Security Analyst
Role details
Job location
Tech stack
Job description
Microsoft Defender Suite
-
Design and implement automated alert response playbooks in Defender; deploy automated containment for account compromise and identity-based threats via Entra ID Protection
-
Configure Defender for Cloud Apps, Defender for Cloud, and Defender for Identity across the environment
-
Tune detection rules and improve signal quality through KQL-based custom detection rules
Entra Identity Security & Phishing-Resistant MFA
-
Own deployment and enforcement of phishing-resistant MFA including passkey implementation strategy and rollout
-
Configure and maintain Conditional Access policies with documented logic, exceptions, and recertification schedules; manage Entra ID security posture including risk-based authentication and identity protection
Multi-Cloud Security Posture Management
-
Assess and document security configurations across Azure and AWS; maintain Oracle Cloud environment (legacy, maintenance-mode); produce baseline documents covering current state, gaps, and risk for each platform
-
Collaborate with IT to drive gap remediation; evaluate environments against industry frameworks
Security Operations
-
Participate in the alert response queue within published SLA windows
-
Maintain the team's alert response SOP library
AI-Augmented Security
-
Lead deployment and integration of Microsoft Security Copilot into team investigation and triage workflows
-
Research, evaluate, and implement emerging AI security tools with practical operational value; establish QA practices for AI-generated output and serve as the team's internal AI security subject matter expert
Documentation
- Maintain documentation of security configurations, detection logic, and incident response procedures; translate findings into business risk language for leadership, Our Cybersecurity & Compliance team protects a multi-cloud enterprise environment spanning Microsoft Azure, AWS, and Oracle Cloud. This is a hands-on engineering and operations role - not a monitoring and reporting function. The right person enjoys building and running security solutions, leads incident response when it matters, and takes ownership of the platforms they manage. We are expanding Defender coverage, deploying phishing-resistant authentication, and implementing Microsoft Security Copilot, and this role leads all of it.
Requirements
Demonstrated hands-on experience with the Microsoft Defender suite - Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, and Defender for Cloud
-
Working experience with Microsoft Entra ID, Conditional Access policy design, and identity security configuration
-
Familiarity with phishing-resistant authentication - passkeys, FIDO2, or certificate-based authentication in an enterprise environment
-
Proficiency in KQL for alert logic and detection rule development; PowerShell or Python a plus
-
Security operations experience - alert triage, incident response, SLA-based response discipline
-
Demonstrated ability to leverage AI security tools as operational accelerators; Microsoft Security Copilot familiarity preferred
-
Bachelor's degree in Cybersecurity, Computer Science, or Information Technology; equivalent experience considered
Preferred
-
Microsoft Sentinel and Defender portal integration; Defender Cases or comparable case management experience; hands-on Microsoft Security Copilot experience including prompt engineering for security investigations
-
Experience with cloud security across Microsoft Azure and AWS; Oracle Cloud familiarity a plus
-
CrowdStrike Falcon familiarity; post-breach or PCI DSS compliance environment experience
-
Certifications: SC-200, SSCP, CCSP, or comparable
What We're Looking For
Technical depth in Defender and Entra identity is the baseline. What differentiates candidates is the combination: deploy and tune automation, hold an alert queue, lead AI implementation, and deliver without close management. The right candidate wants to own their domain.
-
Initiative and reliability - closes gaps without prompting; takes ownership of a problem and drives it to resolution independently; brings new knowledge back as practical application, not just awareness; communicates blockers before deadlines, not after
-
Breadth with depth - strong in Defender and Entra identity with real capability across cloud security and security operations
-
AI-forward mindset - evaluates tools critically, implements them practically, treats AI as a force multiplier
-
Communication - translates technical findings for both technical peers and non-technical leadership, * Demonstrated hands-on experience with the Microsoft Defender suite - Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, and Defender for Cloud
-
Working experience with Microsoft Entra ID, Conditional Access policy design, and identity security configuration
-
Familiarity with phishing-resistant authentication - passkeys, FIDO2, or certificate-based authentication in an enterprise environment
-
Proficiency in KQL for alert logic and detection rule development; PowerShell or Python a plus
-
Security operations experience - alert triage, incident response, SLA-based response discipline
-
Demonstrated ability to leverage AI security tools as operational accelerators; Microsoft Security Copilot familiarity preferred
-
Bachelor's degree in Cybersecurity, Computer Science, or Information Technology; equivalent experience considered - Microsoft Sentinel and Defender portal integration; Defender Cases or comparable case management experience; hands-on Microsoft Security Copilot experience including prompt engineering for security investigations
-
Experience with cloud security across Microsoft Azure and AWS; Oracle Cloud familiarity a plus
-
CrowdStrike Falcon familiarity; post-breach or PCI DSS compliance environment experience
Certifications: SC-200, SSCP, CCSP, or comparable