Demo

Lead Analyst, Cybersecurity Operations

Frontier Airlines
Denver, CO Full Time
POSTED ON 2/20/2025
AVAILABLE BEFORE 5/19/2025

What We Stand For

Low Fares Done Right is our mission and we strive to bring it to life every day. Our ‘Done Right’ promise means delivering not only affordable prices, but making travel friendly and easy for our customers. To do this, we put a great deal of care into every decision and action we take. We must be efficient with the use of our resources and make smart decisions about how we run our business. We must also innovate and be pioneers - we’re not afraid to try new things. While our business requires us to fly high in the air, we also consider ourselves down-to-earth in our approach, creating a warm and friendly experience that truly demonstrates Rocky Mountain Hospitality.

Work Perks

At Frontier, we like to think we’re creating something very special for our team members. Work is why we’re here, but the perks are nice too :

  • Flight benefits for you and your family to fly on Frontier Airlines.
  • Buddy passes for your friends so they can experience what makes us so great.
  • Discounts throughout the travel industry on hotels, car rentals, cruises and vacation packages.
  • Discounts on cell phone plans, movie tickets, restaurants, luggage and over 2,000 other vendors.
  • Enjoy a ‘Dress for your Day’ business casual environment.
  • Flexible work schedules that support work / life balance.
  • Total Rewards program including a competitive base salary, short term incentives, long-term incentives, paid holidays, 401(k) plan, vacation / sick time and medical / dental / vision insurance that begins the 1st of the month following your hire date.
  • We play our part to make a difference. The HOPE League, Frontier Airlines’ non-profit organization, is dedicated to providing employees financial assistance during catastrophic hardship.

Who We Are

Frontier Airlines is committed to offering ‘Low Fares Done Right’ to more than 100 destinations and growing in the United States, Canada, Dominican Republic and Mexico on more than 350 daily flights. Headquartered in Denver, Frontier’s hard-working aviation professionals pride themselves in delivering the company’s signature Low Fares Done Right service to customers. Frontier Airlines is the proud recipient of the Federal Aviation Administration’s 2018 Diamond Award for maintenance excellence and was recently named the industry’s most fuel-efficient airline by The International Council on Clean Transportation (ICCT) as a result of superior technology and operational efficiencies.

What Will You Be Doing?

The Lead Analyst, Cybersecurity Operations will be part of the Cybersecurity team that analyzes, implements, monitors, troubleshoots, and audits the cybersecurity of the Frontier network infrastructure. The analyst provides timely and comprehensive intelligence on internal / external threats for detection, monitoring, threat hunting, and incident response. The scope of environment includes system-monitoring platforms, anti-virus, DLP, URL filtering, and PCI environments. The analyst will be responsible for performing alert analysis, incident response, digital forensics, and supporting penetration remediation on applications / systems.

Essential Functions

  • Monitor, investigate, analyze, respond, and report to cyber incidents identified through detection / response platforms.
  • Lead support to Management in detecting and responding to cybersecurity alerts and incident activity.
  • Responsible for engaging and escalating incidents to CyberOps Management and other Cyber Incident Response Team members.
  • Actively support incident response activities, efforts, and training exercises (e.g., incidents, tabletops, threat simulations) and be the lead incident response analyst.
  • Actively drive risk reduction efforts for known cyber security vulnerabilities and known attack traffic patterns / indicators of compromise (IOC).
  • Actively monitor security threats and risks, provide in-depth incident analysis, evaluate security incidents, provide proactive threat research, and recommend mitigation strategies.
  • Evaluate and determine if / when cybersecurity violations have occurred through examination of network / application logs, open-source research, vulnerability and configuration scan data, and user provided reports.
  • Proactively conduct investigations, analysis, and evaluation of projects to determine cybersecurity risk and feasibility as required.
  • Administer, maintain, tune, and perform heath checks on cybersecurity products and services (such as : secure mail gateway, SIEM, IDS / IPS, EDR, vulnerability management, brand monitoring, threat intelligence, security rating, DDoS, web proxy, file integrity monitoring (FIM), data loss prevention (DLP), User Entity & Behavioral Analytics (UEBA), and other).
  • Provide and implement recommendations for new technical controls to help mitigate security vulnerabilities.
  • Responsible for leading the vulnerability management program functions including hosting weekly meetings with Stakeholders and the operations team, creating and tracking tickets for all vulnerabilities, holding stakeholder teams to meet SLA’s, and reporting to the Manager of Cybersecurity on a weekly basis.
  • Actively perform threat hunting activities in the environment to detect cyber threats in the network.
  • Coordinate and support purple, red, and blue team engagements.
  • Provide cybersecurity technical assistance when needed by system / application owners.
  • Support multiple day-to-day cybersecurity tasks and projects efforts.
  • Provide regular status updates to Management on projects and remediation efforts.
  • Solid understanding of cybersecurity policies and procedures, ability to draft, modify and create standard operating procedures (SOPs) for use of other team members.
  • Support organizational Security Awareness Training efforts (suggest training topics, coordinate phishing campaigns, enable awareness to end-users in support of incidents).
  • Support vulnerability assessments functions (such as : enterprise pen testing, application pen testing, static / dynamic testing, scorecard assessments).
  • Participate and support afterhours / on-call rotation requirements for cybersecurity incidents.
  • Responsible for developing, monitoring, and tracking cyber security metrics on a recurring basis, including creating Powerpoint slide decks for presentations.
  • Coordinate response and remediation efforts across various departments in a cooperative and beneficial manner.
  • Responsible for maintaining Incident Response documentation and auditing member contact information on at least a semi-annual basis or as needed.
  • Responsible for attending all vendor meetings and acts as the point of contact for our Cybersecurity vendors.
  • Demonstrate ownership and understanding of tasks when engaging with other team members.
  • Provide leadership, guidance and partnership to Analyst(s) and Senior Analyst(s).
  • Responsible for the onboarding and training of new analysts to the Cybersecurity Operations team.
  • Provide support to management team.
  • Qualifications

  • Bachelor’s degree in computer science, technology, or equivalent combination of education and relevant experience (required).
  • 6 years of relevant IT / Cybersecurity experience (required).
  • 5 years in security operations with hands-on experience with enterprise cybersecurity products, such as Rapid7, SentinelOne, Proofpoint, Office365, Microsoft Defender for Cloud, Microsoft Defender for Identity (required).
  • 5 years of SIEM (security information and event management) platform experience (required).
  • 4 years supporting adversary tactics and techniques based on MITRE attack framework (required).
  • Knowledge of cyber security standards and frameworks such as ISO 27001, NIST CSF, NIST-800-53, PCI DSS ASV (highly desired).
  • Hands-on experience with tools like PowerShell, Vulnerability Management suite, Wireshark, and NMAP (required).
  • Industry cybersecurity certification : CompTIA : Security or Pentest , CEH, CISSP, OCSP, SANS : GCIH or GSEC, CISSP, ISACA : CISA or CISM, Security , SSCP, or CCNA (required, or willing to attain within 3 months of start date).
  • Hands-on Cloud infrastructure (Azure / AWS / GCP) cybersecurity remediation experience (desirable).
  • Hands-on experience with next-gen endpoint detection / response (EDR), Enterprise Firewall, IPS, Log Management, Cisco, and Checkpoint experience (desirable).
  • URL Filtering (web proxy) and troubleshooting experience (desirable).
  • Solid understanding of a variety of OSINT techniques and digital forensics to aid in proactive Threat Hunting and crown jewel asset protection.
  • Assists Management with gathering metrics on a routine basis and actively aids in a continual reduction of risk and vulnerabilities resulting in an overall more secure environment quarter-over-quarter.
  • Proactively identifies areas within Frontier that require hardening and protection and deploys solutions with the respective supporting teams.
  • Active involvement within the cybersecurity community (Bsides, OWASP, ISSA, ISACA, or similar) and willing to submit to speak publicly at a conference at least annually.
  • Living in or willing to relocate within 3 months of start date to Colorado; to be on-site at Frontier Corporate Headquarters as needed.
  • Knowledge, Skills and Abilities

  • Ability to understand and communicate industry trends, maintain awareness of current vulnerabilities and security concerns, and understand their impact on the organization.
  • Ability to troubleshoot security / network / system-related issues and manage security components in operating environment.
  • Solid understanding of attack vectors, common intrusion techniques, brand intelligence, threat intelligence, application / host / network security hardening, enterprise risk management concepts, and MITRE Attack Framework principles.
  • Knowledge of enterprise risk assessment tools, technologies, and methodologies.
  • Broad and thorough knowledge of enterprise security systems and devices.
  • Knowledgeable in penetration testing, vulnerability assessments, and remediation.
  • Designing and implementing cybersecurity controls in an operating environment.
  • Able to make accurate work estimates and deliver projects within schedule constraints.
  • Proficiency in network traffic analysis and packet analysis.
  • Well-organized with the ability to coordinate and prioritize multiple tasks simultaneously with varying deadlines.
  • Demonstrate understanding and in-depth knowledge of security threats and applying actionable data to processes and procedures.
  • Demonstrate understanding and knowledge correlation analysis, along with an understanding of monitoring programs, such as Splunk and other SIEMs.
  • Understanding of the OSI 7-layer model.
  • Willing to work more than 40 hours and some weekends as needed.
  • Willing to support after-hours and weekend on-call rotation support.
  • Strong written and verbal communication skills.
  • Ability to remain organized and to elicit cooperation from a wide variety of sources including team members and other internal departments.
  • Ability to quickly learn new systems, devices, and methodologies.
  • Able to work independently and with a team of peers and other departments.
  • Proactively identifies and addresses various gaps and solutions within the boundaries of Cybersecurity Operations and deploys these solutions; creates roadmap on these efforts to align with CyberOps goals and provides periodic updates as needed.
  • Equipment Operated

    Laptop endpoint running Windows and a variety of cybersecurity applications, commercial and open-source tools.

    Work Environment

    Team is currently 2 Days a week in office, 3 Days Remote. This is subject to change at any time.

    Requires being on-call for after-hours and weekend support.

    Physical Effort

    Light physical effort required by handling objects up to 20 pounds occasionally and / or up to 10 pounds frequently.

    Supervision Received

    General Direction : The incumbent normally receives little instruction on day-to-day work and receives general instructions on new assignments.

    Positions Supervised

  • None
  • Salary Range

    110,114 - $146,157

    Please note : this posting has a closing date of 3 / 14 / 2025, midnight MT.

    Salary : $110,114 - $146,157

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Lead Analyst, Cybersecurity Operations?

    Sign up to receive alerts about other jobs on the Lead Analyst, Cybersecurity Operations career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $70,462 - $84,818
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Frontier Airlines

    Frontier Airlines
    Hired Organization Address Denver, CO Full Time
    Why Work for Frontier Airlines? At Frontier, we believe the skies should be for everyone. We deliver on this promise thr...
    Frontier Airlines
    Hired Organization Address Denver, CO Full Time
    What We Stand For Low Fares Done Right is our mission and we strive to bring it to life every day. Our ‘Done Right’ prom...
    Frontier Airlines
    Hired Organization Address Denver, CO Full Time
    Why Work for Frontier Airlines? At Frontier, we believe the skies should be for everyone. We deliver on this promise thr...
    Frontier Airlines
    Hired Organization Address Aurora, CO Full Time
    What We Stand For Low Fares Done Right is our mission and we strive to bring it to life every day. Our ‘Done Right’ prom...

    Not the job you're looking for? Here are some other Lead Analyst, Cybersecurity Operations jobs in the Denver, CO area that may be a better fit.

    Lead Analyst, Cybersecurity Operations

    Test Frontier Job Board, Denver, CO

    Analyst II - Cybersecurity Operations

    Test Frontier Job Board, Denver, CO

    AI Assistant is available now!

    Feel free to start your new journey!