Cybersecurity Operations Analyst II

Posted Yesterday
2 Locations
In-Office or Remote
Mid level
Information Technology • Security • Financial Services
The Role
The Cybersecurity Operations Analyst II handles incident response, monitoring, and vulnerability management in Microsoft 365 E5 environments, ensuring compliance and effective threat detection.
Summary Generated by Built In

The Cybersecurity Operations Analyst II (COA2) is responsible for the initial triage and monitoring of security events, working exclusively in Microsoft 365 E5 environments, and helping to enforce CMMC 2.0 requirements.   

The COA 2 is responsible for advanced incident response, proactive threat hunting, vulnerability lifecycle management, and escalation support for Microsoft 365 E5 customers. This role bridges the gap between COA 1 alert/triage and senior analyst/engineering roles, working in-depth with Microsoft Defender XDR, external SOCs, and industry-standard vulnerability tools like Qualys and Tenable.  

Role & Responsibilities: 

Advanced Threat Detection & Response  

  • Lead investigations of escalated alerts across the following:  
  • Defender for Endpoint  
  • Defender for Office 365  
  • Defender for Cloud Apps (MCAS)  
  • Defender for Identity (formerly ATA)  
  • Microsoft Defender XDR  
  • Correlate log and alert data to detect lateral movement, privilege escalation, anomalous behavior, and advanced persistent threats using Microsoft Defender data and investigative tools from external SOC vendors.  
  • Conduct live incident response across customer tenants (containment, eradication, recovery) in accordance with CMMC 2.0 and NIST 800-171 incident response standards.  
  • Coordinate post-incident documentation including RCA, timeline analysis, and recommendations.  

Incident Handling & Response Support  

  • Assist senior analysts during active incidents by collecting logs, screenshots, and device/user activity history.  
  • Document timelines, observations, and artifacts to support root cause analysis and reporting.  
  • Conduct follow-up on low-risk alerts and phishing investigations (possibly with supervised guidance).  

Customer Interaction & Ticket Management  

  • Document findings and updates in the SOC ticketing system with accuracy and clarity.  
  • Respond to basic client inquiries related to user behavior, alert definitions, or mitigation steps under supervision.  
  • Follow documented workflows to support CMMC 2.0 incident response requirements, including reporting timelines and evidence handling.  

Threat Hunting & Detection Engineering Support  

  • Conduct proactive threat hunting using KQL queries in Microsoft Sentinel and hunting dashboards in Defender XDR.  
  • Assist with tuning analytics rules and alert thresholds and reducing false positives in detection logic.  
  • Work with external SOC services to tune rules and alert thresholds.  
  • Identify opportunities for new detections based on threat intelligence and customer risk profiles.  
  • Support configuration and optimization of Microsoft Sentinel data connectors, workbooks, automation rules, and response playbooks.  
  • Monitor log ingestion and telemetry gaps from M365 Defender products, Entra ID, and endpoint clients.  
  • Maintain detection signatures and IOCs provided by Microsoft, ISACs, or third-party feeds.  

Vulnerability & Patch Management  

  • Manage operating system and third-party software patching cycles for customer environments.  
  • Prioritize and manage vulnerability remediation in coordination with infrastructure teams and customer needs.  
  • Perform vulnerability scans using Qualys, Tenable.io, or Nessus across hybrid and cloud environments.  
  • Analyze, prioritize, and track vulnerabilities by CVSS score, exploitability, and exposure relevance to customer mission.  
  • Collaborate with customer IT and endpoint teams to validate and remediate critical vulnerabilities in operating systems, applications, and Microsoft 365 services.  
  • Report on vulnerability trends and threat exposure as part of recurring customer security reviews.  

Customer Engagement & Documentation  

  • Participate in high-touch incident communications and brief customers on security events, containment actions, and risk.  
  • Generate clear, actionable incident summaries and vulnerability reports tailored for both technical and executive audiences.  
  • Assist with compliance evidence collection during audits or IR tabletop exercises.  
  • Lead or assist in conducting security awareness training campaigns and tabletop exercises for customers.  
  • Assist in gathering and assembling audit evidence to support compliance assessments. 

Competencies / Skills: 

  • 3–5 years of cybersecurity experience, with at least 1 year in a SOC, IR, or detection-focused role.  
  • Strong knowledge of attacker TTPs, MITRE ATT&CK, and Zero Trust principles.  
  • Hands-on experience with Microsoft 365 E5 security stack.  
  • Familiarity with CMMC 2.0, NIST 800-171, and FedRAMP security controls.  
  • Experience conducting or responding to vulnerability scans and remediation workflows.  
  • Security+ or SC-900 certification  
  • Must be a U.S. citizen eligible for ITAR-compliant work.  

Preferred: 

  • Certified Ethical Hacker (CEH)  
  • Microsoft SC-100, SC-200, SC-300, or SC-400 certifications  
  • Microsoft AZ-500  

 

Where required by law, this posting includes a good‑faith pay range for candidates who will perform the role in specific jurisdictions. For other locations, the actual compensation may differ. Final compensation will be determined based on qualifications, experience, skills, work location, internal equity, and current market data. This job posting is not a contract or promise of employment or any particular compensation, and any employment offer will be set out in a written offer letter. 

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Top Skills

Kql
Microsoft 365 E5
Microsoft Defender Xdr
Microsoft Sentinel
Qualys
Tenable
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Tysons Corner, VA
184 Employees
Year Founded: 2003

What We Do

NeoSystems LLC. provides outsourced accounting & financial management, human capital, information technology, hosting and managed security services to government contractors and nonprofit organizations. Our flexible approach, highly experienced staff, and best-in-class software applications allow clients to reduce their accounting and financial costs, hire, on-board, evaluate, develop and terminate staff while meeting rigorous and continuously changing government standards and program requirements all while supported by an innovative, responsive staff of IT specialists. Our managed service model and world-class FedRAMP Moderate Equivalent hosting environment enables us to help companies operate more efficiently and better achieve their core missions. In addition to managed services, we offer system integrations and implementation consulting, hosting, managed security, short or long term project support, staff augmentation and financial planning & analysis services. Our mission is to enable our clients to grow, assisting them in becoming more profitable, efficient, and better equipped to win new business. Our varied and scalable strategic back office solutions allow for businesses and organizations to focus on what they do best – serving their customers, growing their businesses, and fulfilling their own missions. #Deltek #Costpoint #IBM #DCAACompliance #Accounting

Similar Jobs

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Fort Meade, MD, USA
28000 Employees
122K-213K Annually

ServiceNow Logo ServiceNow

Monetization Strategy Director

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Waltham, MA, USA
28000 Employees
184K-322K Annually

ServiceNow Logo ServiceNow

Director, Outbound Product Management - CRM for Manufacturing Products

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Santa Clara, CA, USA
28000 Employees
221K-387K Annually

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Washington, DC, USA
28000 Employees
169K-278K Annually

Similar Companies Hiring

Rain Thumbnail
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3 • Infrastructure as a Service (IaaS)
New York, NY
100 Employees
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees
Milestone Systems Thumbnail
Software • Security • Other • Big Data Analytics • Artificial Intelligence • Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account