MatchPoint Solutions is a fast-growing, young, energetic global IT-Engineering services company with clients across the US. We provide technology solutions to various clients like Uber, Robinhood, Netflix, Airbnb, Google, Sephora, and more! More recently, we have expanded to working internationally in Canada, China, Ireland, UK, Brazil, and India. Through our culture of innovation, we inspire, build, and deliver business results, from idea to outcome. We keep our clients on the cutting edge of the latest technologies and provide solutions by using industry-specific best practices and expertise.
We are excited to be continuously expanding our team. If you are interested in this position, please send over your updated resume. We look forward to hearing from you!
Job Description
Role: Information Technology Manager II
Contract Length: 3-6 months contract (contract to hire)
Location: Centennial, CO (Remote with travel to designated office location may be required based on business needs and leadership direction.)
Rate : $85 to $90 per hour
Overview
- We are seeking an experienced cybersecurity leader to oversee advanced incident response, digital forensics, threat hunting, detection engineering, and security operations initiatives.
- This role is responsible for leading complex investigations, supporting enterprise security platforms, improving detection and response capabilities, and mentoring cybersecurity professionals across the organization.
Key Responsibilities
Cyber Incident Response & Investigation
- Direct sophisticated cybersecurity investigations spanning enterprise, cloud, hybrid, and on-premises environments.
- Execute the complete incident response lifecycle, including identification, triage, impact analysis, containment, eradication, recovery, and post-incident documentation.
- Investigate security events involving network compromises, credential misuse, ransomware, insider threats, fraud, unauthorized activity, and advanced adversary campaigns.
- Maintain proper evidence handling practices and chain-of-custody requirements for legal, regulatory, compliance, and forensic matters.
- Develop investigative reports, root cause assessments, executive-level summaries, and corrective action recommendations. Digital Forensics & Malware Investigation
- Conduct digital forensics and incident response activities across endpoint, identity, cloud, network, application, and Windows environments.
- Perform forensic examinations, artifact reviews, timeline reconstruction, and evidence acquisition.
- Gather and analyze information from hosts, applications, cloud resources, identities, email systems, and network environments.
- Evaluate malicious files, malware behavior, persistence techniques, attacker tools, and indicators of compromise.
- Assist with highly sensitive investigations involving Legal, Human Resources, Compliance, Insider Risk, and business teams. Threat Hunting & Detection Development
- Perform proactive threat hunting activities to uncover attacker behavior, emerging risks, and security control deficiencies.
- Create, optimize, and enhance SIEM detections, alerting logic, correlation rules, KQL searches, dashboards, and automated response processes.
- Leverage threat intelligence, MITRE ATT&CK, adversary tactics, and lessons learned from incidents to strengthen detection coverage.
- Collaborate with SOC, Threat Intelligence, Engineering, and Platform teams to improve visibility and incident response effectiveness.
- Drive ongoing enhancements to monitoring capabilities, alert fidelity, response workflows, and security use cases. Security Engineering & Platform Administration
- Support implementation, administration, and continual improvement of cybersecurity technologies and platforms.
- Assist with telemetry onboarding, log integration, normalization efforts, validation activities, and security use case development.
- Work alongside Infrastructure, Cloud, Identity, Application, and Security Operations teams to strengthen security monitoring and response.
- Develop automation, scripts, dashboards, queries, and technical processes that accelerate investigations and improve outcomes.
- Advance enterprise security capabilities across SIEM, EDR, NDR, SOAR, identity security, cloud security, and forensic platforms. AI, Automation & Emerging Security Technologies
- Utilize AI-enabled tools, copilots, scripting, and automation solutions to improve investigative processes, reporting, and analysis.
- Demonstrate enthusiasm for learning and adopting emerging AI-driven and automated security operations technologies.
- Participate in initiatives focused on AI-enhanced workflows, operational automation, security agents, and team-developed solutions.
- Show practical experience through lab exercises, automation efforts, scripting projects, AI experimentation, or hands-on development.
- Understand AI security considerations, including governance, prompt safety, responsible usage, and data protection requirements. Threat Emulation, Red Teaming & Purple Team Collaboration (Preferred)
- Apply an adversarial mindset to investigations to better understand attacker objectives, techniques, and behaviors.
- Participate in threat emulation and purple team exercises that test security controls, detections, and response readiness.
- Utilize knowledge of ethical hacking, penetration testing, adversary simulation, and red team methodologies to enhance defensive capabilities.
- Support attack path reviews, threat actor analysis, lateral movement investigations, persistence assessments, and detection validation efforts.
- Preferred experience with BAS platforms, Atomic Red Team, MITRE ATT&CK, adversary simulation frameworks, detection testing, or offensive security labs. Leadership & Team Development
- Act as a senior technical resource during major security investigations and response engagements.
- Provide mentorship to Security Analysts, SOC Leads, Incident Responders, and Security Engineers on investigative and forensic practices.
- Contribute to operational documentation, threat hunting methodologies, standards, runbooks, and playbooks.
- Support ongoing maturity efforts across DFIR, Incident Response, Detection Engineering, Threat Hunting, and Security Automation programs.
- Communicate effectively with technical teams, executive leadership, Legal, HR, Compliance, and business stakeholders.
Required Qualifications
- 5+ to 10+ years of experience in Incident Response, Cybersecurity, Security Operations, Threat Hunting, Detection Engineering, DFIR, or related security disciplines.
- Demonstrated success leading enterprise-scale cyber incident investigations.
- Hands-on expertise with forensic investigations, malware analysis, evidence collection, and formal investigative reporting.
- Experience operating within cloud, hybrid, endpoint, identity, network, and traditional on-premises environments.
- Background creating automation, detections, scripts, engineering solutions, playbooks, or workflows that strengthen security operations.
- Technical Expertise
Strong Knowledge Of
- Microsoft Entra ID, Active Directory, Azure, Microsoft 365, identity security principles, and authentication technologies.
- Windows operating systems, forensic artifacts, authentication events, endpoint telemetry, and persistence methods.
- Security concepts across Azure, AWS, GCP, SaaS environments, logging, monitoring, and identity platforms.
- MITRE ATT&CK, cyber kill chain methodologies, threat intelligence practices, and threat-informed defense strategies.
- Security operations technologies including SIEM, SOAR, EDR, NDR, vulnerability management, network security, and email security.
- Experience With SIEM technologies including Microsoft Sentinel, Splunk, QRadar, or similar platforms.
- XDR and EDR solutions such as Microsoft Defender for Endpoint, Microsoft Defender XDR, CrowdStrike, SentinelOne, or equivalent tools.
- Forensic analysis platforms, endpoint investigations, evidence preservation, timeline creation, artifact acquisition, and forensic imaging.
- PowerShell, Python, SQL, APIs, Kusto Query Language, automation development, and scripting technologies.
- Malware triage, detection engineering, threat hunting, dashboard creation, alert optimization, correlation logic, and response orchestration.
- DFIR Capabilities
- Experience conducting artifact-driven investigations involving identity, endpoint, cloud, network, and email data.
- Knowledge of event logs, registry artifacts, attacker techniques, authentication behaviors, persistence methods, and Windows forensic artifacts.
- Ability to investigate phishing activity, credential compromise, privilege escalation, lateral movement, command execution, and data access incidents.
- Experience preparing forensic timelines, investigation reports, executive summaries, and mitigation recommendations.
- Capable of operating independently during critical or high-severity incidents while maintaining documentation quality and evidence integrity.
Preferred Qualifications
- Bachelor's degree in Cyber Security, Computer Science, Information Technology, Digital Forensics, or a related discipline. Equivalent experience will be considered.
- Experience supporting regulatory, compliance, fraud, insider risk, HR, or legal investigations.
- Background in malware analysis, red teaming, penetration testing, threat hunting, purple team operations, or detection engineering.
- Experience with AI-powered security solutions, automation frameworks, copilots, personal lab environments, scripting, or security agents.
- Experience within Microsoft-centric environments utilizing Microsoft Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, and KQL.
Preferred Certifications
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Forensic Examiner (GCFE)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Reverse Engineering Malware (GREM)
- GIAC Cloud Forensics Responder (GCFR)
- GIAC Network Forensic Analyst (GNFA)
- GIAC Cyber Threat Intelligence (GCTI)
- Offensive Security Certified Professional (OSCP)
- Certified Ethical Hacker (CEH)
- Certified Information Systems Security Professional (CISSP)
- Microsoft Security Operations Analyst
- Microsoft Cybersecurity Architect
MatchPoint Solutions provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.