Summary
Hansell Tierney is a premier staffing and recruiting company in the Pacific Northwest. They are seeking a Cybersecurity Analyst II to support day-to-day security operations, incident response, and detection tuning in a fully remote capacity.
Responsibilities
- Proactively monitor the environment to detect, analyze, and help mitigate cyber threats as part of daily security operations
- Review, investigate, and respond to real-time alerts across SIEM, EDR/XDR, email security, identity, network, cloud, and other security platforms
- Support incident response by gathering evidence, documenting timelines, coordinating containment and mitigation activity, and communicating status clearly to stakeholders
- Configure, maintain, monitor, and tune security tools to improve detection fidelity and reduce recurring false positives
- Translate security strategy into tactical work items, runbooks, use cases, reporting, and control improvements
- Collaborate across infrastructure, endpoint, cloud, network, application, and business teams to implement practical, risk-based security controls
- Create reporting and metrics that demonstrate security program health, operational trends, investigation outcomes, and opportunities for improvement
- Develop or implement scripts, queries, dashboards, or tools that improve detection, prevention, analysis, reporting, or workflow efficiency
- Lead small security workstreams or discrete implementation efforts as needed, escalating architectural or policy decisions appropriately
Skills
- Bachelor's degree in information security, computer science, or equivalent experience preferred
- 4–6 years of progressive IT and security experience, including hands-on security operations, cyber defense, and incident response
- Strong hands-on EDR/XDR investigation experience, including endpoint timeline review, suspicious process analysis, containment coordination, and remediation validation
- Strong hands-on SIEM experience, including log analysis, query writing, alert triage, correlation, use-case tuning, and detection quality improvement
- Experience administering or technically supporting at least one major security platform (e.g., EDR/XDR, SIEM, secure email gateway, phishing simulation, vulnerability management, identity security, or cloud security monitoring)
- Experience with phishing analysis and email security workflows, including header review, URL/domain/file reputation analysis, user reporting, and response documentation
- Working knowledge of Active Directory and Azure AD/Entra ID security concepts, including MFA, conditional access, authentication anomalies, and identity-based investigations
- Practical understanding of incident response phases, evidence handling, containment/eradication/recovery coordination, and post-incident documentation
- Ability to investigate network anomalies and security events across on-premises and cloud environments
- Ability to communicate technical findings clearly to non-technical audiences with written summaries, recommendations, and decision-ready context
- Working knowledge of security frameworks and concepts such as NIST, MITRE ATT&CK, least privilege, defense-in-depth, vulnerability management, and ITSM practices
- Ability to operate independently under time pressure, manage multiple priorities, and escalate appropriately as risk or business impact evolves
- PowerShell, Python, SPL, or other scripting/query language experience for automation, detection, and analysis
- Experience creating dashboards or metrics in Power BI or similar reporting and visualization tools
- Familiarity with Microsoft security tooling, Azure security monitoring, AWS or GCP security monitoring, or hybrid cloud security concepts
- Experience building runbooks, detection logic, incident report templates, executive-ready summaries, or security operations process improvements
- Experience with AI model integration for cybersecurity monitoring
- Relevant certifications such as Security+, CySA+, GCIH, GCIA, GCFA, or equivalent practical experience
Qualifications
Must Haves
- Bachelor's degree in information security, computer science, or equivalent experience preferred
- 4–6 years of progressive IT and security experience, including hands-on security operations, cyber defense, and incident response
- Strong hands-on EDR/XDR investigation experience, including endpoint timeline review, suspicious process analysis, containment coordination, and remediation validation
- Strong hands-on SIEM experience, including log analysis, query writing, alert triage, correlation, use-case tuning, and detection quality improvement
- Experience administering or technically supporting at least one major security platform (e.g., EDR/XDR, SIEM, secure email gateway, phishing simulation, vulnerability management, identity security, or cloud security monitoring)
- Experience with phishing analysis and email security workflows, including header review, URL/domain/file reputation analysis, user reporting, and response documentation
- Working knowledge of Active Directory and Azure AD/Entra ID security concepts, including MFA, conditional access, authentication anomalies, and identity-based investigations
- Practical understanding of incident response phases, evidence handling, containment/eradication/recovery coordination, and post-incident documentation
- Ability to investigate network anomalies and security events across on-premises and cloud environments
- Ability to communicate technical findings clearly to non-technical audiences with written summaries, recommendations, and decision-ready context
- Working knowledge of security frameworks and concepts such as NIST, MITRE ATT&CK, least privilege, defense-in-depth, vulnerability management, and ITSM practices
- Ability to operate independently under time pressure, manage multiple priorities, and escalate appropriately as risk or business impact evolves
Nice to Haves
- PowerShell, Python, SPL, or other scripting/query language experience for automation, detection, and analysis
- Experience creating dashboards or metrics in Power BI or similar reporting and visualization tools
- Familiarity with Microsoft security tooling, Azure security monitoring, AWS or GCP security monitoring, or hybrid cloud security concepts
- Experience building runbooks, detection logic, incident report templates, executive-ready summaries, or security operations process improvements
- Experience with AI model integration for cybersecurity monitoring
- Relevant certifications such as Security+, CySA+, GCIH, GCIA, GCFA, or equivalent practical experience
Benefits
- Benefits available to eligible employees or consultants may include medical, dental, and vision insurance
- Paid sick leave
- Retirement savings plans
- Other employer sponsored programs
- Benefits available to eligible employees or consultants may include medical, dental, and vision insurance, paid sick leave, retirement savings plans, paid time off, and other employer-sponsored programs