Senior Security Analyst

Katalyst

North Carolina

On-site

USD 120,000 - 180,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) matching
Paid time off
Health insurance
Vision insurance

Job summary

Katalyst is seeking a Senior Security Analyst to lead the most challenging investigations and drive the security posture for multiple customers in the Eastern Time Zone. You will own incident response, build detections, and mentor Tier 1–2 staff, working deeply with Defender XDR and Microsoft Sentinel.

You will shape how we implement, configure, detect, and respond, helping stand up a mature security practice and deliver high-value client outcomes. North/South Carolina location preferred.

Qualifications

  • 5+ years in a SOC, MDR, MSSP, or incident-response role.
  • Microsoft Defender suite expertise (Defender for Endpoint, Identity, Office 365, Cloud).
  • Strong Microsoft Sentinel skills with fluent KQL for hunting/detection engineering.
  • Proven managed detection and response experience leading investigations to resolution.
  • Experience with Microsoft 365 and Azure licensing and ecosystems.

Responsibilities

  • Lead complex investigations across endpoint, identity, email, and cloud as escalation point for Tier 1/2 analysts.
  • Leverage AI technologies and tooling to empower defenses with advanced reasoning and automation.
  • Own incident response end-to-end: scope, contain, eradicate, recover, and post-incident reviews.
  • Run proactive threat hunts across customer environments using threat intelligence and advanced hunting.
  • Engineer detections: author and tune Sentinel analytics rules, KQL queries, and SOAR/Logic Apps automation.
  • Build and maintain runbooks, playbooks, and escalation paths for SOC operations.
  • Mentor junior analysts with reviews, shadowing, and knowledge sharing.
  • Optimize Defender/Sentinel deployment for coverage and onboarding of new tenants.
  • Contribute to MXDR verification and SOC 2 readiness.

Skills

Microsoft Defender experience
KQL
Automation scripting
Incident response
SOC/MDR/MSSP

Tools

PowerShell
Logic Apps
Sentinel SOAR
Azure

Job description

LOCATION PREFERENCE:

North/South Carolina,


No applications from candidates outside of Eastern Time Zone will be considered.


About the Company

Katalyst Network Group is Your Digital Operations Partner. We Connect, Protect, and Operate Your Digital Backbone, taking accountability for our customers\' technology so they can focus on their business. What do you get from Katalyst? An organization that puts a high value on family. A well-documented onboarding plan. A culture that rewards performance and client outcomes. Continuous learning opportunities and professional development. Full benefits package. We value grit, humility, curiosity, and a strong client-first approach. Candidates who share these values and meet the qualifications outlined below will find strong opportunities for growth and success at Katalyst.


About the Role

This is the top of our Security Analyst/Cyber Defense track. As a Senior Security Analyst, you're the person the team escalates to, who runs the hardest investigations, hunts for what the alerts miss, and owns the response when a real incident hits. You\'ll work deep in Microsoft Defender XDR and Microsoft Sentinel, building detection content and playbooks that make the whole operation sharper and more proactive. You\'ll also set the technical bar. As we build a deep security practice, you\'ll mentor Tier 1 and Tier 2 analysts, shape how we implement, configure, detect and respond across our customer base, and help stand up the operations that our clients depend on. We take accountability for our customers\' security posture and you\'ll be central to how we deliver on that.


Responsibilities


  • Lead complex investigations across endpoint, identity, email, and cloud as the escalation point for Tier 1 and Tier 2 analysts.

  • Leverage AI technologies and tooling to empower defenses with the latest capabilities for advanced reasoning and automation.

  • Own incident response end to end: scope, contain, eradicate, recover, and lead post-incident reviews.

  • Run proactive threat hunts across customer environments using Microsoft threat intelligence and advanced hunting.

  • Engineer detections - author and tune Sentinel analytics rules, KQL queries, and SOAR/Logic App automation to raise signal and cut noise.

  • Build and maintain the runbooks, playbooks, and escalation paths that standardize how the SOC operates.

  • Mentor and upskill junior analysts with reviews, shadowing, and knowledge sharing.

  • Optimize the Defender and Sentinel deployment - coverage, configuration, and onboarding of new customer tenants.

  • Contribute to the operational maturity behind our Microsoft MXDR verification and SOC 2 readiness.


Qualifications

Required:



  • [5+] years in a SOC, MDR, MSSP, or incident-response role, with demonstrable hands-on Microsoft Defender experience.

  • Deep, practical command of the Microsoft Defender suite - Defender for Endpoint, Identity, Office 365, and Cloud.

  • Strong Microsoft Sentinel skills, including fluent KQL for hunting and detection engineering.

  • Proven managed detection and response experience where you\'ve led investigations through to resolution.

  • Working knowledge of the Microsoft 365 and Azure ecosystem and customer licensing (Business Premium, E3, E5, Defender P1/P2, etc.).

  • Clear communication and sound judgment under pressure, with a track record of mentoring others.

  • A drive to keep learning and to grow with the practice as it scales - we value this at every level.


Preferred Skills:


  • Detection-engineering or purple-team experience; MITRE ATT&CK fluency.

  • Automation and scripting depth (PowerShell, KQL, Logic Apps / Sentinel SOAR).

  • Experience helping stand up or scale a SOC or MSSP practice.


Certifications


  • SC-200 - Microsoft Security Operations Analyst (expected as our core SOC credential).

  • AZ-500 - Azure Security Engineer Associate (strongly preferred at this level).

  • SC-100 - Cybersecurity Architect Expert (preferred as the senior-track credential we\'ll help you reach).

  • SC-300 - Identity and Access Administrator, for advanced identity-protection work.

  • Microsoft Defender XDR Applied Skills - hands-on credentials that reinforce day-to-day response.

  • Be a founding technical leader in a new security practice. You set the standards, not inherit them.

  • Go deeper on the Microsoft security stack than most roles allow, with a fully supported certification path.

  • A clear track toward lead, principal, and SOC leadership as the team and customer base grow.

  • 401(k) matching

  • Paid time off

  • Health insurance

  • Vision insurance


Equal Opportunity Statement:

Katalyst is an equal opportunity employer and does not discriminate on the basis of race, color, religion, national origin, sex, physical or mental disability, or age.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst: Defender XDR & SOC Lead
Senior Security Analyst: Defender XDR & SOC Lead

Katalyst • North Carolina

On-site
USD 120,000 - 180,000
401(k) matching
Paid time off
Health insurance
+1
Senior Security Engineer
Senior Security Engineer

Carex Consulting Group • Madison (WI)

On-site
USD 100,000 - 130,000
Senior Defender for Endpoint & SIEM Security Engineer
Senior Defender for Endpoint & SIEM Security Engineer

Carex Consulting Group • Madison (WI)

On-site
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Security Analyst
Security Analyst

Tenarai Europe • Town of Poland (NY)

Hybrid
USD 32,000 - 51,000
Remote/Hybrid work
Office spaces
Parking
+8
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Visa Hunt • United States

Hybrid
USD 120,000 - 180,000
Cybersecurity Analyst
Cybersecurity Analyst

Technix LLC • Carson City (NV)

On-site
USD 85,000 - 110,000
Sr. Analyst, Falcon Complete (Remote)
Sr. Analyst, Falcon Complete (Remote)

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 125,000 - 180,000
Competitive compensation and equity
Paid vacation and holidays
Professional development
+1
Analyst, Security
Analyst, Security

Socket.dev • Owensboro (KY)

On-site
USD 55,000 - 75,000
Medical
Vision
Dental
+11