{"id":944594,"url":"https://alion.io/job/nuharbor-security-analyst-mxdr","title":"Security Analyst, MXDR","company":{"id":720298,"name":"Nuharbor","domain":"nuharbor.com","url":"https://alion.io/company/nuharbor","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"junior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Colchester, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":90000,"max":116000,"currency":"USD","period":"year","gross":null,"usd_annual":116000},"salary_estimate":null,"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"Service Desk","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false}],"status":"live","first_seen_at":"2026-08-24T21:13:07Z","employer_posted_date":"2026-08-25","last_verified_at":"2026-09-27T23:05:54Z","board_verified":true,"closed_at":null,"days_open":34,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":34},"description":"Cybersecurity for the public good.\nAt nuHarbor, we help organizations navigate an increasingly complex cybersecurity landscape with confidence. By combining expert guidance, innovative technology, and trusted partnerships, we make security stronger, more effective, and easier to understand. We're looking for talented individuals who are passionate about solving meaningful challenges, helping clients succeed, and continuously improving alongside a team that values curiosity, collaboration, and impact.\nThe Opportunity\nThe Security Analyst, MxDR, is a core member of nuHarbor’s MxDR delivery team, responsible for the full-lifecycle triage, investigation, and disposition of security alerts and incidents across our supported MxDR environments. The Analyst drives each case to a defensible, evidence-based disposition, escalating per defined criteria and documenting findings clearly enough for the next person in the chain to act on. This is not a passive alert-monitoring role: it demands sound investigative judgement under time pressure, disciplined documentation, and good calibration on when to escalate versus resolve.\nThis role operates within a 24x7 service delivery model, where high severity incidents require rapid response at any time and analysts are expected to manage a dynamic queue of concurrent alerts across multiple client environments while meeting defined response time objectives.\nShift\nMonday - Friday, 3:30pm - 12:00 ET\nWhat Success Looks Like \nIn this role, you will focus on: \nSecurity Monitoring & InvestigationReview, analyze and investigate security alerts and incidents in Microsoft Defender and Sentinel environments.\nIdentify and assess indicators of compromise (IOC) and attack (IOA) across client environments\nDrive incidents through full lifecycle: triage -> investigation -> disposition -> escalation or closure\nAccurately triage and classify alerts, minimizing false positives while preserving visibility into real threats and document outcomes to support continuous improvement and quality review.\n\nIncident Response & EscalationExecute incident response procedures aligned to defined playbooks and client escalation plans\nEscalate incidents that meet client escalation criteria with documented evidence, impacted entities, and investigation summary.\nSupport containment actions (e.g., isolate endpoints, kill processes) when access allows\nPartner with client SOC or IT teams when additional enrichment or remediation is required\nActively balance accuracy vs. urgency in escalation decisions\n\nSLO OperationsMeet defined SLOs for alert triage start, investigation updates, and case closure, with elevated response standards for high-severity and 24x7 priority incidents.\nPrioritize and respond to high severity incidents during second shift, in alignment with 24x7 response requirements and defined SLOs. Reprioritize and update investigations when incident severity changes, ensuring timely escalation and accurate documentation\n\nDetection Tuning & Continuous ImprovementEvaluate alert quality and recommend tuning or suppression of non-actionable detections\nReview and improve analytics rules, queries, and detection logic\nIdentify gaps in visibility, logging, or detection coverage\nContribute to development of playbooks, automation, and operational processes\n\nClient Communication & ReportingDocument all investigations, findings, and actions in service desk systems\nProvide timely updates through ticketing platforms and escalation channels\nSupport regular reporting on: Incident trends, Environment health, Open cases and outcomes\nParticipate in client calls, reviews, and quarterly business reviews as needed\n\nAutonomy & OwnershipOperate independently in a fast-paced environment, managing multiple investigations simultaneously\nMake informed decisions with incomplete data and limited client context\nProactively identify risks, gaps, and opportunities for improvement\nTake ownership of your queue, your clients, and the quality of your work\n\nYour Foundation\nWe're looking for someone who brings these minimum qualifications:\nBachelor’s Degree and two (2) years of experience in cybersecurity, SOC, MDR or incident response.In lieu of a degree, two (2) years of experience in a related technology field and relevant industry certifications are required.\n\nDemonstrated experience with SIEM solutions, SOC operations, executing security event triaging and tuning.\nExperience working in SIEM/XDR tools including specifically Microsoft Sentinel or Defender.\nProven ability to independently investigate and triage security events.\nExperience with security event analysis, log correlation, and threat detection.\nExperience with KQL or similar query languages.\nFamiliarity with common endpoint security concepts.\nDemonstrated knowledge of security log, infrastructure design and networking fundamentals.\nUnderstanding of Identity and Access threats.\nStrong investigative mindset with attention to detail.\nAbility to anticipate problems, communicate them, and resolve appropriately.\nDemonstrated verbal and written communication skills for various internal and external audiences.\nMust be a citizen of the United States.\nStand out With\nYou may stand out if you have experience with:\nBachelor’s Degree and five (5) or more years in the Information Technology field.\nHolds relevant industry certificationsCompTIA Security+, CySA+, CISSP, etc.\nMicrosoft Security Operations Analyst (SC-200)\nAzure Security Engineer (AZ-500)\n\nProven experience in a MSSP or multi-client environment\nAbility to conduct multi-step breach and investigative analysis to trace dynamic activities associated with advanced threats.\nExhibit advanced understanding of, and ability to communicate, security technologies that can be used to mitigate cyber risks.\nStrong understanding of Incident Response phases and demonstrated experience responding to security incidents.\nAttention to detail and a methodical approach to standard operating procedures.\nAbility to explain simple hardening methods for network and process detections.\nAbility to manage multiple concurrent objectives or activities and effectively make judgments.\nUnderstanding of common network services and attacks against them.\nWhy nuHarbor?\nAt nuHarbor, you'll find more than a job - you'll find a team committed to helping each other grow, solve meaningful problems, and make a measurable impact.\nYou can expect:\nA collaborative, high-performing team environment\nLeaders who are invested in your success and development\nMeaningful work that helps organizations protect critical services and missions\nThe encouragement to bring your authentic self to work every day\nCompetitive pay, performance-based bonus opportunities, generous paid time off, and comprehensive benefits\nCompensation\nThis position has an anticipated base salary range of $90,000-$116,000 annually and is eligible for a shift premium. Plus, this position is eligible for nuHarbor's annual bonus program with a target opportunity of 10%.\nActual compensation is based on factors including experience, skills, certifications, and geographic location.\nJoin Us\nAt nuHarbor, we believe great security starts with great people. We're looking for curious problem-solvers, trusted advisors, and continuous learners who are passionate about helping clients win.\nIf you're ready to make an impact while growing alongside a team that values people as much as technology, we'd love to hear from you.\nAAP/EEO Statement\nThe Equal Employment Opportunity Policy of nuHarbor is to provide a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religion, national origin, gender, sexual orientation, age, marital status or disability. nuHarbor hires and promotes individuals solely based on their qualifications for the job to be filled.\nnuHarbor believes that employees should be provided with a working environment which enables each associate to be productive and to work to the best of his or her ability. We do not condone or tolerate an atmosphere of intimidation or harassment based on race, color, religion, national origin, gender, sexual orientation, age, marital status, or disability. We expect and require the cooperation of all employees in maintaining a discrimination and harassment-free atmosphere.","description_format":"text","description_chars":8292,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-15T20:00:52Z"}],"liveness":{"score":55,"band":"ok","label":"Likely open","p_open":1,"p_active":0.736,"p_room":0.75,"age_days":33,"expected_fill_days":36,"reasons":["conf:2","win:late","comp:junior"],"computed_at":"2026-09-27T05:45:00Z"},"pay":{"stated_usd_annual":116000,"is_top_pay":true},"html_url":"https://alion.io/job/nuharbor-security-analyst-mxdr","json_url":"https://alion.io/job/nuharbor-security-analyst-mxdr.json","meta":{"generated_at":"2026-09-28T01:13:39Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":787,"day_limit":5000,"remaining_today":4213,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}