Reports To: Security Operations / Information Security Manager
Employment Type: Full-Time
Job Summary:
The Junior Security Analyst supports the organization’s security operations by monitoring security events, assisting with incident response, and helping maintain a strong security posture across endpoints, identities, and cloud services. This role is ideal for someone early in their security career who has hands‑on experience with Microsoft Defender or similar, communicates clearly with both technical and non-technical audiences, and is eager to grow in a collaborative, hybrid environment.
Key Responsibilities:
Security Operations & Monitoring
- Monitor and triage security alerts from Microsoft Defender and related security tooling.
- Assist with investigation of endpoint, identity, and cloud security events.
- Escalate potential security incidents to senior analysts following documented procedures.
- Help validate alerts and reduce false positives through analysis and documentation.
- Participate in incident response activities, including evidence collection, documentation, and follow‑up tasks.
- Assist with containment and remediation efforts under the guidance of senior security staff.
- Support post‑incident reviews and lessons learned documentation.
- Clearly document security findings, incidents, and remediation steps.
- Communicate security issues in a professional, easy‑to‑understand manner to IT teams and business stakeholders.
- Work closely with IT, Help Desk, and Infrastructure teams to resolve security‑related issues.
- Provide timely updates on alert status and investigation progress.
Security Hygiene & Continuous Improvement
- Assist with maintaining endpoint security baselines and security best practices.
- Help review and improve security processes, runbooks, and documentation.
- Stay current on common security threats, attacker techniques, and Microsoft security platform updates.
Required Qualifications:
- 1–2 years of experience in IT, security operations, SOC, or a related role.
- Hands‑on experience with Microsoft Defender or similar (endpoint, identity, or cloud).
- Hands on experience with Microsoft entra ID and active directory
- Strong written and verbal communication skills.
- Ability to document technical issues clearly and accurately.
- Basic understanding of cybersecurity concepts such as malware, phishing, endpoint security, and incident response.
- Ability to work in a hybrid environment with on‑site presence in Birmingham, Alabama.
Preferred Qualifications:
- Experience working with Microsoft security tools beyond Defender.
- Familiarity with basic security frameworks or concepts (e.g., NIST).
- Experience working with ticketing or incident tracking systems.
- Security‑related certifications or coursework (e.g., Security+, Microsoft security fundamentals).
- Microsoft Defender alert review and investigation