Cybersecurity Analyst II

WIDENET CONSULTING, LLC
Seattle, WA, United States
5 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$104,000.0 - $118,560.0
Working hours
Regular working hours

Tech stack

Active Directory Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Data Visualization Database Queries Python (Programming Language) Log Analysis Microsoft Security Essentials Open Source Technology
+13 more
Windows PowerShell Power BI Azure Active Directory Phishing Security Information and Event Management Software Vulnerability Management Scripting Google Cloud Mitre Att&ck HybridCloud Information Technology Cybercrime Cyber Warfare

Job description

The Cybersecurity Analyst II will support day-to-day Cybersecurity operations, alert investigation, incident response, detection tuning, reporting, implementation support, and documentation with limited supervision. The role is hands-on and delivery-focused, and requires the analyst to independently triage ambiguous security events, coordinate with IT partners, recommend risk-based actions, and help mature repeatable security processes.

Requirements:

  • Perform daily security operations by proactively monitoring the environment to detect, analyze, and help mitigate cyber threats.
  • Review, investigate, and respond to real-time alerts across SIEM, EDR/XDR, email security, identity, network, cloud, and other security platforms.
  • Support cybersecurity incident response by gathering evidence, documenting timelines, coordinating containment/mitigation activity, and communicating status clearly.
  • Configure, maintain, monitor, and tune security tools to improve detection fidelity and reduce recurring false positives.
  • Translate IT security strategy into tactical work items, runbooks, use cases, reporting, and control improvements.
  • Work across infrastructure, endpoint, cloud, network, application, and business teams to implement practical, risk-based security controls.
  • Create reporting and metrics that demonstrate security program health, operational trends, investigation outcomes, and opportunities for improvement.
  • Develop or implement scripts, queries, dashboards, or open-source/third-party tools that improve detection, prevention, analysis, reporting, or workflow efficiency.
  • Lead small security workstreams or discrete implementation efforts when needed, while escalating architectural or policy decisions appropriately.

Requirements

Bachelor’s degree in information security, computer science, or equivalent experience preferred.

  • Targeting 4 to 6 years of progressive IT/security experience, including hands-on security operations cyber defense, incident response.

Must have experience/skills:

  • Strong hands-on EDR/XDR investigation experience, including endpoint timeline review, suspicious process analysis, containment coordination, and remediation validation.
  • Strong hands-on SIEM experience, including log analysis, query writing, alert triage, correlation, use-case tuning, and quality improvement of detections.
  • Experience administering or technically supporting at least one major security platform such as EDR/XDR, SIEM, secure email gateway, phishing simulation platform, vulnerability management tool, identity security tool, or cloud security monitoring platform.
  • Experience with phishing analysis and email security workflows, including header review, URL/domain/file reputation analysis, user reporting, and response documentation.
  • Working knowledge of Active Directory and Entra ID/Azure AD security, including users, groups, MFA, conditional access concepts, authentication anomalies, and identity-based investigations.
  • Practical understanding of incident response phases, evidence handling, containment/eradication/recovery coordination, and post-incident documentation.
  • Ability to investigate network anomalies and security events across on-premises and cloud environments.
  • Ability to communicate technical findings to non-technical audiences with clear written summaries, recommendations, and decision-ready context.
  • Working knowledge of security frameworks and concepts such as NIST, MITRE ATT&CK, least privilege, defense-in-depth, vulnerability management, and ITSM practices.
  • Ability to operate independently under time pressure, manage multiple priorities, and escalate appropriately when risk or business impact changes.

Nice to have experience skills:

  • PowerShell, Python, SPL, or other scripting/query language experience for automation, detection, and analysis.
  • Experience creating dashboards or metrics in Power BI or similar reporting/visualization tools.
  • Familiarity with Microsoft security tooling, Azure security monitoring, AWS/GCP security monitoring, or hybrid cloud security concepts.
  • Experience building runbooks, detection logic, incident report templates, executive-ready summaries, or security operations process improvements.
  • Experience with AI model integration for cybersecurity monitoring.
  • Certifications such as Security+, CySA+, GCIH, GCIA, GCFA, or equivalent practical experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on widenet-consulting.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all