> Markdown version of [/jobs/ext/1949032-cybersecurity-analyst-ii](https://www.wearedevelopers.com/jobs/ext/1949032-cybersecurity-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst II - **Company:** WIDENET CONSULTING, LLC - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Salary:** $104,000.0 - $118,560.0 - **Contract:** Temporary to permanent - **Skills:** Active Directory, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Data Visualization, Database Queries, Python (Programming Language), Log Analysis, Microsoft Security Essentials, Open Source Technology, Windows PowerShell, Power BI, Azure Active Directory, Phishing, Security Information and Event Management, Software Vulnerability Management, Scripting, Google Cloud, Mitre Att&ck, HybridCloud, Information Technology, Cybercrime, Cyber Warfare - **Published:** August 6, 2026 - **Apply:** https://widenet-consulting.com/openings/7000/#apply-now ## About the Role Bachelor's degree in information security, computer science, or equivalent experience preferred. - Targeting 4 to 6 years of progressive IT/security experience, including hands-on security operations cyber defense, incident response. Must have experience/skills: - Strong hands-on EDR/XDR investigation experience, including endpoint timeline review, suspicious process analysis, containment coordination, and remediation validation. - Strong hands-on SIEM experience, including log analysis, query writing, alert triage, correlation, use-case tuning, and quality improvement of detections. - Experience administering or technically supporting at least one major security platform such as EDR/XDR, SIEM, secure email gateway, phishing simulation platform, vulnerability management tool, identity security tool, or cloud security monitoring platform. - Experience with phishing analysis and email security workflows, including header review, URL/domain/file reputation analysis, user reporting, and response documentation. - Working knowledge of Active Directory and Entra ID/Azure AD security, including users, groups, MFA, conditional access concepts, authentication anomalies, and identity-based investigations. - Practical understanding of incident response phases, evidence handling, containment/eradication/recovery coordination, and post-incident documentation. - Ability to investigate network anomalies and security events across on-premises and cloud environments. - Ability to communicate technical findings to non-technical audiences with clear written summaries, recommendations, and decision-ready context. - Working knowledge of security frameworks and concepts such as NIST, MITRE ATT&CK, least privilege, defense-in-depth, vulnerability management, and ITSM practices. - Ability to operate independently under time pressure, manage multiple priorities, and escalate appropriately when risk or business impact changes. Nice to have experience skills: - PowerShell, Python, SPL, or other scripting/query language experience for automation, detection, and analysis. - Experience creating dashboards or metrics in Power BI or similar reporting/visualization tools. - Familiarity with Microsoft security tooling, Azure security monitoring, AWS/GCP security monitoring, or hybrid cloud security concepts. - Experience building runbooks, detection logic, incident report templates, executive-ready summaries, or security operations process improvements. - Experience with AI model integration for cybersecurity monitoring. - Certifications such as Security+, CySA+, GCIH, GCIA, GCFA, or equivalent practical experience. ## Description The Cybersecurity Analyst II will support day-to-day Cybersecurity operations, alert investigation, incident response, detection tuning, reporting, implementation support, and documentation with limited supervision. The role is hands-on and delivery-focused, and requires the analyst to independently triage ambiguous security events, coordinate with IT partners, recommend risk-based actions, and help mature repeatable security processes. Requirements: - Perform daily security operations by proactively monitoring the environment to detect, analyze, and help mitigate cyber threats. - Review, investigate, and respond to real-time alerts across SIEM, EDR/XDR, email security, identity, network, cloud, and other security platforms. - Support cybersecurity incident response by gathering evidence, documenting timelines, coordinating containment/mitigation activity, and communicating status clearly. - Configure, maintain, monitor, and tune security tools to improve detection fidelity and reduce recurring false positives. - Translate IT security strategy into tactical work items, runbooks, use cases, reporting, and control improvements. - Work across infrastructure, endpoint, cloud, network, application, and business teams to implement practical, risk-based security controls. - Create reporting and metrics that demonstrate security program health, operational trends, investigation outcomes, and opportunities for improvement. - Develop or implement scripts, queries, dashboards, or open-source/third-party tools that improve detection, prevention, analysis, reporting, or workflow efficiency. - Lead small security workstreams or discrete implementation efforts when needed, while escalating architectural or policy decisions appropriately. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)