ForgeApply · Job listing
Information Technology Manager II
Arrow Electronics
Tailor your resume for this Arrow Electronics job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Arrow Electronics's site. Free trial, no card required.
About this role
Position: Information Technology Manager II Job Description: What You'll Be Doing: Incident Response & Investigations • Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments.
• Conduct end-to-end incident response activities including triage, scoping, containment, eradication, recovery, and post-incident reporting.
• Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat actor activity.
• Preserve evidence and maintain chain-of-custody procedures for forensic, legal, compliance, and regulatory investigations.
• Produce clear investigative findings, root cause analysis, executive summaries, and remediation recommendations.
Digital Forensics & Malware Analysis • Perform DFIR activities across Windows, cloud, identity, endpoint, network, and application environments.
• Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection.
• Collect, analyze, and interpret host, network, cloud, email, identity, and application artifacts.
• Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise.
• Support sensitive investigations involving Legal, HR, Compliance, Insider Risk, and business stakeholders.
Threat Hunting & Detection Engineering • Conduct proactive threat hunting to identify adversary behaviors, emerging threats, and control gaps.
• Develop, tune, and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows.
• Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage.
• Partner with SOC, Threat Intelligence, Engineering, and Platform teams to validate visibility and improve response outcomes.
• Support continuous improvement of threat detection, alert quality, incident workflows, and security monitoring use cases.
Security Engineering & Platform Support • Support the engineering, administration, and optimization of cyber security tools and platforms.
• Assist with log source onboarding, data normalization, telemetry validation, and use-case development.
• Partner with Infrastructure, Cloud, Identity, Application, and Security Operations teams to improve visibility and response capability.
• Build scripts, queries, automation, dashboards, and technical workflows that improve investigation speed and quality.
• Help mature enterprise security capabilities across SIEM, EDR, NDR, SOAR, cloud security, identity security, and forensic tooling.
AI, Security Automation & Emerging Technologies • Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis.
• Demonstrate curiosity and willingness to learn emerging AI, automation, and agent-assisted security operations capabilities.
• Contribute to team initiatives involving AI-assisted workflows, personal security agents, team-developed agents, and operational automation.
• Show evidence of hands-on experimentation through lab work, scripting, automation, prompt testing, AI tools, or practical tinkering.
• Understand the security considerations of AI usage, including data protection, responsible use, prompt safety, and operational governance.
Threat Emulation, Red Teaming & Purple Team Support, Preferred • Apply an offensive security mindset during investigations to better understand attacker behavior, objectives, and tradecraft.
• Support threat emulation and purple team activities that validate detections, controls, and response procedures.
• Use knowledge of penetration testing, red teaming, adversary simulation, or ethical hacking to strengthen blue team defenses.
• Assist with threat actor tracking, attack path analysis, lateral movement analysis, persistence review, and detection validation.
• Preferred experience with MITRE ATT&CK, Atomic Red Team, adversary emulation, detection testing, BAS tools, or offensive security labs.
Leadership & Mentorship • Serve as a senior technical lead during significant cyber security investigations and incident response efforts.
• Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers on investigative and forensic methodologies.
• Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation.
• Help mature the organization’s DFIR, Incident Response, Detection Engineering, Threat Hunting, and Security Automation capabilities.
• Communicate effectively with technical teams, leadership, Legal, HR, Compliance, and business stakeholders.
What We Are Looking For: • 5–10+ years of experience in Cyber Security, Incident Response, DFIR, Threat Hunting, Detection Engineering, Security Operations, or related disciplines.
• Proven experience leading enterprise-level cyber incident response investigations.
• Hands-on experience with digital forensic analysis, evidence collection, malware analysis, and investigative reporting.
• Experience working across cloud, hybrid, identity, endpoint, network, and on-premises enterprise environments.
• Experience developing detections, automations, playbooks, scripts, queries, or engineering solutions that improve security outcomes.
Technical Skills Strong understanding of: • Microsoft Entra ID, Active Directory, Azure, Microsoft 365, identity security, and enterprise authentication concepts.
• Windows operating systems, endpoint telemetry, authentication logs, forensic artifacts, and persistence mechanisms.
• Cloud security concepts across Azure, AWS, GCP, SaaS, identity, logging, and monitoring environments.
• Incident response frameworks, cyber kill chain, MITRE ATT&CK, threat intelligence, and threat-informed defense.
• Enterprise security operations including SIEM, EDR, NDR, SOAR, vulnerability data, network security, and email security.
Hands-On Experience Wit
Tailor your resume for this Arrow Electronics role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior IT Professional II — Texas A&M University System · College Station, TX
- Manager II Technology — Elevance Health · OH-COLUMBUS, 1006 N HIGH ST, STE 103 | FL-LAKE MARY, 3200 LAKE EMMA RD, STE 1000 | TN-NASHVILLE, 22 CENTURY BLVD, STE 310
- Tech Services Technician II — Levi Strauss & Co. · Henderson, NV
- Desktop Engineering Manager II ITS — Andersen · Oak Park Heights, MN
- IT Technician II — Lennar · Tallahassee FL - Virtual | Miami, FL (Job Posting Location)
- Senior IT Manager — Eliseai · New York City
- Senior IT Manager — Pomelocare · Remote
- Senior IT Network Engineer II — Rocketlab · Long Beach, CA
More like this: More jobs at Arrow Electronics · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)