Senior Cyber Defense Engineer
Arrow Electronics
- Location
- US-CO-Colorado (Remote Employees)
- Work model
- Remote
- Level
- Senior
- H-1B history
- 35 approvals (FY2023)
- Posted
- Aug 12, 2026
Skills
About this role
What You'll Be Doing
Incident Response & Investigations Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments. Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting. Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat actor activity. Preserve evidence and maintain chain-of-custody procedures for forensic, legal, compliance, and regulatory investigations. Produce clear investigative findings, root cause analysis, executive summaries, and remediation recommendations. Digital Forensics & Malware Analysis Perform DFIR activities across Windows, cloud, identity, endpoint, network, and application environments. Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection. Collect, analyze, and interpret host, network, cloud, email, identity, and application artifacts. Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise. Support sensitive investigations involving Legal, HR, Compliance, Insider Risk, and business stakeholders. Threat Hunting & Detection Engineering Conduct proactive threat hunting to identify adversary behaviors, emerging threats, and control gaps. Develop, tune, and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows. Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage. Partner with SOC, Threat Intelligence, Engineering, and Platform teams to validate visibility and improve response outcomes. Support continuous improvement of threat detection, alert quality, incident workflows, and security monitoring use cases. Security Engineering & Platform Support Support the engineering, administration, and optimization of cyber security tools and platforms. Assist with log source onboarding, data normalization, telemetry validation, and use-case development. Partner with Infrastructure, Cloud, Identity, Application, and Security Operations teams to improve visibility and response capability. Build scripts, queries, automation, dashboards, and technical workflows that improve investigation speed and quality. Help mature enterprise security capabilities across SIEM, EDR, NDR, SOAR, cloud security, identity security, and forensic tooling. AI, Security Automation & Emerging Technologies Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis. Demonstrate curiosity and willingness to learn emerging AI, automation, and agent-assisted security operations capabilities. Contribute to team initiatives involving AI-assisted workflows, personal security agents, team-developed agents, and operational automation. Show evidence of hands-on experimentation through lab work, scripting, automation, prompt testing, AI tools, or practical tinkering. Understand the security considerations of AI usage, including data protection, responsible use, prompt safety, and operational governance. Threat Emulation, Red Teaming & Purple Team Support, Preferred Apply an offensive security mindset during investigations to better understand attacker behavior, objectives, and tradecraft. Support threat emulation and purple team activities that validate detections, controls, and response procedures. Use knowledge of penetration testing, red teaming, adversary simulation, or ethical hacking to strengthen blue team defenses. Assist with threat actor tracking, attack path analysis, lateral movement analysis, persistence review, and detection validation. Preferred experience with MITRE ATT&CK, Atomic Red Team, adversary emulation, detection testing, BAS tools, or offensive security labs. Leadership &