Cybersecurity Operations Analyst
Job Description
American Tower is seeking a Cybersecurity Operations Analyst to support its corporate Information Security team in Cary, NC (onsite). This role is centered on day-to-day security operations using Microsoft Sentinel, with collaboration across internal stakeholders and managed detection and response partners to improve detection, investigation, containment, and remediation of complex security events.
What you’ll do
You will help strengthen the Security Operations Center (SOC) by monitoring performance and investigating escalated alerts end to end. You will use Microsoft Sentinel to analyze security events, support response activities, and contribute to processes and guidance that improve defensive readiness.
- Track and analyze key performance indicators and security metrics to evaluate SOC effectiveness and identify improvement opportunities.
- Conduct in-depth event and alert analyses in Microsoft Sentinel for incidents escalated from lower-tier analysts, identifying threats and assessing impact.
- Develop and implement runbooks and event response plans and procedures, including containment, eradication, and recovery strategies to minimize business impact.
- Act as a subject matter expert on Microsoft Sentinel, Microsoft Defender for Endpoint, Microsoft Defender for Office, and related security technologies, providing guidance and recommendations to enhance defenses.
- Collaborate with internal teams and external partners to investigate incidents, gather evidence, and support legal and regulatory compliance needs.
- Stay current on emerging cybersecurity threats and trends, proactively identifying risks and vulnerabilities and recommending preventive measures and countermeasures.
- Partner with IT and business stakeholders to ensure security is incorporated into the evaluation, selection, installation, and configuration of hardware and software.
What you bring
- Bachelor’s degree or equivalent experience required.
- Minimum 4 years of cybersecurity experience focused on incident response and security operations within a SOC environment.
- Hands-on experience with Microsoft Sentinel or other SIEM platforms required.
- Strong analytical and problem-solving skills for investigating complex incidents, identifying root causes, and recommending remediation.
- Ability to communicate technical details clearly for the appropriate audience.
- Approx. 5% travel may be required.
- Strong written and oral communication skills, plus the ability to present ideas and recommendations effectively.
- Ability to work across functional groups and employee levels to achieve results professionally.
- Strong organizational skills to manage multiple tasks on agreed timeframes in a fast-paced environment.
Tools and technologies
- Microsoft Sentinel
- Microsoft Defender for Endpoint
- Microsoft Defender for Office
- Security information and event management platforms (SIEM)
Benefits and support
- Healthcare coverage
- 401(k) savings plan
- Paid time off
- Company holidays
- Sick leave
- Parental leave
- Access to an Employee Assistance Program focused on mental and financial wellness
- Annual bonus
- Annual equity award
- Participation in the Employee Stock Purchase Plan (ESPP)
The team
In this role, you will oversee the identification, analysis, containment, and remediation of complex security events using Microsoft Sentinel. You will also work closely with managed detection and response partners as part of the broader incident response and security operations workflow.