Job Description:
Location: This position is remote within the US.
Overview of Role :
The Cybersecurity Analyst II will support day-to-day Cybersecurity operations, alert investigation, incident response, detection tuning, reporting, implementation support, and documentation with limited supervision. The role is hands-on and delivery-focused, and requires the analyst to independently triage ambiguous security events, coordinate with IT partners, recommend risk-based actions, and help mature repeatable security processes.
Requirements :
- Perform daily security operations by proactively monitoring the environment to detect, analyze, and help mitigate cyber threats.
- Review, investigate, and respond to real-time alerts across SIEM, EDR/XDR, email security, identity, network, cloud, and other security platforms.
- Support cybersecurity incident response by gathering evidence, documenting timelines, coordinating containment/mitigation activity, and communicating status clearly.
- Configure, maintain, monitor, and tune security tools to improve detection fidelity and reduce recurring false positives.
- Translate IT security strategy into tactical work items, runbooks, use cases, reporting, and control improvements.
- Work across infrastructure, endpoint, cloud, network, application, and business teams to implement practical, risk-based security controls.
- Create reporting and metrics that demonstrate security program health, operational trends, investigation outcomes, and opportunities for improvement.
- Develop or implement scripts, queries, dashboards, or open-source/third-party tools that improve detection, prevention, analysis, reporting, or workflow efficiency.
- Lead small security workstreams or discrete implementation efforts when needed, while escalating architectural or policy decisions appropriately.
Education / Experience :
- Bachelor's degree in information security, computer science, or equivalent experience preferred.
- Targeting 4 to 6 years of progressive IT/security experience, including hands-on security operations cyber defense, incident response.
Must have experience/skills :
- Strong hands-on EDR/XDR investigation experience, including endpoint timeline review, suspicious process analysis, containment coordination, and remediation validation.
- Strong hands-on SIEM experience, including log analysis, query writing, alert triage, correlation, use-case tuning, and quality improvement of detections.
- Experience administering or technically supporting at least one major security platform such as EDR/XDR, SIEM, secure email gateway, phishing simulation platform, vulnerability management tool, identity security tool, or cloud security monitoring platform.
- Experience with phishing analysis and email security workflows, including header review, URL/domain/file reputation analysis, user reporting, and response documentation.
- Working knowledge of Active Directory and Entra ID/Azure AD security, including users, groups, MFA, conditional access concepts, authentication anomalies, and identity-based investigations.
- Practical understanding of incident response phases, evidence handling, containment/eradication/recovery coordination, and post-incident documentation.
- Ability to investigate network anomalies and security events across on-premises and cloud environments.
- Ability to communicate technical findings to non-technical audiences with clear written summaries, recommendations, and decision-ready context.
- Working knowledge of security frameworks and concepts such as NIST, MITRE ATT&CK, least privilege, defense-in-depth, vulnerability management, and ITSM practices.
- Ability to operate independently under time pressure, manage multiple priorities, and escalate appropriately when risk or business impact changes.
Nice to have experience skills :
- PowerShell, Python, SPL, or other scripting/query language experience for automation, detection, and analysis.
- Experience creating dashboards or metrics in Power BI or similar reporting/visualization tools.
- Familiarity with Microsoft security tooling, Azure security monitoring, AWS/GCP security monitoring, or hybrid cloud security concepts.
- Experience building runbooks, detection logic, incident report templates, executive-ready summaries, or security operations process improvements.
- Experience with AI model integration for cybersecurity monitoring.
- Certifications such as Security+, CySA+, GCIH, GCIA, GCFA, or equivalent practical experience.
Pay Range: $50.00 - $57.00 per hour, depending upon experience.
Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.