Security Analyst

Insight Global
Irving, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Job location

Irving, United States of America

Tech stack

Artificial Intelligence
Amazon Web Services (AWS)
Azure
Cloud Computing
Cloud Computing Security
Computer Security
Information Security Management
Python
Microsoft Security Essentials
PCI Data Security Standards
Powershell
Azure
Phishing
Kusto Query Language
EndPointSecurity
Prompt Engineering
Multi-Cloud
Information Technology
Microsoft Sentinel
Oracle Cloud Infrastructure

Job description

Microsoft Defender Suite

  • Design and implement automated alert response playbooks in Defender; deploy automated containment for account compromise and identity-based threats via Entra ID Protection

  • Configure Defender for Cloud Apps, Defender for Cloud, and Defender for Identity across the environment

  • Tune detection rules and improve signal quality through KQL-based custom detection rules

Entra Identity Security & Phishing-Resistant MFA

  • Own deployment and enforcement of phishing-resistant MFA including passkey implementation strategy and rollout

  • Configure and maintain Conditional Access policies with documented logic, exceptions, and recertification schedules; manage Entra ID security posture including risk-based authentication and identity protection

Multi-Cloud Security Posture Management

  • Assess and document security configurations across Azure and AWS; maintain Oracle Cloud environment (legacy, maintenance-mode); produce baseline documents covering current state, gaps, and risk for each platform

  • Collaborate with IT to drive gap remediation; evaluate environments against industry frameworks

Security Operations

  • Participate in the alert response queue within published SLA windows

  • Maintain the team's alert response SOP library

AI-Augmented Security

  • Lead deployment and integration of Microsoft Security Copilot into team investigation and triage workflows

  • Research, evaluate, and implement emerging AI security tools with practical operational value; establish QA practices for AI-generated output and serve as the team's internal AI security subject matter expert

Documentation

  • Maintain documentation of security configurations, detection logic, and incident response procedures; translate findings into business risk language for leadership, Our Cybersecurity & Compliance team protects a multi-cloud enterprise environment spanning Microsoft Azure, AWS, and Oracle Cloud. This is a hands-on engineering and operations role - not a monitoring and reporting function. The right person enjoys building and running security solutions, leads incident response when it matters, and takes ownership of the platforms they manage. We are expanding Defender coverage, deploying phishing-resistant authentication, and implementing Microsoft Security Copilot, and this role leads all of it.

Requirements

Demonstrated hands-on experience with the Microsoft Defender suite - Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, and Defender for Cloud

  • Working experience with Microsoft Entra ID, Conditional Access policy design, and identity security configuration

  • Familiarity with phishing-resistant authentication - passkeys, FIDO2, or certificate-based authentication in an enterprise environment

  • Proficiency in KQL for alert logic and detection rule development; PowerShell or Python a plus

  • Security operations experience - alert triage, incident response, SLA-based response discipline

  • Demonstrated ability to leverage AI security tools as operational accelerators; Microsoft Security Copilot familiarity preferred

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology; equivalent experience considered

Preferred

  • Microsoft Sentinel and Defender portal integration; Defender Cases or comparable case management experience; hands-on Microsoft Security Copilot experience including prompt engineering for security investigations

  • Experience with cloud security across Microsoft Azure and AWS; Oracle Cloud familiarity a plus

  • CrowdStrike Falcon familiarity; post-breach or PCI DSS compliance environment experience

  • Certifications: SC-200, SSCP, CCSP, or comparable

What We're Looking For

Technical depth in Defender and Entra identity is the baseline. What differentiates candidates is the combination: deploy and tune automation, hold an alert queue, lead AI implementation, and deliver without close management. The right candidate wants to own their domain.

  • Initiative and reliability - closes gaps without prompting; takes ownership of a problem and drives it to resolution independently; brings new knowledge back as practical application, not just awareness; communicates blockers before deadlines, not after

  • Breadth with depth - strong in Defender and Entra identity with real capability across cloud security and security operations

  • AI-forward mindset - evaluates tools critically, implements them practically, treats AI as a force multiplier

  • Communication - translates technical findings for both technical peers and non-technical leadership, * Demonstrated hands-on experience with the Microsoft Defender suite - Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, and Defender for Cloud

  • Working experience with Microsoft Entra ID, Conditional Access policy design, and identity security configuration

  • Familiarity with phishing-resistant authentication - passkeys, FIDO2, or certificate-based authentication in an enterprise environment

  • Proficiency in KQL for alert logic and detection rule development; PowerShell or Python a plus

  • Security operations experience - alert triage, incident response, SLA-based response discipline

  • Demonstrated ability to leverage AI security tools as operational accelerators; Microsoft Security Copilot familiarity preferred

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology; equivalent experience considered - Microsoft Sentinel and Defender portal integration; Defender Cases or comparable case management experience; hands-on Microsoft Security Copilot experience including prompt engineering for security investigations

  • Experience with cloud security across Microsoft Azure and AWS; Oracle Cloud familiarity a plus

  • CrowdStrike Falcon familiarity; post-breach or PCI DSS compliance environment experience

Certifications: SC-200, SSCP, CCSP, or comparable

Apply for this position