Senior Security Analyst - Microsoft

    Highlights

    We expect senior analysts to hold or quickly earn Microsoft credentials that anchor our partner standing, and we invest in advancing them: SC-200 - Microsoft Security Operations Analyst (expected as our core SOC credential). As we build a deep security practice, you'll mentor Tier 1 and Tier 2 analysts, shape how we implement, configure, detect and respond across our customer base, and help stand up the operations that our clients depend on.

    Numbers & Facts

    LocationWA

    Description

    Home / Careers / Senior Security Analyst

    Now Hiring

    Senior Security Analyst - Microsoft

    Managed Detection & Response · Security Operations Center

    LocationRemote

    TypeFull-time

    LevelSenior

    About the role

    This is the top of our Security Analyst/Cyber Defense track. As a Senior Security Analyst, you're the person the team escalates to, who runs the hardest investigations, hunts for what the alerts miss, and owns the response when a real incident hits. You'll work deep in Microsoft Defender XDR and Microsoft Sentinel, building detection content and playbooks that make the whole operation sharper and more proactive.

    You'll also set the technical bar. As we build a deep security practice, you'll mentor Tier 1 and Tier 2 analysts, shape how we implement, configure, detect and respond across our customer base, and help stand up the operations that our clients depend on. We take accountability for our customers' security posture and you'll be central to how we deliver on that.

    Duties & Responsibilities

    • Lead complex investigations across endpoint, identity, email, and cloud as the escalation point for Tier 1 and Tier 2 analysts.
    • Leverage AI technologies and tooling to empower defenses with the latest capabilities for advanced reasoning and automation
    • Own incident response end to end: scope, contain, eradicate, recover, and lead post-incident reviews.
    • Run proactive threat hunts across customer environments using Microsoft threat intelligence and advanced hunting.
    • Engineer detections - author and tune Sentinel analytics rules, KQL queries, and SOAR/Logic App automation to raise signal and cut noise.
    • Build and maintain the runbooks, playbooks, and escalation paths that standardize how the SOC operates.
    • Mentor and upskill junior analysts with reviews, shadowing, and knowledge sharing.
    • Optimize the Defender and Sentinel deployment - coverage, configuration, and onboarding of new customer tenants.
    • Contribute to the operational maturity behind our Microsoft MXDR verification and SOC 2 readiness.

    Qualifications

    Required:

    • [5+] years in a SOC, MDR, MSSP, or incident-response role, with demonstrable hands-on Microsoft Defender experience.
    • Deep, practical command of the Microsoft Defender suite - Defender for Endpoint, Identity, Office 365, and Cloud.
    • Strong Microsoft Sentinel skills, including fluent KQL for hunting and detection engineering.
    • Proven managed detection and response experience where you've led investigations through to resolution.
    • Working knowledge of the Microsoft 365 and Azure ecosystem and customer licensing (Business Premium, E3, E5, Defender P1/P2, etc.).
    • Clear communication and sound judgment under pressure, with a track record of mentoring others.
    • A drive to keep learning and to grow with the practice as it scales - we value this at every level.

    Nice to have:

    • Detection-engineering or purple-team experience; MITRE ATT&CK fluency.
    • Automation and scripting depth (PowerShell, KQL, Logic Apps / Sentinel SOAR).
    • Experience helping stand up or scale a SOC or MSSP practice.

    Certifications

    We expect senior analysts to hold or quickly earn Microsoft credentials that anchor our partner standing, and we invest in advancing them:

    • SC-200 - Microsoft Security Operations Analyst (expected as our core SOC credential).
    • AZ-500 - Azure Security Engineer Associate (strongly preferred at this level).
    • SC-100 - Cybersecurity Architect Expert (preferred as the senior-track credential we'll help you reach).
    • SC-300 - Identity and Access Administrator, for advanced identity-protection work.
    • Microsoft Defender XDR Applied Skills - hands-on credentials that reinforce day-to-day response.

    Why join

    • Be a founding technical leader in a new security practice. You set the standards, not inherit them.
    • Go deeper on the Microsoft security stack than most roles allow, with a fully supported certification path.
    • A clear track toward lead, principal, and SOC leadership as the team and customer base grow.

    Benefits

    • 401(k) matching
    • Paid time off
    • Dental insurance
    • Health insurance
    • Vision insurance

    Katalyst is an equal opportunity employer and does not discriminate on the basis of race, color, religion, national origin, sex, physical or mental disability, or age.

    Ready to apply?

    To apply, send your resume through the form below or to careers@katalystng.com.

    Apply Now

    LocationRemote

    ScheduleBusiness hours + on-call

    LevelSenior

    Reports toSOC Manager

    TypeFull-time

    What do you get from Katalyst?

    • An organization that puts a high value on family.
    • A well-documented onboarding plan.
    • A culture that rewards performance and client outcomes.
    • Continuous learning opportunities and professional development.
    • Full benefits package.

    Apply Today

    Join the team

    Complete the application below. We value grit, humility, and curiosity, and we review every submission.

    Please enable JavaScript to view and submit the application form, or email your resume to careers@katalystng.com.

    Similar Jobs

    See more jobs