Security Operations Analyst II

CFA Institute•Washington, DC
•$83,000 - $110,000

About The Position

CFA Institute is looking for a Security Operations Analyst II to join our Security Operations Center and strengthen our in-house cybersecurity capability. You will operate as a highly capable security analyst across monitoring, investigation, incident response and threat hunting, working between our managed security service and senior Security Operations specialists. You will join at an important point for the team, taking meaningful ownership of day-to-day security operations while helping us continue to mature areas including proactive threat hunting and investigative capability.

Requirements

  • Hands-on professional experience within a Security Operations Center, cybersecurity operations or a closely related technical security environment.
  • Practical experience with Microsoft Defender and/or Microsoft Sentinel, with the ability to use the Microsoft security environment as part of real investigations.
  • Hands-on experience using KQL to query security data, investigate suspicious activity or support threat hunting.
  • Strong understanding of SIEM and EDR/XDR technologies and how their telemetry is used during an investigation.
  • Demonstrable experience investigating security alerts and incidents across areas such as endpoints, identity, email and cloud environments.
  • Experience investigating phishing, suspicious email activity and potential credential compromise.
  • The technical judgment to work independently through complex or ambiguous situations while recognising when escalation is the right course of action.
  • Understanding of incident-response processes, security investigation methodologies and attacker tactics and techniques, including familiarity with MITRE ATT&CK.
  • Strong communication skills, including the ability to turn detailed technical findings into clear information for different audiences.
  • A curious, continuously learning approach to cybersecurity and a genuine interest in keeping pace with emerging threats, technologies and investigative techniques.

Responsibilities

  • Investigate security alerts and events across endpoints, identities, email, cloud services and network infrastructure, determining whether activity is malicious or legitimate.
  • Use Microsoft Defender XDR, Microsoft Sentinel and KQL to investigate suspicious activity, correlate telemetry and identify indicators of compromise and attacker behaviours.
  • Independently own routine and moderately complex investigations, determining scope, severity and potential business impact and escalating when specialist or senior support is required.
  • Review escalated security cases and work closely with our managed security service provider and senior analysts to ensure investigations are thorough and appropriately handled.
  • Support incident response across identification, investigation, containment and recovery, including collecting and analysing evidence to establish investigative timelines.
  • Investigate phishing, suspicious email activity, credential compromise and cloud or identity-related security events.
  • Contribute to the development of more proactive threat-hunting capability, using security telemetry and investigative queries to identify potential threats.
  • Recommend improvements to detection coverage, hunting queries, playbooks and investigation procedures based on what you uncover.
  • Translate technical findings into clear, useful information for technical and non-technical stakeholders, including contributing to executive-ready security briefings when required.
  • Participate in a rotational on-call schedule supporting significant or time-sensitive security incidents.

Benefits

  • Eligibility for an annual incentive bonus
  • 12% employer contribution to a 401(k) or pension plan
  • Comprehensive medical benefits package
  • Health coverage
  • Generous time off
  • Competitive retirement plans
  • Flexible work options
  • Wellbeing and development programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service