Job Description: Location: This position is remote within the US. Overview of Role: The Cybersecurity Analyst II will support day-to-day Cybersecurity operations, alert investigation, incident response, detection tuning, reporting, implementation support, and documentation with limited supervision. The role is hands-on and delivery-focused, and requires the analyst to independently triage ambiguous security events, coordinate with IT partners, recommend risk-based actions, and help mature repeatable security processes. Requirements: - Perform daily security operations by proactively monitoring the environment to detect, analyze, and help mitigate cyber threats. - Review, investigate, and respond to real-time alerts across SIEM, EDR/XDR, email security, identity, network, cloud, and other security platforms. - Support cybersecurity incident response by gathering evidence, documenting timelines, coordinating containment/mitigation activity, and communicating status clearly. - Configure, maintain, monitor, and tune security tools to improve detection fidelity and reduce recurring false positives. - Translate IT security strategy into tactical work items, runbooks, use cases, reporting, and control improvements. - Work across infrastructure, endpoint, cloud, network, application, and business teams to implement practical, risk-based security controls. - Create reporting and metrics that demonstrate security program health, operational trends, investigation outcomes, and opportunities for improvement. - Develop or implement scripts, queries, dashboards, or open-source/third-party tools that improve detection, prevention, analysis, reporting, or workflow efficiency. - Lead small security workstreams or discrete implementation efforts when needed, while escalating architectural or policy decisions appropriately. Education / Experience: - Bachelor's degree in information security, computer science, or equivalent experience preferred. - Targeting 4 to 6 years of progressive IT/security experience, including hands-on security operations cyber defense, incident response. Must have experience/skills: - Strong hands-on EDR/XDR investigation experience, including endpoint timeline review, suspicious process analysis, containment coordination, and remediation validation. - Strong hands-on SIEM experience, including log analysis, query writing, alert triage, correlation, use-case tuning, and quality improvement of detections. - Experience administering or technically supporting at least one major security platform such as EDR/XDR, SIEM, secure email gateway, phishing simulation platform, vulnerability management tool, identity security tool, or cloud security monitoring platform. - Experience with phishing analysis and email security workflows, including header review, URL/domain/file reputation analysis, user reporting, and response documentation. - Working knowledge of Active Directory and Entra ID/Azure AD security, including users, groups, MFA, conditional access concepts, authentication anomalies, and identity-based investigations. - Practical understanding of incident response phases, evidence handling, containment/eradication/recovery coordination, and post-incident documentation. - Ability to investigate network anomalies and security events across on-premises and cloud environments. - Ability to communicate technical findings to non-technical audiences with clear written summaries, recommendations, and decision-ready context. - Working knowledge of security frameworks and concepts such as NIST, MITRE ATT&CK, least privilege, defense-in-depth, vulnerability management, and ITSM practices. - Ability to operate independently under time pressure, manage multiple priorities, and escalate appropriately when risk or business impact changes. Nice to have experience skills: - PowerShell, Python, SPL, or other scripting/query language experience for automation, detection, and analysis. - Experience creating dashboards or metrics in Power BI or similar reporting/visualization tools. - Familiarity with Microsoft security tooling, Azure security monitoring, AWS/GCP security monitoring, or hybrid cloud security concepts. - Experience building runbooks, detection logic, incident report templates, executive-ready summaries, or security operations process improvements. - Experience with AI model integration for cybersecurity monitoring. - Certifications such as Security+, CySA+, GCIH, GCIA, GCFA, or equivalent practical experience. Pay Range: $50.00 - $57.00 per hour, depending upon experience. Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.