Home / Careers / Security Analyst
Now Hiring
Security Analyst - Microsoft
Managed Detection & Response · Security Operations Center
LocationRemote
TypeFull-time
LevelEntry - Mid Level
Role Description
This is a full-time, remote/hybrid role supporting our Microsoft-heavy clients. In this position you will provide day to day security triage and security response centered around the Microsoft ecosystem of security products.
You will work in our Security Operation Center supporting clients through Microsoft Defender XDR, the Defender Suite and Microsoft Sentinel, catching threats early, and driving them to resolution. You won't just triage alerts, you'll take accountability for the response activities that happen next. And you'll have the latest AI-powered tools and technologies to help.
This is a role for someone who lives in the Microsoft security stack and is hungry to master it. The analysts who join now will help shape how we detect, investigate, and respond, and will grow their careers as the team and our customer base scale.
Duties & Responsibilities
- Work with clients to implement and configure best practices for the Microsoft Defender XDR portfolio of products to ensure cyber risk reduction and properly flows of alerts and telemetry
- Investigate alerts and cyber incidents across endpoint, identity, email, and cloud - Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud.
- Leverage AI technologies and tooling to empower defenses with the latest capabilities for advanced reasoning and automation
- Run response actions to contain, remediate, and document activities, escalating cleanly when an incident needs a senior hand.
- Write and tune Sentinel analytics rules, KQL queries, and detection content to cut noise and catch what matters.
- Hunt proactively for threats using Microsoft threat intelligence and advanced hunting.
- Keep clear records in our ticketing system and contribute to runbooks, playbooks, and customer reporting.
- Communicate findings plainly to teammates and, when needed, to customers.
Qualifications
Required - You have most of these, and you're eager to close any gaps quickly:
- Hands-on experience with, or strong working knowledge of, the Microsoft Defender suite and Microsoft security tooling.
- Familiarity with Microsoft Sentinel (SIEM) and comfort writing or reading KQL queries.
- A solid grasp of security fundamentals, the attack lifecycle, the kill-chain, common threats, identity, endpoint, and email security.
- Understanding of the Microsoft 365 and Azure ecosystem and how customers are licensed (Business Premium, E3, E5, Defender P1/P2, etc.).
- Sharp analytical instincts, clear written communication, and calm under pressure.
- A strong desire to learn rapidly, and this is the single most important trait we're hiring for.
Nice to have:
- Prior SOC, MSSP, MDR, or IT security experience.
- Scripting or automation (PowerShell, KQL, Logic Apps / SOAR).
- Exposure to incident response, threat hunting, or vulnerability management.
Certifications
You don't need these to apply but if you have the drive, we'll help you earn them.
- SC-200 - Microsoft Security Operations Analyst (a core credential; required within 6 months of hire).
- SC-900 - Security, Compliance & Identity Fundamentals (great starting point for early-career analysts).
- AZ-500 - Azure Security Engineer Associate (a growth target we'll support).
- SC-300 - Identity and Access Administrator, for deeper identity-protection skills.
- Microsoft Defender XDR Applied Skills - hands-on credentials that sharpen day-to-day response.
Why join us now
- Our focus on leveraging AI to help our clients and to better Protect their environments means you'll have access to the latest tools and participate heavily in this AI wave
- Get in at the ground floor of a security practice and help build and shape it.
- Go deep on the Microsoft security stack with real mentorship and a clear certification path fully supported.
- Massive career growth opportunities with a defined growth toward senior roles from analyst to threat hunter, and beyond as we scale.
Benefits
- 401(k) matching
- Paid time off
- Dental insurance
- Health insurance
- Vision insurance
Katalyst is an equal opportunity employer and does not discriminate on the basis of race, color, religion, national origin, sex, physical or mental disability, or age.
Ready to apply?
To apply, send your resume through the form below or to careers@katalystng.com.
Apply Now
LocationRemote
ScheduleBusiness hours + on-call
LevelEntry - Mid Level
Reports toCyber Defense Operations Lead
TypeFull-time
What do you get from Katalyst?
- An organization that puts a high value on family.
- A well-documented onboarding plan.
- A culture that rewards performance and client outcomes.
- Continuous learning opportunities and professional development.
- Full benefits package.
Apply Today
Join the team
Complete the application below. We value grit, humility, and curiosity, and we review every submission.
Please enable JavaScript to view and submit the application form, or email your resume to careers@katalystng.com.