2

Remote Microsoft Security Operations Analyst Jobs in Texas

Manager, Security Operations (Sentinel)

Dallas, TX ยท On-site +1

$150K - $178K/yr

Avanade's Security Practice supports clients in protecting, detecting, and responding to cyber threats using Microsoft's security ecosystem. This role sits within Security Operations and focuses on ...

Manager, Security Operations (Sentinel)

Austin, TX ยท On-site +1

$150K - $178K/yr

Avanade's Security Practice supports clients in protecting, detecting, and responding to cyber threats using Microsoft's security ecosystem. This role sits within Security Operations and focuses on ...

Security Operations Manager

Sugar Land, TX ยท Remote

$130K - $153K/hr

Remote Department: Information Technology Compensation: $130,000-$153,000 annually Position Type ... Strong analytical, investigative, organizational, and problem-solving skills * Ability to ...

Security Operations Manager

Sugar Land, TX ยท Remote

$130K - $153K/hr

Remote Department: Information Technology Compensation: $130,000-$153,000 annually Position Type ... Strong analytical, investigative, organizational, and problem-solving skills * Ability to ...

IAM Operations Analyst

Austin, TX ยท Remote

$25 - $27/hr

The Information Security Analyst will support the Information Security Identity and Access ... remote position. Application Deadline This position is anticipated to close on Aug 21, 2026. About ...

Proficient with Microsoft Office Tools (Excel, PowerPoint, Word, and Outlook) Preferred * Previous ... REMOTE You are encouraged to learn and share ideas when you join the OneSource Virtual team. We ...

Revenue Operations Analyst

Houston, TX ยท Remote

$60K - $70K/yr

Operations Analyst We are looking for a precision-oriented Operations Analyst to serve as the ... This position is 100% remote. Essential Duties & Responsibilities * Master our backend architecture ...

next page

Showing results 1-20

Remote Microsoft Security Operations Analyst information

What is a Remote Microsoft Security Operations Analyst?

A Remote Microsoft Security Operations Analyst is a cybersecurity professional who monitors, investigates, and responds to security threats and incidents within Microsoft environments, such as Microsoft 365, Azure, and Windows systems, while working remotely. They use various security tools and platforms, like Microsoft Sentinel and Defender, to detect suspicious activity, analyze alerts, and implement security measures. Their primary goal is to protect organizational data and systems from cyber threats by identifying vulnerabilities and addressing them promptly, all while collaborating with other IT and security teams from a remote location.

How does a Remote Microsoft Security Operations Analyst typically collaborate with other IT and security team members?

As a Remote Microsoft Security Operations Analyst, you will frequently work alongside IT administrators, incident response teams, and other security professionals to monitor, investigate, and respond to security threats. Collaboration often takes place through virtual meetings, shared dashboards, and ticketing systems to ensure timely communication and efficient incident handling. You may also participate in cross-functional projects, sharing insights from security monitoring tools like Microsoft Sentinel or Defender, and help develop or refine company-wide security policies and procedures. Effective communication and documentation skills are key to ensuring alignment and maintaining a strong security posture while working remotely.

What are the key skills and qualifications needed to thrive as a Remote Microsoft Security Operations Analyst, and why are they important?

To thrive as a Remote Microsoft Security Operations Analyst, you need strong knowledge of cybersecurity principles, threat detection, incident response, and familiarity with Microsoft security solutions, often supported by a relevant degree or certifications like Microsoft Certified: Security Operations Analyst Associate. Proficiency with tools such as Microsoft Sentinel, Defender for Endpoint, and Security Information and Event Management (SIEM) systems is essential. Excellent problem-solving, analytical thinking, and clear communication are crucial soft skills for investigating threats and collaborating with distributed teams. These skills ensure effective protection of organizational assets, quick response to security incidents, and seamless remote teamwork in a dynamic security environment.

What is the difference between Remote Microsoft Security Operations Analyst vs Remote Cybersecurity Analyst?

AspectRemote Microsoft Security Operations AnalystRemote Cybersecurity Analyst
CertificationsMicrosoft Security certifications, CompTIA Security+CompTIA Security+, CISSP, CEH
Work EnvironmentPrimarily within Microsoft security tools and cloud platformsVaried environments, including multiple security tools and platforms
Industry UsageCommon in organizations using Microsoft products and cloud servicesWidespread across industries with diverse security needs
Job FocusMonitoring Microsoft security solutions, incident response, threat detectionBroader security analysis, vulnerability assessment, incident handling

The Remote Microsoft Security Operations Analyst specializes in managing Microsoft security tools and cloud environments, focusing on threat detection and incident response within Microsoft ecosystems. In contrast, the Remote Cybersecurity Analyst has a broader scope, working across various security platforms and industries. Both roles require security certifications but differ in their technical focus and work environment.

Can you work remotely as a Microsoft Security Operations Analyst?

Yes, many Microsoft Security Operations Analyst roles are available as remote positions, allowing analysts to monitor security alerts, investigate threats, and manage security tools from home. Employers often require familiarity with cloud security platforms like Microsoft Defender and remote collaboration tools. Remote work arrangements depend on the company's policies and the specific role's requirements.

What are the most commonly searched types of Microsoft Security Operations Analyst jobs in Texas?

The most popular types of Microsoft Security Operations Analyst jobs in Texas are:

What are popular job titles related to Remote Microsoft Security Operations Analyst jobs in Texas?

For Remote Microsoft Security Operations Analyst jobs in Texas, the most frequently searched job titles are:

What job categories do people searching Remote Microsoft Security Operations Analyst jobs in Texas look for?

The top searched job categories for Remote Microsoft Security Operations Analyst jobs in Texas are:

What cities in Texas are hiring for Remote Microsoft Security Operations Analyst jobs?

Cities in Texas with the most Remote Microsoft Security Operations Analyst job openings:

Senior Microsoft Security Engineer

3B Staffing LLC

Murphy, TX โ€ข Remote

$109K - $150K/yr

Full-time

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Senior Microsoft Security Engineer

Sentinel & Defender XDR

Duration : 6 + months

Location : Remote

About the Role

Senior Microsoft Security Engineer who knows Sentinel inside and out - and can carry that expertise across into Defender XDR. This is not a generalist role. The ideal candidate has deep, hands-on Sentinel experience, understands how Defender XDR maps to it functionally, and has ideally led or been a key contributor to a Sentinel-to-XDR migration in a production environment.

You will be embedded with a client SOC team, owning detection engineering, platform configuration, and the technical work required to bridge two platforms without dropping coverage or continuity. If you have lived through a migration and know where the gaps are, this role was written for you.

Key Responsibilities

Microsoft Sentinel (Primary Platform)

  • Design, configure, and optimize Microsoft Sentinel environments including data connectors, analytics rules, and workbooks
  • Build and maintain detection logic using UEBA, ML-based anomaly detection, and threat intelligence integrations
  • Develop KQL queries and hunting workbooks for proactive threat identification
  • Create and manage SOAR playbooks via Azure Logic Apps to automate SOC response workflows
  • Continuously tune detection rules and reduce false positive rates in partnership with the SOC team
  • Document architecture decisions, runbooks, and operational procedures

Microsoft Defender XDR (Secondary Platform)

  • Map existing Sentinel analytics rules, KQL logic, and detection coverage to Defender XDR equivalents
  • Configure and manage Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps within a unified XDR framework
  • Define and implement custom detection rules, incidents, and automated response actions within Defender XDR
  • Assess capability gaps between the two platforms and develop mitigation or transition plans
  • Leverage AI-native Defender XDR capabilities including automatic attack disruption and AI-assisted investigation

Migration & Cross-Platform Work

  • Lead or support Sentinel-to-XDR migration workstreams including data migration, rule translation, and platform configuration
  • Identify functional equivalencies and gaps between platforms and communicate tradeoffs clearly to SOC leadership
  • Integrate both platforms with SIEM, SOAR, and CTI tooling as needed
  • Support Copilot for Security and AI-powered SOC automation use cases across both platforms

Required Qualifications

  • 5+ years of hands-on experience with Microsoft Sentinel in an enterprise SOC environment - this is non-negotiable
  • Strong proficiency in KQL and the ability to translate detection logic across platforms
  • Hands-on experience or equivalent training with Microsoft Defender for XDR, including deep familiarity with its sub-components: Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps (Note: Microsoft Defender XDR was released March 2026 - equivalent platform knowledge and migration readiness will be considered in place of tenure)
  • Demonstrated experience with or direct involvement in a Sentinel-to-Defender XDR migration, or the ability to map Sentinel functionality to Defender XDR equivalents based on deep platform knowledge of both
  • Solid understanding of XDR concepts, cross-domain correlation, and automated incident response
  • Deep familiarity with the MITRE ATT&CK framework and its application to detection engineering
  • Experience with Azure Logic Apps, Power Automate, or similar automation platforms
  • Background in threat hunting, incident response, and SOC operations

Preferred Qualifications

  • Microsoft Certified: Security Operations Analyst Associate (SC-200) - strongly preferred
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) - a plus
  • Both certifications held simultaneously - this will stand out
  • Hands-on experience with Copilot for Security and AI-assisted investigation features in Defender XDR
  • Prior involvement in large-scale SIEM or XDR platform migrations
  • Background in CTI integration and tooling
  • Experience supporting global SOC teams across multiple regions
  • Familiarity with SOAR platforms, CRIBL, or similar tools in the SOC ecosystem
  • Exposure to digital forensics or agentic AI workflows in a security operations context