Lead - Cybersecurity Operations

Posted Yesterday
Be an Early Applicant
Denver, CO, USA
In-Office
110K-146K Annually
Senior level
Aerospace • Travel
The Role
Leads cybersecurity operations, including incident monitoring and response, threat hunting, vulnerability management, digital forensics, security-tool administration, and penetration-test remediation. Oversees onshore SOC activities, coordinates with offshore analysts, maintains SOPs and incident documentation, tracks security metrics and SLAs, and supports threat intelligence, security awareness, and purple, red, and blue team engagements. Provides technical guidance, analyst training, vendor coordination, management reporting, and after-hours incident support.
Summary Generated by Built In

Working at Frontier Airlines  

At Frontier, our mission is to Make Every Flight Count. That mission guides how we support our customers, our people and the operation every day.  

As a Frontier employee, your work connects to more than a single role. Whether you’re supporting flights, helping customers, maintaining aircraft, leading teams or working behind the scenes, you help create a travel experience that is safe, reliable and built around value.  

Our work is guided by our core values: customer first, safety always, operational excellence and one team. These values shape how we make decisions, support each other and deliver for the people who count on us.  

Support for work, life and travel  

Frontier offers benefits, programs and travel privileges designed to support eligible employees at work and beyond. Availability may vary by role, employment status, eligibility, location, schedule, applicable policies and current plan details.  

Depending on role and eligibility, available benefits and programs may include:  

  • Medical, dental and vision coverage 
  • 401(k) retirement savings options 
  • Paid holidays, vacation time and sick time 
  • Travel privileges on Frontier Airlines and participating partner airlines, based on current program rules and availability 
  • Buddy passes, based on eligibility and program rules 
  • Travel-related discounts and employee discounts on select products, services and vendors 
  • A hybrid schedule for eligible headquarters roles based in Denver, Colorado 
  • Business casual dress options for eligible corporate and support roles 
  • Employee support programs and resources, including the HOPE League, Frontier Airlines’ nonprofit organization 

About Frontier Airlines 

Frontier Airlines is a Denver-based airline serving destinations across the United States and select international markets. Our people support every part of the travel journey, from airport operations and flight crews to aircraft maintenance, customer support, corporate teams and more.  

We’re focused on delivering meaningful value by making travel more accessible, practical and easy to personalize for our customers. Across the airline, our teams help support a safe, reliable and efficient operation while continuing to strengthen the experience for the people who choose Frontier. 

What Will You Be Doing?

The Lead Analyst, Cybersecurity Operations will be part of the Cybersecurity team that analyzes, implements, monitors, troubleshoots, and audits the cybersecurity of the Frontier network infrastructure. The Lead Analyst provides timely and comprehensive updates to the Sr. Manager of Cybersecurity Operations on the intelligence of internal/external threats for detection, monitoring, threat hunting, and incident response. The scope of environment includes system-monitoring platforms, anti-virus, DLP, URL filtering, and PCI environments and any new leading tools that are brought into the network. The Lead Analyst will oversee the SOC team onshore and will be responsible for the Vulnerability Management program, attaining SLA benchmarks, the collection of tools and performance metrics, ensuring SOP’s and playbooks are well updated and audited, incident response, digital forensics, and supporting penetration remediation on applications/systems. The Lead Analyst onshore will work closely with the peer Lead Analyst offshore to provide daily handover reports, status of threat intelligence alerts, vulnerability management progress, escalation of issues to the Level 2 team, and will hold daily standup calls between the offshore and onshore teams.  The Lead Analyst(s) will meet multiple times per week with the Sr. Manager of Cybersecurity Operations to review ServiceNow tickets, projects, security tool audits, known exploited vulnerabilities and other high priority issues that arise during the week.

Essential Functions

  • Monitor, investigate, analyze, respond, and report to cyber incidents identified through detection/response platforms.
  • Lead support to Management in detecting and responding to cybersecurity alerts and incident activity.
  • Responsible for engaging and escalating incidents to Cyber Operations Management and other Cyber Incident Response Team members.
  • Actively support incident response activities, efforts, and training exercises (e.g., incidents, tabletops, threat simulations) and be the lead incident response analyst.
  • Actively drive risk reduction efforts for known cyber security vulnerabilities and known attack traffic patterns/indicators of compromise (IOC).
  • Actively monitor security threats and risks, provide in-depth incident analysis, evaluate security incidents, provide proactive threat research, and recommend mitigation strategies.
  • Evaluate and determine if/when cybersecurity violations have occurred through examination of network/application logs, open-source research, vulnerability and configuration scan data, and user provided reports.
  • Proactively conduct investigations, analysis, and evaluation of projects to determine cybersecurity risk and feasibility as required.
  • Administer, maintain, tune, and perform heath checks on cybersecurity products and services (such as secure mail gateway, SIEM, EDR, vulnerability management, brand monitoring, threat intelligence, security rating, DDoS, web proxy, file integrity monitoring (FIM), data loss prevention (DLP), User Entity & Behavioral Analytics (UEBA), and other).
  • Provide and implement recommendations for new technical controls to help mitigate security vulnerabilities.
  • Responsible for leading the vulnerability management program functions including hosting weekly meetings with Stakeholders and the operations team, creating and tracking tickets for all vulnerabilities, holding stakeholder teams to meet SLA’s, and reporting to the Sr. Manager of Cybersecurity on a weekly basis.
  • Actively perform threat hunting activities in the environment to detect cyber threats in the network.
  • Coordinate and support purple, red, and blue team engagements.
  • Provide cybersecurity technical assistance when needed by system/application owners.
  • Support multiple day-to-day cybersecurity tasks and projects efforts.
  • Provide regular status updates to Management on projects and remediation efforts.
  • Solid understanding of cybersecurity policies and procedures, ability to draft, modify and create standard operating procedures (SOPs) for use of other team members.
  • Support organizational Security Awareness Training efforts (suggest training topics, coordinate phishing campaigns, enable awareness to end-users in support of incidents).
  • Support vulnerability assessments functions (such as: enterprise pen testing, application pen testing, static/dynamic testing, scorecard assessments).
  • Participate and support afterhours/on-call rotation requirements for cybersecurity incidents.
  • Responsible for developing, monitoring, and tracking cyber security metrics on a recurring basis, including creating PowerPoint slide decks for presentations.
  • Coordinate response and remediation efforts across various departments in a cooperative and beneficial manner.
  • Responsible for maintaining Incident Response documentation and auditing member contact information on at least a semi-annual basis or as needed.
  • Responsible for attending all vendor meetings and acts as the point of contact for our Cybersecurity vendors.
  • Demonstrate ownership and understanding of tasks when engaging with other team members.
  • Provide leadership, guidance and partnership to Analyst(s) and Senior Analyst(s).
  • Responsible for the onboarding and training of new analysts to the Cybersecurity Operations team.
  • Provide support to management team.

Qualifications

  • Bachelor’s degree in computer science, technology, or equivalent combination of education and relevant experience (required).
  • 6+ years of relevant IT/Cybersecurity experience (required).
  • 3+ years in a Supervisor or Lead Analyst, Cybersecurity role (required).
  • 5+ years in security operations with hands-on experience with enterprise cybersecurity products, such as Qualys, SentinelOne, Proofpoint, Office365, Microsoft Defender for Cloud, Microsoft Defender for Identity (required).
  • 5+ years of SIEM (security information and event management) platform experience (required).
  • 4+ years supporting adversary tactics and techniques based on MITRE attack framework (required).
  • Knowledge of cyber security standards and frameworks such as ISO 27001, NIST CSF, NIST-800-53, PCI DSS ASV (highly desired).
  • Hands-on experience with tools like PowerShell, Vulnerability Management suite, Wireshark, and NMAP (required).
  • Industry cybersecurity certification:  CompTIA: Security+ or Pentest+, CEH, CISSP, OCSP, SANS: GCIH or GSEC, CISSP, ISACA: CISA or CISM, Security+, SSCP, or CCNA (required, or willing to attain within 3 months of start date).
  • Hands-on Cloud infrastructure (Azure/AWS/GCP) cybersecurity remediation experience (Microsoft Defender) (required).
  • Hands-on experience with next-gen endpoint detection/response (EDR), Enterprise Firewall, IPS, Log Management, Cisco, and Checkpoint experience (required).
  • URL Filtering (web proxy) and troubleshooting experience (desirable).
  • Solid understanding of a variety of OSINT techniques and digital forensics to aid in proactive Threat Hunting and crown jewel asset protection.
  • Has demonstrable PowerPoint presentations and assists Management with gathering metrics on a routine basis and actively aids in a continual reduction of risk and vulnerabilities resulting in an overall more secure environment quarter-over-quarter.
  • Proactively identifies areas within Frontier that require hardening and protection and deploys solutions with the respective supporting teams.

Knowledge, Skills and Abilities

  • Ability to understand and communicate industry trends, maintain awareness of current vulnerabilities and security concerns, and understand their impact on the organization.
  • Ability to troubleshoot security/network/system-related issues and manage security components in operating environment.
  • Solid understanding of attack vectors, common intrusion techniques, brand intelligence, threat intelligence, application/host/network security hardening, enterprise risk management concepts, and MITRE Attack Framework principles.
  • Knowledge of enterprise risk assessment tools, technologies, and methodologies.
  • Broad and thorough knowledge of enterprise security systems and devices.
  • Knowledgeable in penetration testing, vulnerability assessments, and remediation.
  • Designing and implementing cybersecurity controls in an operating environment.
  • Able to make accurate work estimates and deliver projects within schedule constraints.
  • Proficiency in network traffic analysis and packet analysis.
  • Well-organized with the ability to coordinate and prioritize multiple tasks simultaneously with varying deadlines.
  • Demonstrate understanding and in-depth knowledge of security threats and applying actionable data to processes and procedures.
  • Demonstrate understanding and knowledge correlation analysis, along with an understanding of monitoring programs, such as Splunk and other SIEMs.
  • Understanding of the OSI 7-layer model.
  • Willing to work more than 40 hours and some weekends as needed.
  • Willing to support after-hours and weekend on-call rotation support.
  • Strong written and verbal communication skills.
  • Ability to remain organized and to elicit cooperation from a wide variety of sources including team members and other internal departments.
  • Ability to quickly learn new systems, devices, and methodologies.
  • Able to work independently and with a team of peers and other departments.
  • Proactively identifies and addresses various gaps and solutions within the boundaries of Cybersecurity Operations and deploys these solutions; creates roadmap on these efforts to align with Cyber Operations goals and provides periodic updates as needed.

Equipment Operated

Laptop endpoint running Windows and a variety of cybersecurity applications, commercial and open-source tools.

Work Environment

Denver based employees are required to be in the office 4 days a week, work remote on Friday.This is subject to change at any time.  Requires being on-call for after-hours and weekend support.

Physical Effort

Light physical effort required by handling objects up to 20 pounds occasionally and/or up to 10 pounds frequently.

Supervision Received

General Direction:  The incumbent normally receives little instruction on day-to-day work and receives general instructions on new assignments.

Salary Range: $110,114 - $146,157 - Please note: this role will close on or before 12/31/26. 

Positions Supervised

  • None

Workplace Policies

Disclaimer: The above statements are intended only to describe the general nature and level of work required of the referenced position; they are not intended to be an exhaustive list of all responsibilities, duties, and skills required of individuals in this position.  Please be advised that duties and expectations of this position may be subject to change.

Frontier Airlines, Inc. is an equal opportunity employer and, as such, is committed to providing equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, national origin, age, marital status, veteran status, sexual orientation, gender identity or expression, disability status, pregnancy, genetic information, citizenship status or any other basis protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Frontier Airlines is a Zero Tolerance Drug-Free Workplace. All prospective DOT safety-sensitive employees are subject to pre-employment testing for the following drugs and their metabolites: Marijuana, Cocaine, Amphetamines, Opioids and Phencyclidine (PCP). Further, any DOT safety-sensitive job applicant who is found to have tested positive on any required drug or alcohol test at a former employer will be considered ineligible for employment with Frontier.

Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Skills Required

  • Bachelor’s degree in computer science, technology, or equivalent education and relevant experience
  • 6+ years of relevant IT or cybersecurity experience
  • 3+ years as a supervisor or lead cybersecurity analyst
  • 5+ years in security operations with hands-on enterprise cybersecurity product experience
  • 5+ years of SIEM platform experience
  • 4+ years supporting adversary tactics and techniques based on the MITRE ATT&CK framework
  • Hands-on experience with PowerShell, vulnerability management tools, Wireshark, and Nmap
  • Industry cybersecurity certification, or willingness to obtain one within three months of starting
  • Hands-on cloud infrastructure cybersecurity remediation experience with Azure, AWS, or GCP and Microsoft Defender
  • Hands-on experience with EDR, enterprise firewalls, IPS, log management, Cisco, and Check Point
  • URL filtering and web proxy troubleshooting experience
  • Knowledge of OSINT techniques and digital forensics for threat hunting and asset protection
  • Experience creating PowerPoint presentations and gathering cybersecurity metrics
  • Strong knowledge of attack vectors, intrusion techniques, threat intelligence, security hardening, risk management, and MITRE ATT&CK
  • Proficiency in network traffic and packet analysis
  • Availability for after-hours and weekend on-call rotation
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Denver, CO
4,789 Employees
Year Founded: 1994

What We Do

Frontier Airlines (NASDAQ: ULCC) is committed to “Low Fares Done Right.” Headquartered in Denver, Colorado, the company operates 120 A320 family aircraft and has the largest A320neo family fleet in the U.S. The use of these aircraft, Frontier’s seating configuration, weight-saving tactics and baggage process have all contributed to Frontier’s continued ability to be the most fuel-efficient of all major U.S. carriers when measured by available seat miles (ASMs) per fuel gallon consumed. With more than 230 new Airbus planes on order, Frontier will continue to grow to deliver on the mission of providing affordable travel across America.

Similar Jobs

Peraton Logo Peraton

Cybersecurity Operations Lead

Aerospace • Information Technology • Security • Cybersecurity • Defense
In-Office
Colorado Springs, CO, USA
18000 Employees
112K-179K Annually

RB Global Logo RB Global

Lead, Cybersecurity Operations

Automotive • eCommerce • Transportation • Energy • Agriculture • Industrial
Remote or Hybrid
2 Locations
445 Employees
Remote or Hybrid
2 Locations
2445 Employees

Similar Companies Hiring

Red 6 Thumbnail
Aerospace • Hardware • Software • Virtual Reality • Defense
Orlando, Florida
186 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account