Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender
Peraton
Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender Job Locations: US-DC-Washington Requisition ID: View phone number on click.appcast.io Position Category: Information Technology Clearance: Top Secret Responsibilities Position: Tier 2/3 Cyber Security Analyst - Microsoft Sentinel and Microsoft Defender Program: Peraton Federal Strategic Cyber Mission Peraton is seeking an experienced Tier 2/3 Cyber Security Analyst to join our Federal Strategic Cyber Mission program. This role requires a seasoned cybersecurity professional with extensive hands‑on experience implementing, configuring, and operating Microsoft Sentinel and Microsoft Defender security solutions. The ideal candidate will serve as a senior escalation point for complex security incidents, lead advanced threat‑hunting operations, and drive the maturation of detection capabilities across the Microsoft security ecosystem. Incident Detection, Analysis, and Response Detect, classify, process, track, and report cybersecurity events and incidents across the enterprise. Serve as senior escalation point for Tier 1 and Tier 2 triage, conducting in‑depth analysis of complex and coordinated threats in a 24x7x365 environment. Analyze logs from multiple sources (host, EDR, firewalls, IDS, servers) to identify, contain, and remediate suspicious activity. Characterize and analyze network traffic to identify anomalies and potential threats. Perform forensic analysis of host artifacts, network traffic, and email content. Analyze malicious scripts and code to mitigate threats. Conduct malware analysis and develop IOCs to support threat identification and mitigation. Microsoft Sentinel & Defender Engineering and Operations Design, implement, configure, and maintain Microsoft Sentinel SIEM, including workspace architecture, data connectors, and log ingestion pipelines. Develop and tune analytics rules, scheduled queries, NRT rules, and fusion rules to optimize detection fidelity. Create and maintain Sentinel workbooks, hunting queries, and automation playbooks (Logic Apps). Implement and manage Microsoft Defender for Endpoint (MDE), including ASR rules, AIR, policy configuration, and KQL‑based advanced hunting. Configure and operationalize Microsoft Defender for Identity, including sensor deployment, threat‑detection tuning, and lateral movement path analysis. Manage Microsoft Defender for Office 365, including Safe Attachments, Safe Links, anti‑phishing policies, and investigation capabilities. Implement and maintain Microsoft Defender for Cloud for CSPM, workload protection, and cloud‑native threat detection across multi‑cloud environments. Develop custom KQL queries for hunting, detection engineering, and security analytics across M365 Defender and Sentinel. Integrate Sentinel with SOAR, developing automated response playbooks and orchestration workflows. Monitor data connector health, troubleshoot ingestion issues, and optimize log collection. Implement and manage Microsoft Entra ID security capabilities including Conditional Access, Identity Protection, PIM, and access reviews. Threat Hunting & Intelligence Conduct proactive hunts for APTs using Sentinel and MDE hunting capabilities. Integrate and operationalize threat intelligence within Sentinel to enhance detection. Analyze threat intelligence reporting and apply adversary methodology knowledge to improve detection posture. Map detections and hunting hypotheses to MITRE ATT&CK and D3FEND frameworks. Collaboration & Reporting Collaborate with customer teams to investigate and respond to events and incidents. Monitor and respond via SOAR, hotline, and designated email inboxes. Create tickets and initiate workflows in accordance with SOPs. Coordinate and report incident information to CISA as required. Engage with local, national, and international CIRTs as directed. Submit alert tuning requests and lead ongoing detection engineering efforts. Mentor and provide technical guidance to Tier 1 and Tier 2 analysts on Microsoft security tools and incident response processes. Qualifications Minimum Requirements Education & Experience: Bachelor's degree and a minimum of 5 years of cybersecurity experience, OR a high school diploma and 9 years of cybersecurity experience. Minimum 3 years of hands‑on experience implementing and operating Microsoft Sentinel (workspace deployment, analytics rule development, workbook creation, playbook automation). Minimum 3 years of experience implementing and managing Microsoft Defender solutions (Defender for Endpoint, Defender for Identity, Defender for Office 365, and/or Defender for Cloud). Certifications: Must possess (or be able to obtain prior to start date) at least one of the following; continued certification is required as a condition of employment: CCNA‑Security; CND; CySA+; GICSP; GSEC; Security+ CE; SSCP Technical Skills Extensive proficiency in Kusto Query Language (KQL) for advanced detections, hunting queries, and Sentinel/M365 Defender analytical workbooks. Experience designing and implementing Microsoft Sentinel analytics rules (scheduled, NRT, fusion). Proven experience deploying and managing Microsoft Defender for Endpoint (policy configuration, ASR rules, AIR, live response). Experience with Microsoft Defender for Identity (sensor deployment, detection tuning, identity‑based investigations). Demonstrated experience across the full Incident Response lifecycle (Preparation through Lessons Learned). Knowledge of SOAR platforms and automated response systems (ServiceNow, Splunk SOAR, Sentinel Playbooks/Logic Apps). Experience with SIEM platforms (Sentinel, Splunk, Elastic, QRadar). Experience with EDR solutions (MDE, ElasticXDR, CarbonBlack, CrowdStrike). Knowledge of cloud security monitoring and incident response, especially in Azure. Ability to integrate IOCs and track APT actor activity. Ability to analyze threat intelligence and understand adversary techniques. Knowledge of static and dynamic malware analysis techniques. Knowledge of MITRE ATT&CK and D3FEND frameworks and ability to map detections. Clearance & Citizenship U.S. Citizenship required. Ability to obtain a Top Secret security clearance. Preferred Qualifications Microsoft SC200 (Security Operations Analyst) – highly preferred Microsoft SC100 (Cybersecurity Architect) Microsoft AZ500 (Azure Security Engineer) Microsoft SC300 (Identity and Access Administrator) Experience architecting multitenant or multiworkspace Sentinel environments Experience with Sentinel content hub solutions and custom content development Proficiency with Microsoft Defender for Cloud workload protection across Azure, AWS, and GCP Experience developing Logic Apps and Power Automate flows for security automation Proficiency with Splunk for monitoring, alerting, and threat hunting Knowledge of Microsoft Azure/Entra ID access and identity management (Conditional Access, PIM, Identity Protection) Experience with digital forensics tools (Autopsy, Magnet Forensics, KAPE, CyLR, Volatility, Zimmerman tools) Experience with ServiceNow SOAR for automated ticketing and response Proficiency in Python, PowerShell, and Bash for automation and tool development Ability to perform static/dynamic malware analysis and reverse engineering Experience integrating cyber threat intelligence and IOC‑based hunting into Sentinel TI module Experience leading purple team exercises and translating findings into actionable detections Preferred Certifications Microsoft: SC200, SC100, AZ500, SC300, SC900 Industry: SecurityX/CASP+, CySA+, Cloud+, GCIH, GCIA, GCFA, GNFA, GREM, GEIR, CCSP, CCSK, CHFI, GCLD, PRMP Practical: TryHackMe SAL1, HackTheBox CDSA, CyberDefenders CCD EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law. #J-18808-Ljbffr Peraton
- Peraton is seeking an experienced Tier 2/3 Cyber Security Analyst to enhance its Federal Strategic Cyber Mission program in Washington, DC. The role focuses on implementing Microsoft Sentinel and Microsoft Defender, analyzing cybersecurity incidents, and leading advanced...Microsoft
- ...manage enterprise mobility solutions in a federal IT environment. This role involves providing Tier 2/3 support, maintaining mobile device management solutions like Microsoft Intune and Jamf, and ensuring high operational efficiency. The ideal candidate should have at least...Microsoft
- Tier 2 / Tier 3 IT Support Specialist job at Parallel Partners. Washington DC. Job Description Tier 2 / Tier 3 IT Support Specialist We... ...Provide escalated IT support. - Troubleshoot Windows 10/11, Microsoft 365 applications, VPNs, printers, and peripherals. - Support...MicrosoftRemote work
- ...experienced and motivated Service Desk Tier 2-3 Lead ~~~ Position contingent upon contract... ...in hybrid role. Datawiz delivers secure, ITIL-aligned Tier 1-3 IT support services... ...: Windows and macOS operating systems Microsoft 365 enterprise services Mobile platforms...MicrosoftContract workTemporary workLocal areaRemote workFlexible hours
- Aretec, Inc. is seeking a Tier 2 Analyst in Washington, DC. This role involves supporting enterprise SOC operations, reviewing escalated tickets... ...must have a Bachelor's degree or equivalent experience, 3+ years in the field, and must hold an active Secret clearance....SuggestedRemote jobFlexible hours
- ...Cyber Threat Management Specialist Nightwing... .... The Tier 2 Analysts perform deep-dive... ...efforts to identified security incidents... ...measures Deploy Sentinel 1 agents efficiently... ...including Microsoft Defender for Cloud Apps, Defender... ...: ~3+ years IT security...MicrosoftWork at office
- ...Job Description Clearance: Public Trust Tier 2 clearance level is required... ...designing, implementing, and maintaining secure network architectures that enforce Zero Trust... ...operations, while collaborating with cloud, Microsoft engineering, and cybersecurity teams....MicrosoftFor contractorsWork at office
$140k - $160k
...anytime, anywhere, securely. We combine technical... ...seeking an experienced Tier 2 Shift Lead for the Cyber Incident Response... ...ServiceNow, Splunk SOAR, Microsoft Sentinel). Experience with... ...(e.g., Microsoft Defender for Endpoint,... ...appraised at CMMI Level 3 for Services and Development...MicrosoftContract workLocal areaAll shiftsShift work$55.2k - $126k
Booz Allen Hamilton is seeking a Security Operations Center Analyst to monitor and mitigate cyber threats for a federal regulatory agency. This role requires... ...in real time, using tools such as Splunk and Microsoft Sentinel. A Bachelor's degree and experience in SOC operations...Microsoft- ...Senior Cyber Security Analyst Work Location: Hybrid (3 days onsite / 2 days remote) Role Description: The Senior Cyber Security Analyst is responsible... ...technology tools such as CheckPoint, Azure, Microsoft Entra, Defender, and Purview. Preferred Education...MicrosoftRemote work
$258 - $314 per day
...Job Posting: June 2, 2026 Closing... ...CONSULTANCY Information Security Consultant - Security... ...Management Analyst PAHO is searching... ...technologies such as Microsoft Sentinel, Microsoft Defender suite, Varonis, and Qualys... ...DESCRIPTION OF DUTIES: 3. Duties and...MicrosoftDaily paidFull timeContract workFor contractorsWork at office$160k - $175k
...Solutions is seeking a Network Engineer (Tier 3) to support a contract with the Department of Energy and the National Nuclear Security Agency (NNSA). This position is fully onsite... ...response. Solid understanding of Layer 2/3 networking, subnetting, encryption, and...Contract work$140k - $180k
...Solutions is looking for a CLEARED Tier 3 Network Engineer to join... ..., load balancers, and security devices. Monitor and analyze... ...network engineering, network analyst, network administrator, system... ...cism, iat level ii, iat level 2, routing protocols, omp, ospf...Full time$60k - $72k
...ITS Tier 2 Support Technician (Crystal City, VA) ITS Tier 2 Support Technician Security Clearance Required Salary Range: $60,000 to $72,... ...accredited college or university, OR 3+ years of related... ...equivalent ITSM platform) and Microsoft SCCM. • Active Secret clearance...MicrosoftFull timeContract workWork at office- ...Service Desk Agent, Tier 2 GTSC seeks experienced and motivated Service Desk... ...performed in hybrid role. GTSC delivers secure, ITIL-aligned Tier 1–3 IT support services to Federal... ...imaging and device configuration, support Microsoft 365 and enterprise applications,...MicrosoftFull timeTemporary workRemote work
- ...degree and at least 2 years of... ...ServiceNow, Splunk SOAR, Microsoft Sentinel). Demonstrated... ...with using Security Information and Event... ...Ability to analyze cyber threat... ...Proficiency with Microsoft Defender for Endpoint and... ...experienced CIRT Tier 2 Analyst to join Peratons'...MicrosoftLocal areaShift work
- ...experienced and motivated Service Desk Agents, Tier 2. ~~~ Position contingent upon... ...Description Datawiz delivers secure, ITIL-aligned Tier 1–3 IT support services to Federal Government... ...and device configuration. Support Microsoft 365 and enterprise applications....MicrosoftContract workTemporary workLocal areaRemote workFlexible hours
- ...Desktop Support Technician - TIER 2 to provide hands‑on support for... ...computing devices within a secure federal environment. This role... ...business applications Support Microsoft 365 applications and related end... ...AND QUALIFICATIONS 2-3 years of experience in desktop...MicrosoftWork at officeLocal area
- ## Tier 3 Service Desk LeadApplylocations: Washington, DCtime type: Full timeposted on: Posted... ...troubleshooting and administration across Microsoft 365, Azure, Active Directory, and... ...-tier operations.* Mentor Tier 1 and Tier 2 personnel and support technical training...MicrosoftFull timeContract work
- ...Overview Tier 2 Help Desk Analyst Arlington, VA Are you ready to enhance... ...to sustain national security and provide services to our... ...with ticket escalation to Tier 3 support or other specialized... ...Ability to troubleshoot Microsoft products including, but not...MicrosoftWork at officeLocal areaRemote work
- ...Ignite IT is seeking a Tier 2 Desk Side Support Specialist to provide... ...have a Bachelor’s degree, 3+ years of experience supporting... ..., and group policies in Microsoft 365 and Active Directory. ·... ...· Ensure compliance with IT security policies, standards, and procedures...MicrosoftTemporary workWork at officeRemote workFlexible hours
- TCG is seeking an Application Support / Tier 3 Help Desk Analyst to join a project team supporting a Federal agency in Washington, DC. The successful candidate will develop expertise in a complex business application and handle troubleshooting requests from users. This...
$107.9k - $195.05k
...experienced M365 Security and Compliance Administrator... ...compliance of the Microsoft 365 (M365)... ...protections to defend against evolving threats... ...(Defender / Sentinel) Lead integration... ...collaboration Provide Tier 3 troubleshooting... ...collaboration (Cyber, Ops, EA, ICAM, Comms...MicrosoftNight shiftDay shift$31.25 per hour
...company, is seeking a Tier 3 Help Desk Support Engineer... ...totaling 80 hours/2 weeks. We offer competitive... ...system patches and security vulnerability updates to... ...tools (currently Microsoft System Center Configuration... ...Details Job Family: IT, Cyber Security, Network...MicrosoftHourly payFor contractorsWork at officeLocal areaRemote workFlexible hours3 days per week- ...seeking an to serve as Tier 2 - Senior Desk Side IT Specialist... ...to ensure reliable and secure operations. Salary... ...~Collaborate with Tier 3, Network, and Security... ...OS, Active Directory, Microsoft 365, SCCM, Intune, and AVD... ..., Cloud Solutions, Cyber Security, and IT Managed...MicrosoftFull timeRemote work
- RIVA Solutions Inc. is seeking a Tier 3 Service Desk Lead in Washington, DC to provide expert technical support and leadership for a... ...of service delivery. The role demands extensive experience with Microsoft 365, Azure services, and advanced Active Directory...Microsoft
- ...ActioNet is seeking a Tier 2 - Desk Side Support -... ...have a Bachelor's degree, 3+ years of experience... ...and group policies in Microsoft 365 and Active Directory... ...Ensure compliance with IT security policies, standards,... ...Engineering, Cloud Solutions, Cyber Security, and IT...MicrosoftFull timeWork at officeRemote work
$26.44 per hour
...Services company, is seeking a Tier 2 Help Desk Engineer to... ...Washington, DC a minimum of three (3) days per week - 80 hours... ...as CompTIA A+ certification, Microsoft Certified Solutions Expert (MCSE... ...2 Job Details Job Family IT, Cyber Security, Network Systems Job Function...MicrosoftHourly payWork at officeLocal areaRelocationFlexible hoursShift work3 days per week- RIVA Solutions, Inc is seeking an experienced Tier 3 Service Desk Lead in Washington, DC. You will spearhead technical support and leadership... ...teams. The ideal candidate has hands-on experience with Microsoft 365, Azure services, and Active Directory. You will play a...Microsoft
- ...Washington, D.C. to lead Linux engineering efforts and provide Tier 3 support. The role involves system installation, maintenance, and... ...options. Experience with technical environments including Microsoft, Linux, and various monitoring tools is essential. #J-18808-Ljbffr...MicrosoftRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender. Be the first to apply!
- remote cyber security analyst Washington DC
- junior cyber security analyst Washington DC
- cyber security analyst Washington DC
- information security consultant Washington DC
- entry level cyber security analyst Washington DC
- cyber threat intelligence analyst Washington DC
- cyber threat hunter Washington DC
- cyber Washington DC
- manager microsoft dynamics 365 Washington DC
- microsoft engineer Washington DC


