Security Analyst, MXDR
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Security Management & Operations
Cybersecurity for the public good.
At nu Harbor, we help organizations navigate an increasingly complex cybersecurity landscape with confidence. By combining expert guidance, innovative technology, and trusted partnerships, we make security stronger, more effective, and easier to understand. We're looking for talented individuals who are passionate about solving meaningful challenges, helping clients succeed, and continuously improving alongside a team that values curiosity, collaboration, and impact.
The OpportunityThe Security Analyst, MxDR, is a core member of nu Harbor’s MxDR delivery team, responsible for the full-lifecycle triage, investigation, and disposition of security alerts and incidents across our supported MxDR environments. The Analyst drives each case to a defensible, evidence-based disposition, escalating per defined criteria and documenting findings clearly enough for the next person in the chain to act on.
This is not a passive alert-monitoring role: it demands sound investigative judgement under time pressure, disciplined documentation, and good calibration on when to elevate versus resolve.
This role operates within a 24x7 service delivery model, where high severity incidents require rapid response at any time and analysts are expected to manage a dynamic queue of concurrent alerts across multiple client environments while meeting defined response time objectives.
ShiftMonday - Friday, 3:30pm - 12:00 ET
What Success Looks LikeIn this role, you will focus on:
- Security Monitoring & Investigation
- Review, analyze and investigate security alerts and incidents in Microsoft Defender and Sentinel environments.
- Identify and assess indicators of compromise (IOC) and attack (IOA) across client environments
- Drive incidents through full lifecycle: triage -> investigation -> disposition -> escalation or closure
- Accurately triage and classify alerts, minimizing false positives while preserving visibility into real threats and document outcomes to support continuous improvement and quality review.
- Incident Response & Escalation
- Execute incident response procedures aligned to defined playbooks and client escalation plans
- Escalate incidents that meet client escalation criteria with documented evidence, impacted entities, and investigation summary.
- Support containment actions (e.g., isolate endpoints, kill processes) when access allows
- Partner with client SOC or IT teams when additional enrichment or remediation is required
- Actively balance accuracy vs. urgency in escalation decisions
- SLO Operations
- Meet defined SLOs for alert triage start, investigation updates, and case closure, with elevated response standards for high-severity and 24x7 priority incidents.
- Prioritize and respond to high severity incidents during second shift, in alignment with 24x7 response requirements and defined SLOs. Reprioritize and update investigations when incident severity changes, ensuring timely escalation and accurate documentation
- Detection Tuning & Continuous Improvement
- Evaluate alert quality and recommend tuning or suppression of non-actionable detections
- Review and improve analytics rules, queries, and detection logic
- Identify gaps in visibility, logging, or detection coverage
- Contribute to development of playbooks, automation, and operational processes
- Client Communication & Reporting
- Document all investigations, findings, and actions in service desk systems
- Provide timely updates through ticketing platforms and escalation channels
- Support regular reporting on:
Incident trends, Environment health, Open cases and outcomes - Participate in client calls, reviews, and quarterly business reviews as needed
- Autonomy & Ownership
- Operate independently in a fast-paced environment, managing multiple investigations simultaneously
- Make informed decisions with incomplete data and limited client context
- Proactively identify risks, gaps, and opportunities for improvement
- Take ownership of your queue, your clients, and the quality of your work
We're looking for someone who brings these minimum qualifications:
- Bachelor’s Degree and two (2) years of experience in cybersecurity, SOC, MDR or incident response.
- In lieu of a degree, two (2)…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).