Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender

Peraton

Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender Job Locations: US-DC-Washington Requisition ID: View phone number on click.appcast.io Position Category: Information Technology Clearance: Top Secret Responsibilities Position: Tier 2/3 Cyber Security Analyst - Microsoft Sentinel and Microsoft Defender Program: Peraton Federal Strategic Cyber Mission Peraton is seeking an experienced Tier 2/3 Cyber Security Analyst to join our Federal Strategic Cyber Mission program. This role requires a seasoned cybersecurity professional with extensive hands‑on experience implementing, configuring, and operating Microsoft Sentinel and Microsoft Defender security solutions. The ideal candidate will serve as a senior escalation point for complex security incidents, lead advanced threat‑hunting operations, and drive the maturation of detection capabilities across the Microsoft security ecosystem. Incident Detection, Analysis, and Response Detect, classify, process, track, and report cybersecurity events and incidents across the enterprise. Serve as senior escalation point for Tier 1 and Tier 2 triage, conducting in‑depth analysis of complex and coordinated threats in a 24x7x365 environment. Analyze logs from multiple sources (host, EDR, firewalls, IDS, servers) to identify, contain, and remediate suspicious activity. Characterize and analyze network traffic to identify anomalies and potential threats. Perform forensic analysis of host artifacts, network traffic, and email content. Analyze malicious scripts and code to mitigate threats. Conduct malware analysis and develop IOCs to support threat identification and mitigation. Microsoft Sentinel & Defender Engineering and Operations Design, implement, configure, and maintain Microsoft Sentinel SIEM, including workspace architecture, data connectors, and log ingestion pipelines. Develop and tune analytics rules, scheduled queries, NRT rules, and fusion rules to optimize detection fidelity. Create and maintain Sentinel workbooks, hunting queries, and automation playbooks (Logic Apps). Implement and manage Microsoft Defender for Endpoint (MDE), including ASR rules, AIR, policy configuration, and KQL‑based advanced hunting. Configure and operationalize Microsoft Defender for Identity, including sensor deployment, threat‑detection tuning, and lateral movement path analysis. Manage Microsoft Defender for Office 365, including Safe Attachments, Safe Links, anti‑phishing policies, and investigation capabilities. Implement and maintain Microsoft Defender for Cloud for CSPM, workload protection, and cloud‑native threat detection across multi‑cloud environments. Develop custom KQL queries for hunting, detection engineering, and security analytics across M365 Defender and Sentinel. Integrate Sentinel with SOAR, developing automated response playbooks and orchestration workflows. Monitor data connector health, troubleshoot ingestion issues, and optimize log collection. Implement and manage Microsoft Entra ID security capabilities including Conditional Access, Identity Protection, PIM, and access reviews. Threat Hunting & Intelligence Conduct proactive hunts for APTs using Sentinel and MDE hunting capabilities. Integrate and operationalize threat intelligence within Sentinel to enhance detection. Analyze threat intelligence reporting and apply adversary methodology knowledge to improve detection posture. Map detections and hunting hypotheses to MITRE ATT&CK and D3FEND frameworks. Collaboration & Reporting Collaborate with customer teams to investigate and respond to events and incidents. Monitor and respond via SOAR, hotline, and designated email inboxes. Create tickets and initiate workflows in accordance with SOPs. Coordinate and report incident information to CISA as required. Engage with local, national, and international CIRTs as directed. Submit alert tuning requests and lead ongoing detection engineering efforts. Mentor and provide technical guidance to Tier 1 and Tier 2 analysts on Microsoft security tools and incident response processes. Qualifications Minimum Requirements Education & Experience: Bachelor's degree and a minimum of 5 years of cybersecurity experience, OR a high school diploma and 9 years of cybersecurity experience. Minimum 3 years of hands‑on experience implementing and operating Microsoft Sentinel (workspace deployment, analytics rule development, workbook creation, playbook automation). Minimum 3 years of experience implementing and managing Microsoft Defender solutions (Defender for Endpoint, Defender for Identity, Defender for Office 365, and/or Defender for Cloud). Certifications: Must possess (or be able to obtain prior to start date) at least one of the following; continued certification is required as a condition of employment: CCNA‑Security; CND; CySA+; GICSP; GSEC; Security+ CE; SSCP Technical Skills Extensive proficiency in Kusto Query Language (KQL) for advanced detections, hunting queries, and Sentinel/M365 Defender analytical workbooks. Experience designing and implementing Microsoft Sentinel analytics rules (scheduled, NRT, fusion). Proven experience deploying and managing Microsoft Defender for Endpoint (policy configuration, ASR rules, AIR, live response). Experience with Microsoft Defender for Identity (sensor deployment, detection tuning, identity‑based investigations). Demonstrated experience across the full Incident Response lifecycle (Preparation through Lessons Learned). Knowledge of SOAR platforms and automated response systems (ServiceNow, Splunk SOAR, Sentinel Playbooks/Logic Apps). Experience with SIEM platforms (Sentinel, Splunk, Elastic, QRadar). Experience with EDR solutions (MDE, ElasticXDR, CarbonBlack, CrowdStrike). Knowledge of cloud security monitoring and incident response, especially in Azure. Ability to integrate IOCs and track APT actor activity. Ability to analyze threat intelligence and understand adversary techniques. Knowledge of static and dynamic malware analysis techniques. Knowledge of MITRE ATT&CK and D3FEND frameworks and ability to map detections. Clearance & Citizenship U.S. Citizenship required. Ability to obtain a Top Secret security clearance. Preferred Qualifications Microsoft SC200 (Security Operations Analyst) – highly preferred Microsoft SC100 (Cybersecurity Architect) Microsoft AZ500 (Azure Security Engineer) Microsoft SC300 (Identity and Access Administrator) Experience architecting multitenant or multiworkspace Sentinel environments Experience with Sentinel content hub solutions and custom content development Proficiency with Microsoft Defender for Cloud workload protection across Azure, AWS, and GCP Experience developing Logic Apps and Power Automate flows for security automation Proficiency with Splunk for monitoring, alerting, and threat hunting Knowledge of Microsoft Azure/Entra ID access and identity management (Conditional Access, PIM, Identity Protection) Experience with digital forensics tools (Autopsy, Magnet Forensics, KAPE, CyLR, Volatility, Zimmerman tools) Experience with ServiceNow SOAR for automated ticketing and response Proficiency in Python, PowerShell, and Bash for automation and tool development Ability to perform static/dynamic malware analysis and reverse engineering Experience integrating cyber threat intelligence and IOC‑based hunting into Sentinel TI module Experience leading purple team exercises and translating findings into actionable detections Preferred Certifications Microsoft: SC200, SC100, AZ500, SC300, SC900 Industry: SecurityX/CASP+, CySA+, Cloud+, GCIH, GCIA, GCFA, GNFA, GREM, GEIR, CCSP, CCSK, CHFI, GCLD, PRMP Practical: TryHackMe SAL1, HackTheBox CDSA, CyberDefenders CCD EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law. #J-18808-Ljbffr Peraton

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender in Washington DC vacancy
  • Peraton is seeking an experienced Tier 2/3 Cyber Security Analyst to enhance its Federal Strategic Cyber Mission program in Washington, DC. The role focuses on implementing Microsoft Sentinel and Microsoft Defender, analyzing cybersecurity incidents, and leading advanced... 
    Microsoft

    Peraton

    Washington DC
    1 day ago
  •  ...manage enterprise mobility solutions in a federal IT environment. This role involves providing Tier 2/3 support, maintaining mobile device management solutions like Microsoft Intune and Jamf, and ensuring high operational efficiency. The ideal candidate should have at least... 
    Microsoft

    The Britton Group

    Washington DC
    2 days ago
  • Tier 2 / Tier 3 IT Support Specialist job at Parallel Partners. Washington DC. Job Description Tier 2 / Tier 3 IT Support Specialist We...  ...Provide escalated IT support. - Troubleshoot Windows 10/11, Microsoft 365 applications, VPNs, printers, and peripherals. - Support... 
    Microsoft
    Remote work

    Payfuture Technologies

    Washington DC
    3 days ago
  •  ...experienced and motivated Service Desk Tier 2-3 Lead ~~~ Position contingent upon contract...  ...in hybrid role. Datawiz delivers secure, ITIL-aligned Tier 1-3 IT support services...  ...: Windows and macOS operating systems Microsoft 365 enterprise services Mobile platforms... 
    Microsoft
    Contract work
    Temporary work
    Local area
    Remote work
    Flexible hours

    Gtsc

    Washington DC
    3 days ago
  • Aretec, Inc. is seeking a Tier 2 Analyst in Washington, DC. This role involves supporting enterprise SOC operations, reviewing escalated tickets...  ...must have a Bachelor's degree or equivalent experience, 3+ years in the field, and must hold an active Secret clearance.... 
    Suggested
    Remote job
    Flexible hours

    Aretec, Inc.

    Washington DC
    1 day ago
  •  ...Cyber Threat Management Specialist Nightwing...  .... The Tier 2 Analysts perform deep-dive...  ...efforts to identified security incidents...  ...measures Deploy Sentinel 1 agents efficiently...  ...including Microsoft Defender for Cloud Apps, Defender...  ...: ~3+ years IT security... 
    Microsoft
    Work at office

    Nightwing

    Falls Church, VA
    2 days ago
  •  ...Job Description Clearance: Public Trust Tier 2 clearance level is required...  ...designing, implementing, and maintaining secure network architectures that enforce Zero Trust...  ...operations, while collaborating with cloud, Microsoft engineering, and cybersecurity teams.... 
    Microsoft
    For contractors
    Work at office

    Ohm Systems, Inc

    Washington DC
    4 days ago
  • $140k - $160k

     ...anytime, anywhere, securely. We combine technical...  ...seeking an experienced Tier 2 Shift Lead for the Cyber Incident Response...  ...ServiceNow, Splunk SOAR, Microsoft Sentinel). Experience with...  ...(e.g., Microsoft Defender for Endpoint,...  ...appraised at CMMI Level 3 for Services and Development... 
    Microsoft
    Contract work
    Local area
    All shifts
    Shift work

    SkyePoint Decisions

    Beltsville, MD
    18 days ago
  • $55.2k - $126k

    Booz Allen Hamilton is seeking a Security Operations Center Analyst to monitor and mitigate cyber threats for a federal regulatory agency. This role requires...  ...in real time, using tools such as Splunk and Microsoft Sentinel. A Bachelor's degree and experience in SOC operations... 
    Microsoft

    Booz Allen Hamilton

    Washington DC
    1 day ago
  •  ...Senior Cyber Security Analyst Work Location: Hybrid (3 days onsite / 2 days remote) Role Description: The Senior Cyber Security Analyst is responsible...  ...technology tools such as CheckPoint, Azure, Microsoft Entra, Defender, and Purview. Preferred Education... 
    Microsoft
    Remote work

    E-talentnetwork

    Washington DC
    4 days ago
  • $258 - $314 per day

     ...Job Posting: June 2, 2026 Closing...  ...CONSULTANCY Information Security Consultant - Security...  ...Management Analyst PAHO is searching...  ...technologies such as Microsoft Sentinel, Microsoft Defender suite, Varonis, and Qualys...  ...DESCRIPTION OF DUTIES: 3. Duties and... 
    Microsoft
    Daily paid
    Full time
    Contract work
    For contractors
    Work at office

    Pan American Health Organization

    Washington DC
    3 days ago
  • $160k - $175k

     ...Solutions is seeking a Network Engineer (Tier 3) to support a contract with the Department of Energy and the National Nuclear Security Agency (NNSA). This position is fully onsite...  ...response. Solid understanding of Layer 2/3 networking, subnetting, encryption, and... 
    Contract work

    Piper Companies

    Washington DC
    2 days ago
  • $140k - $180k

     ...Solutions is looking for a CLEARED Tier 3 Network Engineer to join...  ..., load balancers, and security devices. Monitor and analyze...  ...network engineering, network analyst, network administrator, system...  ...cism, iat level ii, iat level 2, routing protocols, omp, ospf... 
    Full time

    Piper Companies

    Washington DC
    2 days ago
  • $60k - $72k

     ...ITS Tier 2 Support Technician (Crystal City, VA) ITS Tier 2 Support Technician Security Clearance Required Salary Range: $60,000 to $72,...  ...accredited college or university, OR 3+ years of related...  ...equivalent ITSM platform) and Microsoft SCCM. • Active Secret clearance... 
    Microsoft
    Full time
    Contract work
    Work at office

    OPS TECH ALLIANCE LLC

    Arlington, VA
    1 day ago
  •  ...Service Desk Agent, Tier 2 GTSC seeks experienced and motivated Service Desk...  ...performed in hybrid role. GTSC delivers secure, ITIL-aligned Tier 1–3 IT support services to Federal...  ...imaging and device configuration, support Microsoft 365 and enterprise applications,... 
    Microsoft
    Full time
    Temporary work
    Remote work

    GTSC Talent Solutions (a GTSC Company)

    Washington DC
    3 days ago
  •  ...degree and at least 2 years of...  ...ServiceNow, Splunk SOAR, Microsoft Sentinel). Demonstrated...  ...with using Security Information and Event...  ...Ability to analyze cyber threat...  ...Proficiency with Microsoft Defender for Endpoint and...  ...experienced CIRT Tier 2 Analyst to join Peratons'... 
    Microsoft
    Local area
    Shift work

    Peraton

    Beltsville, MD
    1 day ago
  •  ...experienced and motivated Service Desk Agents, Tier 2. ~~~ Position contingent upon...  ...Description Datawiz delivers secure, ITIL-aligned Tier 1–3 IT support services to Federal Government...  ...and device configuration. Support Microsoft 365 and enterprise applications.... 
    Microsoft
    Contract work
    Temporary work
    Local area
    Remote work
    Flexible hours

    Datawiz

    Washington DC
    1 day ago
  •  ...Desktop Support Technician - TIER 2 to provide hands‑on support for...  ...computing devices within a secure federal environment. This role...  ...business applications Support Microsoft 365 applications and related end...  ...AND QUALIFICATIONS 2-3 years of experience in desktop... 
    Microsoft
    Work at office
    Local area

    InquisIT LLC

    Alexandria, VA
    1 day ago
  • ## Tier 3 Service Desk LeadApplylocations: Washington, DCtime type: Full timeposted on: Posted...  ...troubleshooting and administration across Microsoft 365, Azure, Active Directory, and...  ...-tier operations.* Mentor Tier 1 and Tier 2 personnel and support technical training... 
    Microsoft
    Full time
    Contract work

    Diné Source, LLC

    Washington DC
    1 day ago
  •  ...Overview Tier 2 Help Desk Analyst Arlington, VA Are you ready to enhance...  ...to sustain national security and provide services to our...  ...with ticket escalation to Tier 3 support or other specialized...  ...Ability to troubleshoot Microsoft products including, but not... 
    Microsoft
    Work at office
    Local area
    Remote work

    SecuriGence LLC

    Arlington, VA
    10 days ago
  •  ...Ignite IT is seeking a Tier 2 Desk Side Support Specialist to provide...  ...have a Bachelor’s degree, 3+ years of experience supporting...  ..., and group policies in Microsoft 365 and Active Directory. ·...  ...· Ensure compliance with IT security policies, standards, and procedures... 
    Microsoft
    Temporary work
    Work at office
    Remote work
    Flexible hours

    Ignite IT

    Washington DC
    3 days ago
  • TCG is seeking an Application Support / Tier 3 Help Desk Analyst to join a project team supporting a Federal agency in Washington, DC. The successful candidate will develop expertise in a complex business application and handle troubleshooting requests from users. This... 

    TCG

    Washington DC
    2 days ago
  • $107.9k - $195.05k

     ...experienced M365 Security and Compliance Administrator...  ...compliance of the Microsoft 365 (M365)...  ...protections to defend against evolving threats...  ...(Defender / Sentinel) Lead integration...  ...collaboration Provide Tier 3 troubleshooting...  ...collaboration (Cyber, Ops, EA, ICAM, Comms... 
    Microsoft
    Night shift
    Day shift

    Koitecc Solutions

    Washington DC
    5 days ago
  • $31.25 per hour

     ...company, is seeking a Tier 3 Help Desk Support Engineer...  ...totaling 80 hours/2 weeks. We offer competitive...  ...system patches and security vulnerability updates to...  ...tools (currently Microsoft System Center Configuration...  ...Details Job Family: IT, Cyber Security, Network... 
    Microsoft
    Hourly pay
    For contractors
    Work at office
    Local area
    Remote work
    Flexible hours
    3 days per week

    Koniag Government Services

    Washington DC
    5 days ago
  •  ...seeking an  to serve as Tier 2 - Senior Desk Side IT Specialist...  ...to ensure reliable and secure operations. Salary...  ...~Collaborate with Tier 3, Network, and Security...  ...OS, Active Directory, Microsoft 365, SCCM, Intune, and AVD...  ..., Cloud Solutions, Cyber Security, and IT Managed... 
    Microsoft
    Full time
    Remote work

    ActioNet

    Washington DC
    1 day ago
  • RIVA Solutions Inc. is seeking a Tier 3 Service Desk Lead in Washington, DC to provide expert technical support and leadership for a...  ...of service delivery. The role demands extensive experience with Microsoft 365, Azure services, and advanced Active Directory... 
    Microsoft

    RIVA Solutions Inc.

    Washington DC
    3 days ago
  •  ...ActioNet is seeking a Tier 2 - Desk Side Support -...  ...have a Bachelor's degree, 3+ years of experience...  ...and group policies in Microsoft 365 and Active Directory...  ...Ensure compliance with IT security policies, standards,...  ...Engineering, Cloud Solutions, Cyber Security, and IT... 
    Microsoft
    Full time
    Work at office
    Remote work

    ActioNet

    Washington DC
    4 days ago
  • $26.44 per hour

     ...Services company, is seeking a Tier 2 Help Desk Engineer to...  ...Washington, DC a minimum of three (3) days per week - 80 hours...  ...as CompTIA A+ certification, Microsoft Certified Solutions Expert (MCSE...  ...2 Job Details Job Family IT, Cyber Security, Network Systems Job Function... 
    Microsoft
    Hourly pay
    Work at office
    Local area
    Relocation
    Flexible hours
    Shift work
    3 days per week

    Koniag Government Services

    Washington DC
    5 days ago
  • RIVA Solutions, Inc is seeking an experienced Tier 3 Service Desk Lead in Washington, DC. You will spearhead technical support and leadership...  ...teams. The ideal candidate has hands-on experience with Microsoft 365, Azure services, and Active Directory. You will play a... 
    Microsoft

    RIVA Solutions, Inc

    Washington DC
    4 days ago
  •  ...Washington, D.C. to lead Linux engineering efforts and provide Tier 3 support. The role involves system installation, maintenance, and...  ...options. Experience with technical environments including Microsoft, Linux, and various monitoring tools is essential. #J-18808-Ljbffr... 
    Microsoft
    Remote work

    6AM City, LLC

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender. Be the first to apply!