nuHarbor logo
nuHarbor
Posted 41 days agoVerified live 13h ago

Security Analyst, MXDR

Brief overview

Remote
UndergradOr in progress
$90k–$116k/yrStated range
2+ yrsMinimum
Microsoft SentinelMicrosoft DefenderSIEM/SOC OperationsSecurity Event Triage and AnalysisIncident ResponseKQLLog CorrelationThreat DetectionEndpoint SecurityIdentity and Access ThreatsSecurity CertificationsInvestigative JudgmentNetworking FundamentalsVerbal and Written Communication

Job description

Summary

nuHarbor provides cybersecurity guidance, technology, and partnerships to help organizations strengthen their security and protect critical services. The Security Analyst, MXDR supports the full lifecycle of security alert and incident triage, investigation, disposition, escalation, and documentation across multiple client environments. The role also contributes to incident response, detection tuning, SLO operations, client communication, and continuous improvement within a 24x7 service delivery model.

Responsibilities

  • Review, analyze and investigate security alerts and incidents in Microsoft Defender and Sentinel environments
  • Identify and assess indicators of compromise (IOC) and attack (IOA) across client environments
  • Drive incidents through full lifecycle: triage -> investigation -> disposition -> escalation or closure
  • Accurately triage and classify alerts, minimizing false positives while preserving visibility into real threats and document outcomes to support continuous improvement and quality review
  • Execute incident response procedures aligned to defined playbooks and client escalation plans
  • Escalate incidents that meet client escalation criteria with documented evidence, impacted entities, and investigation summary
  • Support containment actions (e.g., isolate endpoints, kill processes) when access allows
  • Partner with client SOC or IT teams when additional enrichment or remediation is required
  • Actively balance accuracy vs. urgency in escalation decisions
  • Meet defined SLOs for alert triage start, investigation updates, and case closure, with elevated response standards for high-severity and 24x7 priority incidents
  • Prioritize and respond to high severity incidents during second shift, in alignment with 24x7 response requirements and defined SLOs. Reprioritize and update investigations when incident severity changes, ensuring timely escalation and accurate documentation
  • Evaluate alert quality and recommend tuning or suppression of non-actionable detections
  • Review and improve analytics rules, queries, and detection logic
  • Identify gaps in visibility, logging, or detection coverage
  • Contribute to development of playbooks, automation, and operational processes
  • Document all investigations, findings, and actions in service desk systems
  • Provide timely updates through ticketing platforms and escalation channels
  • Support regular reporting on: Incident trends, Environment health, Open cases and outcomes
  • Participate in client calls, reviews, and quarterly business reviews as needed
  • Operate independently in a fast-paced environment, managing multiple investigations simultaneously
  • Make informed decisions with incomplete data and limited client context
  • Proactively identify risks, gaps, and opportunities for improvement
  • Take ownership of your queue, your clients, and the quality of your work

Skills

  • Bachelor's Degree and two (2) years of experience in cybersecurity, SOC, MDR or incident response
  • In lieu of a degree, two (2) years of experience in a related technology field and relevant industry certifications are required
  • Demonstrated experience with SIEM solutions, SOC operations, executing security event triaging and tuning
  • Experience working in SIEM/XDR tools including specifically Microsoft Sentinel or Defender
  • Proven ability to independently investigate and triage security events
  • Experience with security event analysis, log correlation, and threat detection
  • Experience with KQL or similar query languages
  • Familiarity with common endpoint security concepts
  • Demonstrated knowledge of security log, infrastructure design and networking fundamentals
  • Understanding of Identity and Access threats
  • Strong investigative mindset with attention to detail
  • Ability to anticipate problems, communicate them, and resolve appropriately
  • Demonstrated verbal and written communication skills for various internal and external audiences
  • Must be a citizen of the United States
  • Bachelor's Degree and five (5) or more years in the Information Technology field
  • Holds relevant industry certifications
  • CompTIA Security+, CySA+, CISSP, etc
  • Microsoft Security Operations Analyst (SC-200)
  • Azure Security Engineer (AZ-500)
  • Proven experience in a MSSP or multi-client environment
  • Ability to conduct multi-step breach and investigative analysis to trace dynamic activities associated with advanced threats
  • Exhibit advanced understanding of, and ability to communicate, security technologies that can be used to mitigate cyber risks
  • Strong understanding of Incident Response phases and demonstrated experience responding to security incidents
  • Attention to detail and a methodical approach to standard operating procedures
  • Ability to explain simple hardening methods for network and process detections
  • Ability to manage multiple concurrent objectives or activities and effectively make judgments
  • Understanding of common network services and attacks against them

Qualifications

Must Haves

  • Bachelor's Degree and two (2) years of experience in cybersecurity, SOC, MDR or incident response
  • In lieu of a degree, two (2) years of experience in a related technology field and relevant industry certifications are required
  • Demonstrated experience with SIEM solutions, SOC operations, executing security event triaging and tuning
  • Experience working in SIEM/XDR tools including specifically Microsoft Sentinel or Defender
  • Proven ability to independently investigate and triage security events
  • Experience with security event analysis, log correlation, and threat detection
  • Experience with KQL or similar query languages
  • Familiarity with common endpoint security concepts
  • Demonstrated knowledge of security log, infrastructure design and networking fundamentals
  • Understanding of Identity and Access threats
  • Strong investigative mindset with attention to detail
  • Ability to anticipate problems, communicate them, and resolve appropriately
  • Demonstrated verbal and written communication skills for various internal and external audiences
  • Must be a citizen of the United States

Nice to Haves

  • Bachelor's Degree and five (5) or more years in the Information Technology field
  • Holds relevant industry certifications
  • CompTIA Security+, CySA+, CISSP, etc
  • Microsoft Security Operations Analyst (SC-200)
  • Azure Security Engineer (AZ-500)
  • Proven experience in a MSSP or multi-client environment
  • Ability to conduct multi-step breach and investigative analysis to trace dynamic activities associated with advanced threats
  • Exhibit advanced understanding of, and ability to communicate, security technologies that can be used to mitigate cyber risks
  • Strong understanding of Incident Response phases and demonstrated experience responding to security incidents
  • Attention to detail and a methodical approach to standard operating procedures
  • Ability to explain simple hardening methods for network and process detections
  • Ability to manage multiple concurrent objectives or activities and effectively make judgments
  • Understanding of common network services and attacks against them

Benefits

  • A collaborative, high-performing team environment
  • Leaders who are invested in your success and development
  • Meaningful work that helps organizations protect critical services and missions
  • The encouragement to bring your authentic self to work every day
  • Competitive pay
  • Performance-based bonus opportunities
  • Generous paid time off
  • Comprehensive benefits
  • This position is eligible for a shift premium.
  • This position is eligible for nuHarbor's annual bonus program with a target opportunity of 10%.

More jobs like this