We are seeking a Cyber Security Analyst to monitor, investigate, and responds to security threats across KBS and its subsidiaries' networks, endpoints, and cloud environments. This role combines proactive threat hunting, analytics, and automation to detect, contain, and mitigate cyber risks. The analyst plays a key role in strengthening enterprise defenses, improving visibility, and supporting continuous improvement of the company's overall security posture.
This role is a remote opportunity .
Position Summary
The Cyber Security Analyst configures, implements, monitors, investigates, and responds to security threats across KBS and its subsidiaries' networks, endpoints, and cloud environments. The role requires deep working knowledge of the security capabilities available in AWS and Microsoft 365, along with the ability to quickly gain command of the KBS security tool stack.
The analyst works closely with the rest of the security team and with cross-departmental functions, including Software Engineering and DevOps, guiding best practices and control implementation and explaining the tradeoffs behind each recommendation. This position calls for a self-motivated team player who takes initiative, works effectively with minimal supervision, and understands how to balance strong security with business productivity.
Essential Duties and Responsibilities
Responsibilities may include but are not limited to:
• Apply AWS security best practices across identity, network, workload, and data services, covering areas such as IAM roles and permission scoping, VPC and edge controls, container and serverless compute, storage and databases, and encryption and key management, assessed against the AWS Well-Architected Security Pillar.
• Own AWS security posture, creating platform visibility through the SIEM and driving measurable improvement over time, working with Software Engineering, DevOps, and other stakeholders to see that security requirements are implemented to standard.
• Configure and tune Microsoft 365 security capabilities across endpoint, identity, email, and data protection, including the Defender suite, Purview data protection and insider risk management, and Entra ID access controls such as Conditional Access and privileged access.
• Actively hunt for indicators of compromise, suspicious activity, and adversarial behavior across endpoint, identity, email, network, and cloud environments using CrowdStrike and other EDR/XDR platforms, escalating or remediating as appropriate.
• Identify repetitive security operations work and automate it across detection, control enforcement, and response using SOAR, Python, PowerShell, or infrastructure as code.
• Develop and execute CQL and KQL queries and build dashboards to analyze telemetry from Microsoft, CrowdStrike, AWS, and related sources.
• Participate in red/blue team exercises, simulations, and post-incident reviews to identify and reduce areas of vulnerability/exposure and improve readiness.
• Create and improve security baselines, detection rules, and playbooks to enhance visibility and reduce response time.
• Prepare reports and documentation on incidents, improvements, and overall security posture.
• Ensure alignment with internal policies, industry standards, and relevant security frameworks.
• Stay current on new platform capabilities and emerging attack vectors, applying a proactive, inquisitive, and analytical mindset to surface overlooked threats.
Additional Duties and Responsibilities
As required by management.
Knowledge, Skills and Competencies
• Hands-on AWS security configuration experience across identity, network, and data services is required.
• Advanced working knowledge of Microsoft 365 security and compliance across identity, endpoint, email, and collaboration workloads.
• Able to present platform options and tradeoffs and commit to a clear recommendation.
• Hands-on experience using CQL to build queries and dashboards is required. Working knowledge of KQL.
• EDR/XDR and SIEM platforms (CrowdStrike, Microsoft Defender), plus email security platforms (Abnormal Security).
• Experience with Python or PowerShell scripting for automation and incident enrichment, and with infrastructure as code for configuration enforcement.
• Threat intelligence, vulnerability management, and incident response methodologies.
• Understanding of common threat frameworks (MITRE ATT&CK, Cyber Kill Chain).
• Analytical and detail-oriented with strong problem-solving ability.
• Self-motivated and dependable, working effectively with minimal supervision.
• Collaborative communicator with cross-departmental awareness.
• Curious and proactive, committed to continuous learning and process improvement.
Educational Qualifications/Job Experience Requirements
Experience Required:
• Background in solutions architecture or systems engineering, with demonstrated ability to select among available platform services rather than only operate a fixed configuration. Preferred.
• 5+ years' experience in the information security field
Education:
• Bachelor's degree in a computer-related field, such as cybersecurity, software information assurance, computer science, or an educational equivalent
• Certifications preferred (nice to have):
o AWS: Certified Security - Specialty, and Certified Solutions Architect (Associate or Professional).
o Microsoft: SC-100 Cybersecurity Architect Expert, SC-200 Security Operations Analyst, AZ-500 Azure Security Engineer or its successor SC-500 Cloud and AI Security Engineer, AZ-305 Azure Solutions Architect Expert.
Working Conditions/Physical Requirements
Schedule:
• Regular weekly schedule; weekends or holidays as needed
The working conditions and physical environments described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Physical requirements:
• Extended periods of work seated at a desk; repetitive hand motions; prolonged use of computer; occasionally lift and carry up to 25 lbs.
• Ability to speak clearly (use of voice)
• Vision requirements include close vision, distance vision, moderate peripheral vision, depth perception and ability to adjust focus
• Must be able to see and hear or use prosthetics that will enable these senses to function adequately to ensure that the requirements of this position can be fully met
• Must be able to cope with the mental and emotional stress of the position
Environment:
• Office environment generally mild to moderate conditions including varying temperatures and noise levels conducive to a busy workplace and office equipment
• Lighting varies based on building requirements and may be adjusted within reason
• Time constraints and related pressures to complete work are high
Travel: n/a
The salary range for this position is based on market data and is intended to provide a general guideline for the position. Actual compensation may vary depending on factors such as experience, qualifications, skills, internal equity, and geographic location. The final offer will be determined through a comprehensive evaluation during the hiring process. $90,000-$120,000