Cyber Solution Analyst

The Intersect GroupGreenville, United States
Full TimeOn-siteMidLimited info disclosed
21 views0 applications

Description

Cybersecurity Solutions Analyst Position Summary The Cybersecurity Solutions Analyst is a mid-level technical individual contributor within the IAM/SecOps team responsible for implementing, automating, and supporting cybersecurity solutions, with an emphasis on identity-centric controls, Microsoft security platforms, automation, and durable operational improvements. This role has no direct reports and may provide technical mentorship to Cybersecurity Analysts. The Cybersecurity Solutions Analyst serves as a primary escalation point for Cybersecurity Analysts and escalates complex issues to senior engineering resources as needed. Key Responsibilities Design, test, document, and maintain security automations, scripts, modules, workflows, integrations, and tooling using PowerShell, Python, APIs, Microsoft Graph, and source control . Serve as a primary escalation point for Cybersecurity Analysts and escalate complex issues to senior engineering resources as needed. Troubleshoot complex identity, endpoint, cloud, network access, data protection, monitoring, Microsoft security platform, and security tooling issues. Support incident response activities including investigation, containment, evidence gathering, tool-based analysis, recovery support, documentation, and post-incident improvements. Implement, support, and tune Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, Microsoft Intune, Microsoft 365 security, identity governance, conditional access, privileged access, access reviews, analytics, workbooks, automation rules, and connectors . Configure, integrate, maintain, and improve assigned security platforms, including Sentinel, Netskope, Defender, Intune, Entra ID, privileged access tools, and related technologies . Coordinate security tool integrations, vendor escalations, platform tuning, security platform improvements, managed SOC handoffs, and response partner support. Create and maintain runbooks, knowledge articles, escalation guides, procedures, dashboards, and reusable tools that enable analysts to resolve issues more independently. Analyze recurring tickets, alerts, exceptions, and manual processes and implement durable solutions that reduce manual work, alert noise, and escalation volume. Partner with IAM/SecOps, GRC, Architecture/Engineering, Infrastructure, Helpdesk/Support, vendors, and stakeholders on operational handoffs, documentation, metrics, status updates, and work tracking. Perform other duties as assigned. Required Skills, Experience & Education Relevant certifications such as Microsoft security certifications, Security+, CySA+, GSEC, GIAC , or equivalent experience preferred. 4+ years of hands-on experience in cybersecurity, security operations, identity/security engineering, IT operations, or a related field. Strong PowerShell scripting skills for automation, administration, reporting, and operations. Working knowledge of Python for APIs, integrations, or data handling. Practical experience with Microsoft Entra ID and identity controls such as: Conditional Access Identity Governance Privileged Identity Management Access Reviews Experience with Microsoft Defender, Microsoft Sentinel, Microsoft Intune, Microsoft 365 security capabilities , or comparable security platforms. Ability to troubleshoot complex security, identity, endpoint, and platform issues and translate findings into repeatable procedures or durable solutions. Experience using ticketing, work tracking, documentation, and code repository tools such as ServiceNow, Wrike, GitHub, or similar platforms. Excellent communication and collaboration skills with analysts, engineers, managers, vendors, and non-technical stakeholders. Preferred Skills, Experience & Education Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems , or a related field, or equivalent experience. Experience integrating security tooling through APIs and Microsoft Graph . Familiarity with SIEM/SOAR concepts, managed SOC workflows, automation playbooks, alert tuning, and detection engineering support . Experience with: Netskope Microsoft Defender XDR Microsoft Sentinel Microsoft Intune Entra ID Governance Privileged Identity Management Related identity and security technologies Experience working in healthcare, regulated, multi-entity, or high-growth environments preferred. Work Environment & Schedule Physical Demands Requires sitting for extended periods, more than 66% of the workday (5.5+ hours per day). Travel Minimal travel required, generally less than 5%. Work Schedule & Emergency Response Standard business hours. After-hours work is rare and generally limited to: Scheduled maintenance windows Significant security incidents