3 дня назад
Security Operations Analyst II (Microsoft Defender/Sentinel)
83 000 - 110 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Operations Analyst II (Microsoft Defender/Sentinel): Investigating and responding to security events across endpoints, identities, email, cloud services, and network infrastructure with an accent on Microsoft Defender XDR, Microsoft Sentinel, KQL, and threat hunting. Focus on independently handling complex investigations, building investigative timelines, improving detection coverage and playbooks, and escalating incidents appropriately.
Location: Remote - Virginia, United States
Salary: $83,000–$110,000 per year
Company
is a global organization focused on investment excellence, professional growth, ethical standards, and better financial markets.
What you will do
- Investigate security alerts and events across endpoints, identities, email, cloud services, and network infrastructure.
- Use Microsoft Defender XDR, Microsoft Sentinel, and KQL to correlate telemetry, identify indicators of compromise, and analyze attacker behavior.
- Own routine and moderately complex investigations, assessing scope, severity, and business impact while escalating when needed.
- Support incident response across identification, investigation, containment, and recovery, including evidence collection and timeline analysis.
- Investigate phishing, suspicious email activity, credential compromise, and cloud or identity-related security events.
- Improve threat hunting, detection coverage, hunting queries, playbooks, and investigation procedures, and communicate findings to technical and non-technical stakeholders.
Requirements
- Professional experience in a Security Operations Center, cybersecurity operations, or a related technical security environment.
- Hands-on experience with Microsoft Defender and/or Microsoft Sentinel and practical use of KQL for investigation or threat hunting.
- Strong understanding of SIEM and EDR/XDR technologies and their investigation telemetry.
- Experience investigating alerts and incidents involving endpoints, identity, email, and cloud environments, including phishing and potential credential compromise.
- Understanding of incident-response processes, investigation methodologies, attacker tactics and techniques, and MITRE ATT&CK.
- Ability to work independently through complex or ambiguous situations, communicate findings clearly, and participate in a rotational on-call schedule.
Culture & Benefits
- In-house Security Operations environment with meaningful ownership of investigations.
- Exposure to Microsoft security technologies, threat intelligence, data protection, and brand protection.
- Opportunity to help mature proactive threat hunting, detections, and investigative practices.
- Annual incentive bonus eligibility and a 12% employer contribution to a 401(k) or pension plan.
- Health coverage, generous time off, retirement plans, flexible work options, and wellbeing and development programs.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
SOC Analyst (Cybersecurity)
10 дней назад
Threat Analyst 2 (Cybersecurity)
10 дней назад
Analyst, Security Operations (Cybersecurity)
125 000 - 145 000$
9 дней назад
Senior Detection & Response Engineer (Microsoft Security)
142 900 - 207 200$
7 дней назад
Senior Cybersecurity Analyst (Cyber Defense Operations)
7 дней назад
Security Operations Engineer (Cybersecurity)
91 200 - 118 600$