×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Analyst

Job in Winston-Salem, Forsyth County, North Carolina, 27104, USA
Listing for: Katalyst
Full Time position
Listed on 2026-08-17
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below

LOCATION PREFERENCE:

North/South Carolina,

No applications from candidates outside of Eastern Time Zone will be considered.

About the Company

Katalyst Network Group is Your Digital Operations Partner. We Connect, Protect, and Operate Your Digital Backbone, taking accountability for our customers' technology so they can focus on their business. What do you get from Katalyst? An organization that puts a high value on family. A well-documented onboarding plan. A culture that rewards performance and client outcomes. Continuous learning opportunities and professional development.

Full benefits package. We value grit, humility, curiosity, and a strong client-first approach. Candidates who share these values and meet the qualifications outlined below will find strong opportunities for growth and success at Katalyst.

About the Role

This is the top of our Security Analyst/Cyber Defense track. As a Senior Security Analyst, you're the person the team escalates to, who runs the hardest investigations, hunts for what the alerts miss, and owns the response when a real incident hits. You'll work deep in Microsoft Defender XDR and Microsoft Sentinel, building detection content and playbooks that make the whole operation sharper and more proactive.

You'll also set the technical bar. As we build a deep security practice, you'll mentor Tier 1 and Tier 2 analysts, shape how we implement, configure, detect and respond across our customer base, and help stand up the operations that our clients depend on. We take accountability for our customers' security posture and you'll be central to how we deliver on that.

Responsibilities
  • Lead complex investigations across endpoint, identity, email, and cloud as the escalation point for Tier 1 and Tier 2 analysts.
  • Leverage AI technologies and tooling to empower defenses with the latest capabilities for advanced reasoning and automation.
  • Own incident response end to end: scope, contain, eradicate, recover, and lead post-incident reviews.
  • Run proactive threat hunts across customer environments using Microsoft threat intelligence and advanced hunting.
  • Engineer detections - author and tune Sentinel analytics rules, KQL queries, and SOAR/Logic App automation to raise signal and cut noise.
  • Build and maintain the runbooks, playbooks, and escalation paths that standardize how the SOC operates.
  • Mentor and upskill junior analysts with reviews, shadowing, and knowledge sharing.
  • Optimize the Defender and Sentinel deployment - coverage, configuration, and onboarding of new customer tenants.
  • Contribute to the operational maturity behind our Microsoft MXDR verification and SOC 2 readiness.
Qualifications

Required:

  • [5+] years in a SOC, MDR, MSSP, or incident-response role, with demonstrable hands-on Microsoft Defender experience.
  • Deep, practical command of the Microsoft Defender suite - Defender for Endpoint, Identity, Office 365, and Cloud.
  • Strong Microsoft Sentinel skills, including fluent KQL for hunting and detection engineering.
  • Proven managed detection and response experience where you've led investigations through to resolution.
  • Working knowledge of the Microsoft 365 and Azure ecosystem and customer licensing (Business Premium, E3, E5, Defender P1/P2, etc.).
  • Clear communication and sound judgment under pressure, with a track record of mentoring others.
  • A drive to keep learning and to grow with the practice as it scales - we value this at every level.
Preferred

Skills:
  • Detection-engineering or purple-team experience; MITRE ATT&CK fluency.
  • Automation and scripting depth (Power Shell, KQL, Logic Apps / Sentinel SOAR).
  • Experience helping stand up or scale a SOC or MSSP practice.
Certifications
  • SC-200 - Microsoft Security Operations Analyst (expected as our core SOC credential).
  • AZ-500 - Azure Security Engineer Associate (strongly preferred at this level).
  • SC-100 - Cybersecurity Architect Expert (preferred as the senior-track credential we'll help you reach).
  • SC-300 - Identity and Access Administrator, for advanced identity-protection work.
  • Microsoft Defender XDR Applied Skills - hands-on credentials that reinforce day-to-day response.
  • Be a founding technical leader in a new security practice. You set the standards, not inherit them.
  • Go deeper on the Microsoft security stack than most roles allow, with a fully supported certification path.
  • A clear track toward lead, principal, and SOC leadership as the team and customer base grow.
  • 401(k) matching
  • Paid time off
  • Health insurance
  • Vision insurance
Equal Opportunity Statement:

Katalyst is an equal opportunity employer and does not discriminate on the basis of race, color, religion, national origin, sex, physical or mental disability, or age.

#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary