- Company Name
- Arctic Wolf
- Job Title
- Triage Security Engineer 3
- Job Description
-
Job title: Triage Security Engineer 3
Role Summary: Operate within a 24/7 Security Operations Centre to triage, investigate, and notify clients of security incidents, managing the incident lifecycle and collaborating with specialized teams for remediation.
Expectations: • High‑volume, real‑time event analysis across network, endpoint, and log sources. • Ability to work independently in a shift environment and maintain a proactive attitude toward continuous learning and process improvement.
Key Responsibilities
- Analyze and triage incoming security events from diverse data sources (SIEM, firewalls, IDS/IPS, EDR, etc.).
- Prioritize alerts based on severity and business impact, ensuring timely notification to stakeholders.
- Conduct deep‑dive investigations, performing forensic analysis and determining root causes.
- Coordinate with Incident Response, Threat Hunting, and concierge security teams to contain, eradicate, and recover from incidents.
- Review and validate outgoing tickets/engagements to identify improvement opportunities.
- Mentor junior analysts and share knowledge across the security operation function.
Required Skills
- 5+ years in Information Security, Network Security, or Cybersecurity roles focused on threat hunting, incident response, or security analysis.
- Strong knowledge of networking protocols, perimeter security (firewalls, IDS/IPS, WAF), authentication (AD, SSO, MFA), cloud IaaS (AWS, Azure, GCP), endpoint protection (EDR/AV), and SaaS platforms (O365, GSuite, Salesforce).
- Proficiency in threat intelligence analysis, proactive threat hunting, incident response lifecycle (analysis, containment, eradication), and forensic investigations.
- Excellent analytical, prioritization, and communication skills for internal and external stakeholders.
- Ability to work effectively in shift‑based, high‑pressure environments.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- Industry certifications such as CompTIA Security+, CEH, CISSP, or GCIH preferred.
---