> Markdown version of [/jobs/ext/888146-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/888146-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** Ennoble Care - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $115,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, CompTIA Security+, Cyber Security, Data Security, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Domain Name System (DNS), Message Transfer Agent, Intrusion Detection and Prevention, Log Analysis, Microsoft Security Essentials, Microsoft Office, Phishing, Kusto Query Language, Microsoft InTune, Sender Policy Framework (SPF), Cybercrime, SentinelOne Expertise - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1d6f740eb113f959 ## About the Role Do you have experience in Threat hunting activities?, * 3+ years in a hands-on security operations, security engineering, or security analyst role * Deep working knowledge of Microsoft 365 security stack: Defender for Office 365, Entra ID, Conditional Access, Intune * Experience investigating and remediating email compromise, phishing, and identity-based attacks * Hands-on experience with email authentication (SPF, DKIM, DMARC) and Exchange Online Protection / Defender for Office 365 * Proficiency with KQL for threat hunting and log analysis * Understanding of HIPAA security requirements and how they translate to technical controls * Ability to work independently and prioritize in a fast-moving environment with minimal bureaucracy, * Healthcare industry experience * Experience with Microsoft Purview (Information Protection, DLP, eDiscovery) * Familiarity with SentinelOne or similar EDR platforms * Experience supporting M&A security integration or due diligence * Comfort with AI-assisted security workflows * Certifications: Security+, CISSP, SC-200, SC-300, or SC-400 ## Description We are hiring our first dedicated cybersecurity professional. You will own the day-to-day security operations for a HIPAA-regulated, cloud-only environment. This is a hands-on role: you will harden our Microsoft security stack, run incident response, hunt threats, and build the security program alongside our external Microsoft security partner. This is not a policy-writing job. You will spend most of your time in Defender, Entra ID, Purview, and Exchange Online. You will be the person who investigates alerts, tunes detections, closes gaps in Conditional Access, and ensures our compliance posture holds up under scrutiny. You will report to the CIO and work closely with our CTO and our Engineering AI Transformation Manager who serves as a cybersecurity technical SME with FedRamp/NIST 800-171/Soc2/ISO 27001 cybersecurity R&D background., * Monitor and respond to identity-based threats (token theft, MFA bypass, impossible travel) * Drive adoption of phishing-resistant MFA (FIDO2/passkeys, Windows Hello for Business, certificate-based auth) and deploy token-theft protections - token protection, Continuous Access Evaluation, and sign-in risk-based Conditional Access * Ability to conduct quarterly tabletop exercises for anticipation of threats and corrective action plans. * Conduct regular entitlement reviews and clean up stale access Email & Messaging Security * Harden Exchange Online Protection: Safe Links, Safe Attachments, anti-phishing policies, quarantine management * Own email authentication: configure and maintain SPF, DKIM, and DMARC records in DNS, monitor DMARC aggregate reports for spoofing and broken senders, and drive the domain to enforcement (p=reject) * Strengthen mail transport and anti-spoofing posture (MTA-STS, TLS-RPT, ARC), and enable BIMI once DMARC is at enforcement * Investigate and respond to BEC, phishing, and account compromise incidents * Own the user phishing-reporting workflow (Report Phishing button, submissions triage) and rapid email remediation - ZAP and tenant-wide message purge - with a target time-to-contain for reported messages * Design and execute simulated phishing campaigns to measure and improve user resilience * Run the security awareness and human-risk program (Attack Simulation Training, onboarding and recurring training, just-in-time coaching, targeted remediation for repeat clickers) and report on click-rate and report-rate trends over time Threat Detection & Response * Write and tune KQL queries in Microsoft Defender Advanced Hunting * Triage Defender alerts, investigate incidents end-to-end, and document findings * Coordinate with our MDR provider on endpoint detections * Own the incident response lifecycle from detection through remediation and lessons learned Data Protection & Compliance * Implement Microsoft Purview information protection labels, DLP policies, and retention rules * Collect and maintain evidence for HIPAA compliance assessments and SOC 2 readiness * Support cyber insurance renewals with accurate risk documentation Security Posture & Partnership * Work with our external Microsoft security partner to execute posture improvement roadmaps * Track and improve Microsoft Secure Score across identity, devices, apps, and data * Own the security workstream during M&A integrations (approximately one acquisition per quarter) * Evaluate and recommend security tooling additions as the program matures ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)