Do you enjoy getting hands-on with complex security investigations rather than simply triaging alerts? Are you confident working across Microsoft Defender, Sentinel and KQL to understand what is really happening behind an event? Do you know when to investigate independently and when an incident needs to be escalated?
CFA Institute is looking for a Security Operations Analyst II to join our Security Operations Center and strengthen our in-house cybersecurity capability. You will operate as a highly capable security analyst across monitoring, investigation, incident response and threat hunting, working between our managed security service and senior Security Operations specialists.
You will join at an important point for the team, taking meaningful ownership of day-to-day security operations while helping us continue to mature areas including proactive threat hunting and investigative capability.
What You’ll Do
- Investigate security alerts and events across endpoints, identities, email, cloud services and network infrastructure, determining whether activity is malicious or legitimate.
- Use Microsoft Defender XDR, Microsoft Sentinel and KQL to investigate suspicious activity, correlate telemetry and identify indicators of compromise and attacker behaviours.
- Independently own routine and moderately complex investigations, determining scope, severity and potential business impact and escalating when specialist or senior support is required.
- Review escalated security cases and work closely with our managed security service provider and senior analysts to ensure investigations are thorough and appropriately handled.
- Support incident response across identification, investigation, containment and recovery, including collecting and analysing evidence to establish investigative timelines.
- Investigate phishing, suspicious email activity, credential compromise and cloud or identity-related security events.
- Contribute to the development of more proactive threat-hunting capability, using security telemetry and investigative queries to identify potential threats.
- Recommend improvements to detection coverage, hunting queries, playbooks and investigation procedures based on what you uncover.
- Translate technical findings into clear, useful information for technical and non-technical stakeholders, including contributing to executive-ready security briefings when required.
- Participate in a rotational on-call schedule supporting significant or time-sensitive security incidents.
What We’re Looking For
- Hands-on professional experience within a Security Operations Center, cybersecurity operations or a closely related technical security environment.
- Practical experience with Microsoft Defender and/or Microsoft Sentinel, with the ability to use the Microsoft security environment as part of real investigations.
- Hands-on experience using KQL to query security data, investigate suspicious activity or support threat hunting.
- Strong understanding of SIEM and EDR/XDR technologies and how their telemetry is used during an investigation.
- Demonstrable experience investigating security alerts and incidents across areas such as endpoints, identity, email and cloud environments.
- Experience investigating phishing, suspicious email activity and potential credential compromise.
- The technical judgment to work independently through complex or ambiguous situations while recognising when escalation is the right course of action.
- Understanding of incident-response processes, security investigation methodologies and attacker tactics and techniques, including familiarity with MITRE ATT&CK.
- Strong communication skills, including the ability to turn detailed technical findings into clear information for different audiences.
- A curious, continuously learning approach to cybersecurity and a genuine interest in keeping pace with emerging threats, technologies and investigative techniques.
Why Join Us
- Join an in-house Security Operations team where you will have meaningful ownership of investigations rather than operating solely within an initial alert queue.
- Work across a broad security control environment, with significant hands-on exposure to Microsoft security technologies.
- Help strengthen and mature CFA Institute’s proactive threat-hunting and broader Security Operations capability.
- Work closely with experienced security specialists and contribute to investigations that have visibility across technology and senior leadership.
- Gain exposure to evolving areas of the security portfolio, including threat intelligence, data protection and brand protection.
- Join at a point where the Security Operations function is evolving, giving you the opportunity to contribute to how its capabilities, detections and investigative practices develop.
At CFA Institute, we are committed to transparency and equity in our hiring process. In compliance with wage transparency laws in many of the jurisdictions in which we recruit, we provide the following information regarding compensation for this position:
Expected salary range: US - $83,000 - $110,000 per year.
All salary ranges are subject to adjustment based on experience, education, and other factors relevant to the position. Additional benefits include eligibility for an annual incentive bonus, a 12% employer contribution to a 401(k) or pension plan, and a comprehensive medical benefits package.
We offer a comprehensive benefits package to support our employees, including health coverage, generous time off, competitive retirement plans, flexible work options, and wellbeing and development programs. You can learn more on our careers site: Working at CFA Institute | Comprehensive Benefits
}