Skip to main content
Posted 07 August, 2026

CYBERSECURITY ANALYST II

Widenet Consulting
Seattle, WA, US Full Time

Job Description

Job Description: Location: This position is remote within the US. Overview of Role: The Cybersecurity Analyst II will support day-to-day Cybersecurity operations, alert investigation, incident response, detection tuning, reporting, implementation support, and documentation with limited supervision. The role is hands-on and delivery-focused, and requires the analyst to independently triage ambiguous security events, coordinate with IT partners, recommend risk-based actions, and help mature repeatable security processes. Requirements: – Perform daily security operations by proactively monitoring the environment to detect, analyze, and help mitigate cyber threats. – Review, investigate, and respond to real-time alerts across SIEM, EDR/XDR, email security, identity, network, cloud, and other security platforms. – Support cybersecurity incident response by gathering evidence, documenting timelines, coordinating containment/mitigation activity, and communicating status clearly. – Configure, maintain, monitor, and tune security tools to improve detection fidelity and reduce recurring false positives. – Translate IT security strategy into tactical work items, runbooks, use cases, reporting, and control improvements. – Work across infrastructure, endpoint, cloud, network, application, and business teams to implement practical, risk-based security controls. – Create reporting and metrics that demonstrate security program health, operational trends, investigation outcomes, and opportunities for improvement. – Develop or implement scripts, queries, dashboards, or open-source/third-party tools that improve detection, prevention, analysis, reporting, or workflow efficiency. – Lead small security workstreams or discrete implementation efforts when needed, while escalating architectural or policy decisions appropriately. Education / Experience: – Bachelor’s degree in information security, computer science, or equivalent experience preferred. – Targeting 4 to 6 years of progressive IT/security experience, including hands-on security operations cyber defense, incident response. Must have experience/skills: – Strong hands-on EDR/XDR investigation experience, including endpoint timeline review, suspicious process analysis, containment coordination, and remediation validation. – Strong hands-on SIEM experience, including log analysis, query writing, alert triage, correlation, use-case tuning, and quality improvement of detections. – Experience administering or technically supporting at least one major security platform such as EDR/XDR, SIEM, secure email gateway, phishing simulation platform, vulnerability management tool, identity security tool, or cloud security monitoring platform. – Experience with phishing analysis and email security workflows, including header review, URL/domain/file reputation analysis, user reporting, and response documentation. – Working knowledge of Active Directory and Entra ID/Azure AD security, including users, groups, MFA, conditional access concepts, authentication anomalies, and identity-based investigations. – Practical understanding of incident response phases, evidence handling, containment/eradication/recovery coordination, and post-incident documentation. – Ability to investigate network anomalies and security events across on-premises and cloud environments. – Ability to communicate technical findings to non-technical audiences with clear written summaries, recommendations, and decision-ready context. – Working knowledge of security frameworks and concepts such as NIST, MITRE ATT&CK, least privilege, defense-in-depth, vulnerability management, and ITSM practices. – Ability to operate independently under time pressure, manage multiple priorities, and escalate appropriately when risk or business impact changes. Nice to have experience skills: – PowerShell, Python, SPL, or other scripting/query language experience for automation, detection, and analysis. – Experience creating dashboards or metrics in Power BI or similar reporting/visualization tools. – Familiarity with Microsoft security tooling, Azure security monitoring, AWS/GCP security monitoring, or hybrid cloud security concepts. – Experience building runbooks, detection logic, incident report templates, executive-ready summaries, or security operations process improvements. – Experience with AI model integration for cybersecurity monitoring. – Certifications such as Security+, CySA+, GCIH, GCIA, GCFA, or equivalent practical experience. Pay Range: $50.00 – $57.00 per hour, depending upon experience. Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.