
Security Operations Analyst II
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Florida, +3 more states.
• Examine security alerts and incidents across endpoints, identities, email, cloud services, and network infrastructures.
• Utilize Microsoft Defender XDR, Microsoft Sentinel, and KQL to analyze suspicious activities, correlate telemetry, and identify indicators of compromise and attacker behaviors.
• Manage routine and moderately complex investigations, assessing scope, severity, and business impact.
• Review escalated security cases with the managed security service provider and senior analysts.
• Assist in incident response activities, including identification, investigation, containment, and recovery.
• Gather and analyze evidence to create investigative timelines.
• Investigate phishing incidents, suspicious email activities, credential compromises, and cloud or identity-related security occurrences.
• Contribute to the proactive threat-hunting capability.
• Suggest enhancements to detection coverage, hunting queries, playbooks, and investigation procedures.
• Communicate technical findings to both technical and non-technical stakeholders and participate in preparing executive-ready security briefings.
• Engage in a rotational on-call schedule for significant or urgent security incidents.
• Practical professional experience in a Security Operations Center, cybersecurity operations, or a closely related technical security environment.
• Hands-on experience with Microsoft Defender and/or Microsoft Sentinel.
• Proficient in using KQL to query security data, investigate suspicious activities, or support threat hunting efforts.
• Strong understanding of SIEM and EDR/XDR technologies and their investigative telemetry.
• Proven experience in investigating security alerts and incidents across endpoints, identity, email, and cloud environments.
• Experience in investigating phishing attempts, suspicious email activity, and potential credential compromises.
• Ability to work independently in complex or ambiguous situations and determine when escalation is necessary.
• Knowledge of incident-response processes, security investigation methodologies, and attacker tactics and techniques, including familiarity with MITRE ATT&CK.
• Excellent communication skills for conveying technical findings to diverse audiences.
• Curiosity, a commitment to continuous learning, and an interest in emerging cybersecurity threats, technologies, and investigative techniques.
• Eligibility for an annual incentive bonus.
• 12% employer contribution to a 401(k) or pension plan.
• Comprehensive medical benefits package.
• Health coverage.
• Generous time off.
• Competitive retirement plans.
• Flexible work options.
• Wellbeing and development programs.
OSIbeyond
It4us Cyber Security
Invicti
Get handpicked remote jobs straight to your inbox weekly.