Назад
Company hidden
3 дня назад

Security Operations Analyst II (Microsoft Defender/Sentinel)

83 000 - 110 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Analyst II (Microsoft Defender/Sentinel): Investigating and responding to security events across endpoints, identities, email, cloud services, and network infrastructure with an accent on Microsoft Defender XDR, Microsoft Sentinel, KQL, and threat hunting. Focus on independently handling complex investigations, building investigative timelines, improving detection coverage and playbooks, and escalating incidents appropriately.

Location: Remote - Virginia, United States

Salary: $83,000–$110,000 per year

Company

hirify.global is a global organization focused on investment excellence, professional growth, ethical standards, and better financial markets.

What you will do

  • Investigate security alerts and events across endpoints, identities, email, cloud services, and network infrastructure.
  • Use Microsoft Defender XDR, Microsoft Sentinel, and KQL to correlate telemetry, identify indicators of compromise, and analyze attacker behavior.
  • Own routine and moderately complex investigations, assessing scope, severity, and business impact while escalating when needed.
  • Support incident response across identification, investigation, containment, and recovery, including evidence collection and timeline analysis.
  • Investigate phishing, suspicious email activity, credential compromise, and cloud or identity-related security events.
  • Improve threat hunting, detection coverage, hunting queries, playbooks, and investigation procedures, and communicate findings to technical and non-technical stakeholders.

Requirements

  • Professional experience in a Security Operations Center, cybersecurity operations, or a related technical security environment.
  • Hands-on experience with Microsoft Defender and/or Microsoft Sentinel and practical use of KQL for investigation or threat hunting.
  • Strong understanding of SIEM and EDR/XDR technologies and their investigation telemetry.
  • Experience investigating alerts and incidents involving endpoints, identity, email, and cloud environments, including phishing and potential credential compromise.
  • Understanding of incident-response processes, investigation methodologies, attacker tactics and techniques, and MITRE ATT&CK.
  • Ability to work independently through complex or ambiguous situations, communicate findings clearly, and participate in a rotational on-call schedule.

Culture & Benefits

  • In-house Security Operations environment with meaningful ownership of investigations.
  • Exposure to Microsoft security technologies, threat intelligence, data protection, and brand protection.
  • Opportunity to help mature proactive threat hunting, detections, and investigative practices.
  • Annual incentive bonus eligibility and a 12% employer contribution to a 401(k) or pension plan.
  • Health coverage, generous time off, retirement plans, flexible work options, and wellbeing and development programs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →