Job Description:Role OverviewThe Senior Cybersecurity Analyst is a hands-on, senior individual contributor within Fluence's Global Cybersecurity team, responsible for detecting, investigating, and responding to threats across our corporate, cloud, and product environments. Working primarily in Microsoft Sentinel and Microsoft Defender XDR, this person leads complex, multi-telemetry investigations, drives proactive threat hunting informed by threat intelligence, and turns lessons learned into stronger detections, automation, and preventive controls. The role partners daily with IT infrastructure, DevOps, risk and compliance, and business teams, and interacts with managed service and vendor partners during escalations. The ideal candidate brings at least five years of security operations experience, deep hands-on skill with Microsoft security tooling and query languages such as KQL, a strong automation mindset, and a clear track record of taking ownership of incidents and improvement initiatives from start to finish. The Senior Cybersecurity Analyst also mentors junior analysts and helps set the technical standard for how the security operations team works.
Key ResponsibilitiesThreat Monitoring, Detection and Investigation- Conduct threat monitoring and analysis using threat detection, investigation and response (TDIR) tooling, including security information and event management (SIEM) and extended detection and response (XDR) platforms such as Microsoft Sentinel and Microsoft Defender XDR.
- Lead multi-telemetry investigations across endpoint, identity, email, network, and cloud signals to identify threats originating inside and outside the organization.
- Triage alerts from detection platforms, eliminate false positives, and escalate confirmed attacks with clear, evidence-based findings.
- Drive advanced, hypothesis-led threat hunting using KQL and current threat intelligence on adversary tactics, techniques, and procedures.
- Operationalize threat intelligence by translating indicators, campaign reporting, and MITRE ATT&CK mappings into hunts, detections, and briefings for stakeholders.
- Maintain and extend cloud security monitoring, including the integration of cloud telemetry into SIEM and XDR platforms.
- Perform analysis and testing to identify vulnerabilities, misconfigurations, and other exposures, and to validate the effectiveness of user and security policies.
Incident Response, Root Cause Analysis and Reporting- Take end-to-end ownership of assigned incidents, from first alert through containment, eradication, recovery, and closure, keeping stakeholders informed at every step.
- Document formal technical incident reports for infrastructure teams and senior leadership, including timelines, impact, and evidence.
- Provide infrastructure teams with incident support, including mitigating actions to contain activity and advisory guidance for remediation.
- Carry out root cause analysis and follow-up investigations to recommend prevention mechanisms and configuration changes, and track those actions to completion.
- Support the development and delivery of reporting for compliance and infrastructure teams, as well as performance reporting for the security operations team.
- Develop and present security metrics and incident trends to senior leadership, with clear recommendations.
- Work efficiently to meet Fluence-specific SOC metrics and service level agreements.
Detection Engineering and Automation- Partner with detection content development teams to tune existing detections and create new detection content that reduces noise and improves coverage.
- Design and build automation using scripting (PowerShell, Python) and security orchestration tooling such as Logic Apps or comparable SOAR platforms to accelerate triage, enrichment, and response.
- Own the lifecycle of assigned detection and automation use cases, including requirements, testing, documentation, and measurable outcomes.
- Recommend improvements to security architecture, controls, and processes based on root cause analysis, testing results, and emerging threats.
Security Awareness, Training and Simulation Campaigns- Own the day-to-day management of the security awareness and training program, including the annual campaign calendar, content selection, and communications to employees and contractors.
- Design and run phishing and social engineering simulation campaigns using platforms such as Hoxhunt, Microsoft Defender for Office 365 Attack Simulation Training, or comparable tools, including scenario selection, targeting, scheduling, and follow-up.
- Manage training assignments through the learning management system, including role-based and risk-based curricula, onboarding and annual refresher courses, due dates, reminders, and escalation for overdue completions.
- Automate the assignment and tracking of training by integrating awareness platforms with identity and HR data sources so that curricula stay aligned to department, role, and manager hierarchy.
- Build and deliver awareness reporting, including simulation click and report rates, repeat-clicker trends, completion rates, and audit-ready evidence for compliance and certification requirements.
- Deliver targeted training and coaching for high-risk groups and individuals identified through simulation results, incidents, or user-reported phishing trends.
- Use incident and threat intelligence findings to keep awareness content current, and continuously improve campaign design based on measured outcomes and employee feedback.
- Partner with HR, Legal, Communications, and business leaders to align awareness activities with company policies, onboarding processes, and regional requirements.
Leadership, Collaboration and Continuous Improvement- Lead and mentor junior analysts in threat detection, investigation, and incident response, including case reviews and hands-on coaching.
- Act as escalation point and incident lead during major investigations, coordinating technical workstreams and communications.
- Collaborate with IT, risk, compliance, and business units to ensure holistic security coverage across corporate, cloud, and product environments.
- Participate in and lead incident simulations, tabletop exercises, and red, blue, and purple team activities.
- Maintain current knowledge of security technologies, attacker techniques, and mitigations, and share that knowledge across the team.
- Foster a culture of continuous improvement and professional development within the security operations team.
Required Qualifications- Bachelor's or master's degree in computer science, information security, cybersecurity, or a related field, or equivalent practical experience.
- Minimum 5 years of experience in security operations analysis, incident response, red teaming, penetration testing, IT audit, network operations, or enterprise risk management, with a majority of that time in a hands-on security operations role.
- Minimum 4 years of experience working with regulatory compliance and information security management frameworks such as ISO 27001, NIST CSF, or NIST SP 800-53.
- Hands-on experience monitoring and operating SIEM platforms, with demonstrated depth in Microsoft Sentinel, including analytics rules, workbooks, and data connectors.
- Hands-on experience with Microsoft Defender XDR (Defender for Endpoint, Identity, Office 365, and Cloud Apps) and with network and security technologies such as firewalls and IDS/IPS.
- Strong hands-on skills with analytical and query tools, including Kusto Query Language (KQL), SQL, and Microsoft Excel, to support investigations, alert analysis, reporting, and continuous detection improvement.
- Demonstrated experience building automation for security operations using scripting such as PowerShell or Python and orchestration tooling such as Logic Apps or a comparable SOAR platform.
- Practical experience applying threat intelligence, including adversary tracking, indicator management, and MITRE ATT&CK-based analysis, to detection and response work.
- Hands-on experience configuring and using vulnerability assessment technologies such as Tenable or Nessus.
- Experience managing security work and incidents through ticketing and workflow platforms such as ServiceNow or Jira.
- Hands-on experience running security awareness and training programs, including phishing simulation platforms such as Hoxhunt or Attack Simulation Training, learning management system administration, training assignment tracking, and campaign reporting.
- CompTIA CySA+ or Microsoft Certified: Security Operations Analyst Associate (SC-200), or an equivalent certification.
- Demonstrated ownership mindset, with a track record of driving investigations and improvement initiatives to completion with limited supervision.
- Strong report writing, investigative technique, and communication skills, including the ability to present technical findings to large and non-technical audiences.
Preferred Qualifications- Master's degree in cybersecurity, information security, or a related technical field.
- Additional certifications such as GCIA, GCIH, GCFA, GCTI, CISSP, or Microsoft SC-100.
- Experience securing and monitoring cloud environments such as Azure, GCP, or AWS, including onboarding cloud telemetry into a SIEM.
- Experience with detection-as-code practices, version control, and CI/CD pipelines for security content.
- Exposure to operational technology or industrial control system environments, ideally in energy, utilities, or manufacturing.
- Experience mentoring analysts or leading a shift, queue, or major incident bridge.
- Experience working with managed security service providers or global, follow-the-sun SOC models.
Key Competencies- Ownership and accountability, taking full responsibility for investigations, actions, and outcomes from start to finish.
- Strong decision-making under pressure, with a proven ability to weigh the relative costs and benefits of potential actions and select the most appropriate one.
- Influence and stakeholder engagement, with the ability to shape the opinions, plans, and behaviors of technical and business partners.
- Strong problem-solving, critical thinking, and troubleshooting skills applied to complex, incomplete, or conflicting evidence.
- Automation and continuous improvement mindset, consistently looking for ways to remove manual effort and strengthen controls.
- Business alignment, demonstrated through a clear understanding of Fluence's mission, values, and goals and consistent application of that knowledge.
Collaboration and mentorship, establishing and maintaining effective working relationships and developing others on the team.