraud, insider risk, or regulatory investigations.
- Experience conducting malware analysis, threat hunting, detection engineering, red teaming, penetration testing, or purple team exercises.
- Experience experimenting with AI-assisted security tools, copilots, automation workflows, security agents, scripting, or personal lab environments.
- Experience in Microsoft-focused enterprise environments, including Microsoft Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, and KQL.
Preferred Certifications
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Forensic Examiner (GCFE)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Reverse Engineering Malware (GREM)
- GIAC Cloud Forensics Responder (GCFR)
- GIAC Network Forensic Analyst (GNFA)
- GIAC Cyber Threat Intelligence (GCTI)
- Offensive Security Certified Professional (OSCP)
- Certified Ethical Hacker (CEH)
- Certified Information Systems Security Professional (CISSP)
- Microsoft Security Operations Analyst
- Microsoft Cybersecurity Architect
- Other relevant DFIR, Incident Response, Cloud Security, Red Team, Purple Team, or Security Engineering certifications
Work Arrangement: Fully Remote - Must be able to travel to an Arrow office location as requested by Arrow leadership.
Benefits & conditions
At Arrow, we recognize that financial rewards and great benefits are important aspects of an ideal job. That’s why we offer competitive financial compensation, including various compensation plans and a solid benefits package.
- Medical, Dental, Vision Insurance
- 401k, With Matching Contributions
- Short-Term/Long-Term Disability Insurance
- Health Savings Account (HSA)/Health Reimbursement Account (HRA) Options
- Paid Time Off (including sick, holiday, vacation, etc.)
- Tuition Reimbursement
- Growth Opportunities
- And more!
Are you being referred to one of our roles? If so, ask your connection at Arrow about our Employee Referral Process!
Annual Hiring Range/Hourly Rate:
$121,300.00 - $192,692.50
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
What Are The Top Skills Required For Azure Developers?