
Security Operations Analyst II
- Microsoft Defender
- CFA
- Incident Response
- Microsoft Sentinel
- SIEM
- EDR
- Threat Intelligence
- Equity
- Pension
Do you enjoy getting hands-on with complex security investigations rather than simply triaging alerts? Are you confident working across Microsoft Defender, Sentinel and KQL to understand what is really happening behind an event? Do you know when to investigate independently and when an incident needs to be escalated?
CFA Institute is looking for aSecurity Operations Analyst II to join our Security Operations Center and strengthen our in-house cybersecurity capability. You will operate as a highly capable security analyst across monitoring, investigation, incident response and threat hunting, working between our managed security service and senior Security Operations specialists.
You will join at an important point for the team, taking meaningful ownership of day-to-day security operations while helping us continue to mature areas including proactive threat hunting and investigative capability.
What You’ll Do
- Investigate security alerts and events across endpoints, identities, email, cloud services and network infrastructure, determining whether activity is malicious or legitimate.
- Use Microsoft Defender XDR, Microsoft Sentinel and KQL to investigate suspicious activity, correlate telemetry and identify indicators of compromise and attacker behaviours.
- Independently own routine and moderately complex investigations, determining scope, severity and potential business impact and escalating when specialist or senior support is required.
- Review escalated security cases and work closely with our managed security service provider and senior analysts to ensure investigations are thorough and appropriately handled.
- Support incident response across identification, investigation, containment and recovery, including collecting and analysing evidence to establish investigative timelines.
- Investigate phishing, suspicious email activity, credential compromise and cloud or identity-related security events.
- Contribute to the development of more proactive threat-hunting capability, using security telemetry and investigative queries to identify potential threats.
- Recommend improvements to detection coverage, hunting queries, playbooks and investigation procedures based on what you uncover.
- Translate technical findings into clear, useful information for technical and non-technical stakeholders, including contributing to executive-ready security briefings when required.
- Participate in a rotational on-call schedule supporting significant or time-sensitive security incidents.
What We’re Looking For
- Hands-on professional experience within a Security Operations Center, cybersecurity operations or a closely related technical security environment.
- Practical experience withMicrosoft Defender and/or Microsoft Sentinel, with the ability to use the Microsoft security environment as part of real investigations.
- Hands-on experience usingKQL to query security data, investigate suspicious activity or support threat hunting.
- Strong understanding of SIEM and EDR/XDR technologies and how their telemetry is used during an investigation.
- Demonstrable experience investigating security alerts and incidents across areas such as endpoints, identity, email and cloud environments.
- Experience investigating phishing, suspicious email activity and potential credential compromise.
- The technical judgment to work independently through complex or ambiguous situations while recognising when escalation is the right course of action.
- Understanding of incident-response processes, security investigation methodologies and attacker tactics and techniques, including familiarity with MITRE ATT&CK.
- Strong communication skills, including the ability to turn detailed technical findings into clear information for different audiences.
- A curious, continuously learning approach to cybersecurity and a genuine interest in keeping pace with emerging threats, technologies and investigative techniques.
Why Join Us
- Join an in-house Security Operations team where you will have meaningful ownership of investigations rather than operating solely within an initial alert queue.
- Work across a broad security control environment, with significant hands-on exposure to Microsoft security technologies.
- Help strengthen and mature CFA Institute’s proactive threat-hunting and broader Security Operations capability.
- Work closely with experienced security specialists and contribute to investigations that have visibility across technology and senior leadership.
- Gain exposure to evolving areas of the security portfolio, including threat intelligence, data protection and brand protection.
- Join at a point where the Security Operations function is evolving, giving you the opportunity to contribute to how its capabilities, detections and investigative practices develop.
At CFA Institute, we are committed to transparency and equity in our hiring process. In compliance with wage transparency laws in many of the jurisdictions in which we recruit, we provide the following information regarding compensation for this position:
Expected salary range: US - $83,000 - $110,000 per year.
All salary ranges are subject to adjustment based on experience, education, and other factors relevant to the position. Additional benefits include eligibility for an annual incentive bonus, a 12% employer contribution to a 401(k) or pension plan, and a comprehensive medical benefits package.



We offer a comprehensive benefits package to support our employees, including health coverage, generous time off, competitive retirement plans, flexible work options, and wellbeing and development programs. You can learn more on our careers site:Working at CFA Institute | Comprehensive Benefits
About CFA Institute
CFA Institute is the global leader in investment excellence and ethics. With nearly 200,000 charterholders across 160 markets, we promote professional growth, uphold ethical standards, and help advance better financial markets. Join a global organization committed to putting investors first.
Follow CFA Institute on:LinkedIn |YouTube |Facebook |Instagram |WeChat |Weibo
Important Message: Your application must clearly demonstrate how you meet the requirements as CFA Institute cannot make assumptions about your education, experience, or location. We thank all those who apply.
We are an Equal Opportunity Employer. CFA Institute prohibits both discrimination and harassment with regard to all identifying characteristics: any individual employee, group of employees, or prospective employee on the basis of race, color, national origin, citizenship or immigration status, religion, creed or belief, age, marital or partnership status, marital or family status, care giver status, pregnancy and maternity, sexual and other reproductive health decisions, physical abilities/qualities, disability, sexual orientation, gender, gender identity or expression, predisposing genetic characteristic, military or veteran status, status as a victim or witness of domestic violence or sex offense or stalking, unemployment status, infectious disease carrier status, migrant worker status, educational background, socio-economic status, geographic location and culture or any other basis protected by applicable law. This policy impacts all aspects of employment, including but not limited to, recruitment, hiring, compensation, training, development, promotion, demotion, layoff, recall, furlough, transfer, leave of absence, and dismissal. This is a global policy that applies to all CFA Institute employees, regardless of location.
If, due to a disability or current medical condition, you need an accommodation or assistance to complete a job application, you can request one at any stage of the recruitment process. Please send an email toTAHelpdesk@cfainstitute.org noting the accommodations or assistance you are requesting. Please do not include any medical or health information in this email. We will review your request and contact you to discuss the possible options and arrangements. We will try our best to provide you with an accommodation or assistance that meets your needs and respects your preferences.
Security Operations Analyst II · Cfa Institute