远程工作雷达

高级网络安全工程师

Senior Cyber Defense Engineer

开发工程职能支持限定地区(需当地身份)
公司Arrow Electronics, Inc.
薪资$121,300 - $192,692.5/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间昨天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位:
高级网络安全工程师

职位描述:

你将负责的工作:
事件响应与调查

  • 在企业、云、混合和本地环境中领导复杂的网络事件调查。
  • 执行端到端的事件响应活动,包括初步评估、范围确定、遏制、清除、恢复和事件后报告。
  • 调查网络入侵、账户泄露、勒索软件、内部风险、与欺诈相关的事件、未经授权的访问和高级威胁行为者活动。
  • 保存证据并维护取证、法律、合规和监管调查的保管链流程。
  • 生成清晰的调查结果、根本原因分析、执行摘要和补救建议。

数字取证与恶意软件分析

  • 在Windows、云、身份、终端、网络和应用环境中执行DFIR活动。
  • 进行离线设备取证检查、数据包分析、时间线分析和证据收集。
  • 收集、分析和解释主机、网络、云、电子邮件、身份和应用数据。
  • 分析可疑文件、恶意软件行为、持久化机制、攻击者工具和妥协指标。
  • 支持涉及法律、人力资源、合规、内部风险和业务相关方的敏感调查。

威胁狩猎与检测工程

  • 主动进行威胁狩猎,识别对手行为、新兴威胁和控制漏洞。
  • 开发、调整和改进SIEM检测、关联规则、KQL查询、警报、仪表板和响应工作流。
  • 应用MITRE ATT&CK、威胁情报、事件经验教训和攻击者TTP来提高检测覆盖范围。
  • 与SOC、威胁情报、工程和平台团队合作,验证可见性并改善响应结果。
  • 支持威胁检测、警报质量、事件工作流和安全监控用例的持续改进。

安全工程与平台支持

  • 支持网络安全工具和平台的工程、管理和优化。
  • 协助日志源接入、数据标准化、遥测验证和用例开发。
  • 与基础设施、云、身份、应用和安全运营团队合作,提升可见性和响应能力。
  • 编写脚本、查询、自动化、仪表板和技术工作流,以提高调查速度和质量
查看英文原文

Position:
Senior Cyber Defense Engineer

Job Description:

What You'll Be Doing:
Incident Response & Investigations

  • Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments.
  • Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting.
  • Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat actor activity.
  • Preserve evidence and maintain chain-of-custody procedures for forensic, legal, compliance, and regulatory investigations.
  • Produce clear investigative findings, root cause analysis, executive summaries, and remediation recommendations.

Digital Forensics & Malware Analysis

  • Perform DFIR activities across Windows, cloud, identity, endpoint, network, and application environments.
  • Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection.
  • Collect, analyze, and interpret host, network, cloud, email, identity, and application artifacts.
  • Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise.
  • Support sensitive investigations involving Legal, HR, Compliance, Insider Risk, and business stakeholders.

Threat Hunting & Detection Engineering

  • Conduct proactive threat hunting to identify adversary behaviors, emerging threats, and control gaps.
  • Develop, tune, and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows.
  • Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage.
  • Partner with SOC, Threat Intelligence, Engineering, and Platform teams to validate visibility and improve response outcomes.
  • Support continuous improvement of threat detection, alert quality, incident workflows, and security monitoring use cases.

Security Engineering & Platform Support

  • Support the engineering, administration, and optimization of cyber security tools and platforms.
  • Assist with log source onboarding, data normalization, telemetry validation, and use-case development.
  • Partner with Infrastructure, Cloud, Identity, Application, and Security Operations teams to improve visibility and response capability.
  • Build scripts, queries, automation, dashboards, and technical workflows that improve investigation speed and quality.
  • Help mature enterprise security capabilities across SIEM, EDR, NDR, SOAR, cloud security, identity security, and forensic tooling.

AI, Security Automation & Emerging Technologies

  • Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis.
  • Demonstrate curiosity and willingness to learn emerging AI, automation, and agent-assisted security operations capabilities.
  • Contribute to team initiatives involving AI-assisted workflows, personal security agents, team-developed agents, and operational automation.
  • Show evidence of hands-on experimentation through lab work, scripting, automation, prompt testing, AI tools, or practical tinkering.
  • Understand the security considerations of AI usage, including data protection, responsible use, prompt safety, and operational governance.

Threat Emulation, Red Teaming & Purple Team Support, Preferred

  • Apply an offensive security mindset during investigations to better understand attacker behavior, objectives, and tradecraft.
  • Support threat emulation and purple team activities that validate detections, controls, and response procedures.
  • Use knowledge of penetration testing, red teaming, adversary simulation, or ethical hacking to strengthen blue team defenses.
  • Assist with threat actor tracking, attack path analysis, lateral movement analysis, persistence review, and detection validation.
  • Preferred experience with MITRE ATT&CK, Atomic Red Team, adversary emulation, detection testing, BAS tools, or offensive security labs.

Leadership & Mentorship

  • Serve as a senior technical lead during significant cyber security investigations and incident response efforts.
  • Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers on investigative and forensic methodologies.
  • Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation.
  • Help mature the organization’s DFIR, Incident Response, Detection Engineering, Threat Hunting, and Security Automation capabilities.
  • Communicate effectively with technical teams, leadership, Legal, HR, Compliance, and business stakeholders.

What We Are Looking For:

  • 5–10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines.
  • Proven experience leading enterprise-level cyber incident response investigations.
  • Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting.
  • Experience working across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments.
  • Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions that improve security outcomes.

Technical Skills
Strong understanding of:

  • Microsoft Entra ID, Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication concepts.
  • Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms.
  • Cloud security concepts across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments.
  • Incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense.
  • Enterprise security operations including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security.

Hands-On Experience With

  • SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent technologies.
  • EDR and XDR platforms such as Microsoft Defender XDR, Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or equivalent solutions.
  • Digital forensic tools, forensic imaging, artifact collection, timeline analysis, endpoint investigation, and evidence handling.
  • Scripting, querying, and automation using PowerShell, Python, Kusto Query Language, SQL, APIs, or equivalent technologies.
  • Detection engineering, threat hunting, malware triage, alert tuning, dashboards, correlation rules, and response workflows.

DFIR Technical Capabilities

  • Experience performing artifact-based investigations across endpoint, identity, email, cloud, and network data sources.
  • Knowledge of Windows forensic artifacts, registry analysis, event logs, authentication patterns, persistence techniques, and attacker behaviors.
  • Ability to analyze attacker activity including phishing, credential theft, lateral movement, privilege escalation, command execution, and data access.
  • Experience producing forensic timelines, investigative findings, executive summaries, and remediation recommendations.
  • Ability to operate independently during urgent or high-impact incidents while maintaining accuracy, documentation, and evidence integrity.

Preferred Qualifications

  • Bachelor’s degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, or related field; equivalent experience considered.
  • Experience supporting legal, compliance, HR, fraud, insider risk, or regulatory investigations.
  • Experience conducting malware analysis, threat hunting, detection engineering, red teaming, penetration testing, or purple team exercises.
  • Experience experimenting with AI-assisted security tools, copilots, automation workflows, security agents, scripting, or personal lab environments.
  • Experience in Microsoft-focused enterprise environments, including Microsoft Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, and KQL.

Preferred Certifications

  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Cloud Forensics Responder (GCFR)
  • GIAC Network Forensic Analyst (GNFA)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Offensive Security Certified Professional (OSCP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • Microsoft Security Operations Analyst
  • Microsoft Cybersecurity Architect
  • Other relevant DFIR, Incident Response, Cloud Security, Red Team, Purple Team, or Security Engineering certifications

Work Arrangement: Fully Remote - Must be able to travel to an Arrow office location as requested by Arrow leadership.
What’s In It For You :
At Arrow, we recognize that financial rewards and great benefits are important aspects of an ideal job. That’s why we offer competitive financial compensation, including various compensation plans and a solid benefits package.

  • Medical, Dental, Vision Insurance
  • 401k, With Matching Contributions
  • Short-Term/Long-Term Disability Insurance
  • Health Savings Account (HSA)/Health Reimbursement Account (HRA) Options
  • Paid Time Off (including sick, holiday, vacation, etc.)
  • Tuition Reimbursement
  • Growth Opportunities
  • And more!

Are you being referred to one of our roles? If so, ask your connection at Arrow about our Employee Referral Process!
Annual Hiring Range/Hourly Rate:

$121,300.00 - $192,692.50Actual compensation offer to candidate may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level. The pay ratio between base pay and target incentive (if applicable) will be finalized at offer.

Location:

US-CO-Colorado (Remote Employees)Remote work employees may be required to be present at the closest designated Arrow office for work-related purposes, at the Company’s request and sole discretion.

Time Type:

Full time

Job Category:

Information TechnologyEEO Statement:
Arrow is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, gender, age, sexual orientation, gender identity, national origin, veteran or disability status. (Arrow EEO/AAP policy)
All Arrow job postings are for existing job vacancies. We anticipate this requisition will be open for a minimum of five days, though it may be open for a longer period of time. We encourage your prompt application.
In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位