Information Technology Manager II

IS3 Solutions
  • Centennial, CO
  • Quick Apply
1 day ago

Job Description

We are seeking an experienced cybersecurity leader to oversee advanced incident response, digital forensics, threat hunting, detection engineering, and security operations initiatives. This role is responsible for leading complex investigations, supporting enterprise security platforms, improving detection and response capabilities, and mentoring cybersecurity professionals across the organization.

Key Responsibilities

Cyber Incident Response & Investigation

  • Direct sophisticated cybersecurity investigations spanning enterprise, cloud, hybrid, and on-premises environments.
  • Execute the complete incident response lifecycle, including identification, triage, impact analysis, containment, eradication, recovery, and post-incident documentation.
  • Investigate security events involving network compromises, credential misuse, ransomware, insider threats, fraud, unauthorized activity, and advanced adversary campaigns.
  • Maintain proper evidence handling practices and chain-of-custody requirements for legal, regulatory, compliance, and forensic matters.
  • Develop investigative reports, root cause assessments, executive-level summaries, and corrective action recommendations. Digital Forensics & Malware Investigation
  • Conduct digital forensics and incident response activities across endpoint, identity, cloud, network, application, and Windows environments.
  • Perform forensic examinations, artifact reviews, timeline reconstruction, and evidence acquisition.
  • Gather and analyze information from hosts, applications, cloud resources, identities, email systems, and network environments.
  • Evaluate malicious files, malware behavior, persistence techniques, attacker tools, and indicators of compromise.
  • Assist with highly sensitive investigations involving Legal, Human Resources, Compliance, Insider Risk, and business teams. Threat Hunting & Detection Development
  • Perform proactive threat hunting activities to uncover attacker behavior, emerging risks, and security control deficiencies.
  • Create, optimize, and enhance SIEM detections, alerting logic, correlation rules, KQL searches, dashboards, and automated response processes.
  • Leverage threat intelligence, MITRE Telecommunication&CK, adversary tactics, and lessons learned from incidents to strengthen detection coverage.
  • Collaborate with SOC, Threat Intelligence, Engineering, and Platform teams to improve visibility and incident response effectiveness.
  • Drive ongoing enhancements to monitoring capabilities, alert fidelity, response workflows, and security use cases. Security Engineering & Platform Administration
  • Support implementation, administration, and continual improvement of cybersecurity technologies and platforms.
  • Assist with telemetry onboarding, log integration, normalization efforts, validation activities, and security use case development.
  • Work alongside Infrastructure, Cloud, Identity, Application, and Security Operations teams to strengthen security monitoring and response.
  • Develop automation, scripts, dashboards, queries, and technical processes that accelerate investigations and improve outcomes.
  • Advance enterprise security capabilities across SIEM, EDR, NDR, SOAR, identity security, cloud security, and forensic platforms. AI, Automation & Emerging Security Technologies
  • Utilize AI-enabled tools, copilots, scripting, and automation solutions to improve investigative processes, reporting, and analysis.
  • Demonstrate enthusiasm for learning and adopting emerging AI-driven and automated security operations technologies.
  • Participate in initiatives focused on AI-enhanced workflows, operational automation, security agents, and team-developed solutions.
  • Show practical experience through lab exercises, automation efforts, scripting projects, AI experimentation, or hands-on development.
  • Understand AI security considerations, including governance, prompt safety, responsible usage, and data protection requirements. Threat Emulation, Red Teaming & Purple Team Collaboration (Preferred)
  • Apply an adversarial mindset to investigations to better understand attacker objectives, techniques, and behaviors.
  • Participate in threat emulation and purple team exercises that test security controls, detections, and response readiness.
  • Utilize knowledge of ethical hacking, penetration testing, adversary simulation, and red team methodologies to enhance defensive capabilities.
  • Support attack path reviews, threat actor analysis, lateral movement investigations, persistence assessments, and detection validation efforts.
  • Preferred experience with Client platforms, Atomic Red Team, MITRE Telecommunication&CK, adversary simulation frameworks, detection testing, or offensive security labs. Leadership & Team Development
  • Act as a senior technical resource during major security investigations and response engagements.
  • Provide mentorship to Security Analysts, SOC Leads, Incident Responders, and Security Engineers on investigative and forensic practices.
  • Contribute to operational documentation, threat hunting methodologies, standards, runbooks, and playbooks.
  • Support ongoing maturity efforts across DFIR, Incident Response, Detection Engineering, Threat Hunting, and Security Automation programs.
  • Communicate effectively with technical teams, executive leadership, Legal, HR, Compliance, and business stakeholders.

Required Qualifications

  • 5+ to 10+ years of experience in Incident Response, Cybersecurity, Security Operations, Threat Hunting, Detection Engineering, DFIR, or related security disciplines.
  • Demonstrated success leading enterprise-scale cyber incident investigations.
  • Hands-on expertise with forensic investigations, malware analysis, evidence collection, and formal investigative reporting.
  • Experience operating within cloud, hybrid, endpoint, identity, network, and traditional on-premises environments.
  • Background creating automation, detections, scripts, engineering solutions, playbooks, or workflows that strengthen security operations.

Technical Expertise

Strong Knowledge Of

  • Microsoft Entra ID, Active Directory, Azure, Microsoft 365, identity security principles, and authentication technologies.
  • Windows operating systems, forensic artifacts, authentication events, endpoint telemetry, and persistence methods.
  • Security concepts across Azure, AWS, GCP, SaaS environments, logging, monitoring, and identity platforms.
  • MITRE Telecommunication&CK, cyber kill chain methodologies, threat intelligence practices, and threat-informed defense strategies.
  • Security operations technologies including SIEM, SOAR, EDR, NDR, vulnerability management, network security, and email security.

Experience With

  • SIEM technologies including Microsoft Sentinel, Splunk, QRadar, or similar platforms.
  • XDR and EDR solutions such as Microsoft Defender for Endpoint, Microsoft Defender XDR, CrowdStrike, SentinelOne, or equivalent tools.
  • Forensic analysis platforms, endpoint investigations, evidence preservation, timeline creation, artifact acquisition, and forensic imaging.
  • PowerShell, Python, SQL, APIs, Kusto Query Language, automation development, and scripting technologies.
  • Malware triage, detection engineering, threat hunting, dashboard creation, alert optimization, correlation logic, and response orchestration.

DFIR Capabilities

  • Experience conducting artifact-driven investigations involving identity, endpoint, cloud, network, and email data.
  • Knowledge of event logs, registry artifacts, attacker techniques, authentication behaviors, persistence methods, and Windows forensic artifacts.
  • Ability to investigate phishing activity, credential compromise, privilege escalation, lateral movement, command execution, and data access incidents.
  • Experience preparing forensic timelines, investigation reports, executive summaries, and mitigation recommendations.
  • Capable of operating independently during critical or high-severity incidents while maintaining documentation quality and evidence integrity.

Preferred Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, or a related discipline. Equivalent experience will be considered.
  • Experience supporting regulatory, compliance, fraud, insider risk, HR, or legal investigations.
  • Background in malware analysis, red teaming, penetration testing, threat hunting, purple team operations, or detection engineering.
  • Experience with AI-powered security solutions, automation frameworks, copilots, personal lab environments, scripting, or security agents.
  • Experience within Microsoft-centric environments utilizing Microsoft Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, and KQL.

Preferred Certifications

  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Cloud Forensics Responder (GCFR)
  • GIAC Network Forensic Analyst (GNFA)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Offensive Security Certified Professional (OSCP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • Microsoft Security Operations Analyst
  • Microsoft Cybersecurity Architect

Numbers & Facts

LocationCentennial, CO

Skills

  • Administrative Skillsunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Application Hostingunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Authenticationunmatched
  • Automationunmatched
  • CEH - Certified Ethical Hackerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Campaignsunmatched
  • Cloud Applicationsunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Forensicsunmatched
  • Computer Hackingunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Improvementunmatched
  • Corrective Actionunmatched
  • Cyber Investigationunmatched
  • Database Programming Languagesunmatched
  • Documentationunmatched
  • Email Securityunmatched
  • Email Technologyunmatched
  • Emerging Technologyunmatched
  • Enterprise Protectionunmatched
  • Forensic Scienceunmatched
  • GCFA - GIAC Certified Forensic Analystunmatched
  • GCIA - GIAC Certified Intrusion Analystunmatched
  • GCIH - GIAC Certified Incident Handlerunmatched
  • GCP (Good Clinical Practices)unmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • Human Resourcesunmatched
  • Huntingunmatched
  • Hybrid Cloudunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Investigative Reportsunmatched
  • Laboratoryunmatched
  • Laboratory Automationunmatched
  • Leadershipunmatched
  • Legalunmatched
  • Legal Investigationunmatched
  • Malwareunmatched
  • Malware Analysisunmatched
  • Management of Information Systems/Technology (MIS)unmatched
  • Mentoringunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • Microsoft Windows Operating Systemunmatched
  • Network Performance/Analysisunmatched
  • Network Securityunmatched
  • Onboardingunmatched
  • Operational Auditunmatched
  • Operations Security (OPSEC)unmatched
  • Penetration Testingunmatched
  • Phishingunmatched
  • Process Improvementunmatched
  • Python Programming/Scripting Languageunmatched
  • Quality Managementunmatched
  • Ransomwareunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Reporting Dashboardsunmatched
  • Reporting Skillsunmatched
  • Reverse Engineeringunmatched
  • Riskunmatched
  • Risk Managementunmatched
  • Root Cause Analysisunmatched
  • SQL (Structured Query Language)unmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Simulationunmatched
  • Software as a Service (SaaS)unmatched
  • Splunkunmatched
  • Systems Administration/Managementunmatched
  • Team Buildingunmatched
  • Telecommunicationsunmatched
  • Telemetryunmatched
  • Use Casesunmatched
  • Windows PowerShellunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder