Full-Time

Triage Security Engineer 3

Posted on 11/23/2025

Arctic Wolf

Arctic Wolf

1,001-5,000 employees

24x7 cloud-native cybersecurity with concierge SOC

No salary listed

Cork, Ireland

In Person

Category
IT & Security (1)
Requirements
  • 3-5 years relevant experience
  • Relevant education could include university degree, college diploma, or industry certifications
  • Strong understanding of Active Directory function
  • Strong understanding of Windows utilities
  • Strong understanding of firewall concepts
  • Understanding of common business network environments
  • Basic understanding of security concerns for common cloud-based infrastructure-as-a-service providers
  • Strong understanding of security concerns for common cloud-based services
  • Understanding of security principles and tools
  • Basic understanding of DTR process, and practical use
  • Strong understanding of Identify, Contain, and Eradicate phases of Incident Response
  • Security requirements: Conduct duties in accordance with AWN’s Information Security policies, standards, processes, and controls
  • Background checks are required for this position
  • This position may require access to information protected under U.S. export control laws and regulations including EAR
  • Travel requirements: typically 10% or less of business travel
  • Environment and physical demands: sedentary work, visual acuity, mobility in office, may lift up to 25 pounds
Responsibilities
  • Analyze incoming security events based on different data points; network, endpoint, and log sources expediently, consistently, and accurately
  • Leverage education and training to identify correlations in client environment to determine if behavior is expected
  • Effectively navigate the Incident Triage Dashboard and load the Tier 3 incident queues
  • Own overall technical guidance and direction for the case for the customer, with authority to guide less experienced Triage team members in support tasks and participation in customer interactions
  • Escalate case to Concierge Security Team should customer requests require business relationship support for feature requests
  • Prioritize low or medium to complex incoming events based on SLO determined by customer exceptionally well
  • Use independent judgement to determine prioritization of events and alerts and escalates as needed
  • Independently steer complex investigations within area of expertise, and leverage security knowledge to engage the other experts within other disciplines to resolve matters appropriately
  • Review traffic and logs to determine secondary incidents of compromise and other malicious activity; escalate incidents from Tier 3 to the customer in a heightened state if a true positive event is suspected
  • Review complex customer security requests including but not limited to active customer breaches and compromises or unexpected activity found in their network; independently within area of expertise using security knowledge and engage the other experts within other disciplines to resolve matters appropriately as required to resolve issues quickly
  • Act as a 3rd tier escalation for customer security issues on the phone providing guidance and expertise independently; when a solution is beyond the scope of knowledge, engaging other experts to provide solutions appropriately
  • Conduct quality reviews on outgoing tickets and security engagements
  • At a system level, identify opportunities to improve processes, workflows, and tooling to increase efficiency, and recommend solutions to management based on findings
  • Advise peers and receive input on how to provide a better customer experience
  • Exercise security expertise using the development platform to elevate more precise signal with minimal noise
  • Suggest news ways to refine signal to noise
  • Address all customer questions or concerns related to Tier 3+ security incident tickets
  • Serve as an escalation point for TSA, TSE1, and TSE2, questions or issues
  • Coach and mentor other team members based on expertise
  • Drive security compromise investigations mentoring Tier 2 team members, looking for root point of compromise in a post-mortem
  • Act as the escalation point providing guidance and next steps
  • Prioritize task work according to understood and implied priorities
  • Interact on behalf of AWN with customers as a technical representative and senior-level provider of security services

Arctic Wolf provides continuous cybersecurity protection tailored to each organization. It uses a cloud-native platform paired with a dedicated concierge team to deliver around-the-clock monitoring and security operations (SOC) on a subscription basis. The platform integrates security functions to avoid tool sprawl and alert fatigue, while the concierge team works with clients to meet their specific needs. Clients pay for ongoing protection with 24x7 coverage, and Arctic Wolf offers tools like a Total Cost of Ownership Calculator to illustrate savings and ROI. This approach differentiates Arctic Wolf from competitors by combining a unified, cloud-based platform with a personalized delivery model that embeds security experts with each client. The goal is to improve clients’ security posture, reduce unnecessary security tool investments, and lower total costs while providing reliable, continuous monitoring.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

$899.2M

Headquarters

Eden Prairie, Minnesota

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • Gartner names Arctic Wolf Leader in 2026 MDR Magic Quadrant for Aurora.
  • Datalink partnership expands AI-led SOC to U.S. and Canada MSPs.
  • Cybersecurity market grows to $500 billion by 2030 amid ransomware surge.

What critics are saying

  • 250 layoffs in sales and product delay Aurora platform revenue in 3-6 months.
  • CrowdStrike erodes mid-market share with superior Falcon endpoint detection.
  • SentinelOne's autonomous AI undercuts concierge model with lower costs.

What makes Arctic Wolf unique

  • Aurora Superintelligence Platform processes 10 trillion security events weekly.
  • Concierge Delivery Model pairs AI with human experts for triaged alerts.
  • Swarm of Experts AI framework resolves cases 15 times faster than humans.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Equity For All Employees

Diverse, equitable, & inclusive workplace

Remote Work Opportunities

Paid Parental Leave

Flexible Paid Time Off For All Employees

Professional Development

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
The Associated Press
Mar 23rd, 2026
Arctic Wolf launches world's largest commercial agentic SOC with AI-driven security operations

Arctic Wolf has launched the Aurora Agentic SOC, described as the world's largest commercial agentic security operations centre, shifting from human-led to AI-driven security operations. Built on the Aurora Superintelligence Platform, the system uses a three-tier "Swarm of Experts" model comprising oversight agents, authoritative agents and process agents. The turnkey solution addresses low AI adoption rates in cybersecurity, with only 30% of teams currently integrating AI security tools. Arctic Wolf claims the system resolves cases 15 times faster with three times higher-quality tickets and can be deployed in as little as 10 days. The Aurora Agentic SOC is available today as part of Arctic Wolf's Security Operations Bundles and Aurora Managed Endpoint Security. Existing customers will receive the new capabilities at no additional cost.

Yahoo Finance
Mar 23rd, 2026
Arctic Wolf launches Aurora Superintelligence Platform with Swarm of Experts AI framework

Arctic Wolf has launched the Aurora Superintelligence Platform, designed to address trust and reliability challenges in AI-powered cybersecurity. The platform uses a "Swarm of Experts" agentic framework that combines AI with human validation to ensure reliable performance. The system addresses industry concerns around AI hallucinations and model drift that have limited adoption, with Gartner estimating only 1–5% market penetration for AI SOC agents. Arctic Wolf's approach only deploys agents when they demonstrably outperform human-only workflows. The platform incorporates three key elements: the Swarm of Experts framework with hundreds of adaptive agents, a Security Operations Graph processing nine trillion telemetry events weekly, and validation from over 1,000 security analysts. Drawing on 14 years of security operations experience serving over 10,000 customers, the platform integrates real-world expertise whilst maintaining customer-specific business context.

IT Security News
Mar 17th, 2026
CTG unveils cyber resilience scoring dashboard for measurable risk reduction.

CTG unveils cyber resilience scoring dashboard for measurable risk reduction. 2026-03-17 17:03 Read the original article: Information security training Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post Inside the Updated AI Governance Suite Dashboard | Kovrr appeared first on Security Boulevard. This article has been indexed from Security BoulevardRead the original article: Inside the Updated AI Governance Suite Dashboard | Kovrr March 5, 2026 Arctic Wolf released the Arctic Wolf Cyber Resilience Assessment, a risk assessment tool designed to help businesses of almost any size advance their cyber resilience and improve insurability by effectively mapping their security posture against industry-standard frameworks. The release of Arctic Wolf Cyber Resilience Assessment expands Arctic Wolf's Security Journey... May 7, 2024 Barracuda Networks unveiled the BarracudaONE AI-powered cybersecurity platform. BarracudaONE maximizes threat protection and cyber resilience by unifying layered security defenses and providing deep, intelligent threat detection and response for managed service providers (MSPs), other channel partners and end users. BarracudaONE simplifies and strengthens security operations by unifying Barracuda's comprehensive portfolio... June 2, 2025

Yahoo Finance
Mar 16th, 2026
Arctic Wolf appoints Will May as chief revenue officer to drive global growth

Arctic Wolf, a global leader in security operations, has appointed Will May as Chief Revenue Officer. May will lead the company's global go-to-market organisation, overseeing sales and customer-facing teams. May brings over 15 years of go-to-market leadership experience across software and cybersecurity companies. He most recently served as Chief Revenue Officer at Pendo.io and previously held similar roles at ClickUp. He also held senior sales leadership positions at Zscaler and AppDynamics. The appointment comes as Arctic Wolf expands its security operations platform and global footprint, with growing industry adoption of AI and agentic AI. May will focus on building an AI-native revenue organisation whilst scaling the company globally and deepening customer relationships.

GlobeNewswire
Feb 23rd, 2026
Arctic Wolf acquires exposure assessment visionary Sevco Security

Arctic Wolf, a global leader in security operations, has acquired Sevco Security, an exposure assessment platform developer. Financial terms were not disclosed. Sevco was named a Visionary in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms. Sevco's cloud-native technology will integrate with Arctic Wolf's Aurora Platform, providing unified asset intelligence, vulnerability context and security control coverage. The acquisition aims to help organisations shift from reactive defence to proactive security by offering real-time visibility of assets and exposures across hybrid environments. The combined capabilities will complement Arctic Wolf Managed Risk, enabling customers to identify, prioritise and remediate security exposures more effectively. Gartner predicts that by 2027, organisations integrating exposure assessment data will experience 30% less unplanned downtime from exploited vulnerabilities.

INACTIVE