Full-Time

Level 2 Cyber Security Analyst

Updated on 5/26/2026

Lyra Technology Group

Lyra Technology Group

51-200 employees

Decentralized MSP portfolio and acquisition platform

Compensation Overview

$100k/yr

Denver, CO, USA

Remote

Fully remote role; candidates must be able to work from home in a fully remote environment.

Category
IT & Security
Required Skills
PowerShell
Linux/Unix
Requirements
  • 2–4 years of experience in a SOC, incident response, cyber analyst or security operations role
  • 2–4 years of hands-on experience working with at least one of the following: Microsoft Defender for Endpoint (MDE), CrowdStrike EDR, SentinelOne EDR, Stellar Cyber XDR
  • Strong knowledge of attacker tactics and techniques aligned to MITRE ATT&CK, NIST, Lockheed Martin (e.g., persistence, privilege escalation, lateral movement, exfiltration)
  • Solid understanding of Windows security fundamentals (event logs, authentication, common persistence locations) and basic Linux/macOS concepts
  • Familiarity with common security log sources and workflows (SIEM concepts, ticketing/case management, escalation processes)
  • Ability to write clear incident documentation and communicate findings to both technical and non-technical stakeholders
  • Experience handling sensitive information and following documented procedures and change controls
  • Strong knowledge of the Windows and Linux operating systems
  • Ability to establish and maintain a strong level of customer trust and confidence
Responsibilities
  • Monitor and triage security alerts from EDR/XDR, SIEM, and related security tooling; prioritize incidents based on risk and business impact
  • Investigate endpoint threats (malware, ransomware, credential theft, persistence, lateral movement) using Microsoft Defender for Endpoint (MDE), CrowdStrike EDR, SentinelOne EDR, and Stellar Cyber XDR
  • Perform incident response activities: evidence collection, scoping, containment, eradication, recovery, and post-incident reporting
  • Conduct endpoint and host-based analysis (process trees, command-line execution, registry changes, scheduled tasks, persistence mechanisms, network connections)
  • Correlate telemetry across endpoint, identity, network, and cloud sources to confirm malicious activity and reduce false positives
  • Execute response actions (e.g., isolate host, kill/quarantine process, block indicators, remove persistence, enforce policy changes) in accordance with playbooks and approvals
  • Develop and maintain detection and response playbooks/runbooks for common attack scenarios (phishing, suspicious PowerShell, credential dumping, suspicious service creation, etc.)
  • Create and tune alerting rules, exclusions, and detections to improve signal quality and reduce noise while maintaining security coverage
  • Document investigations thoroughly: timelines, IOCs, impacted assets/users, actions taken, and recommendations for prevention
  • Support threat hunting activities using EDR/XDR telemetry and threat intelligence to identify suspicious patterns and proactively reduce risk
  • Participate in on-call rotation and shift-based SOC coverage as required
  • Research security enhancements and make recommendations for management
  • Stay up to date on information technology trends and security standards
  • Train, mentor, and guide teammates through direct comms and by hosting knowledge transfer calls
Desired Qualifications
  • Experience with Microsoft security ecosystem (e.g., Defender for Identity, Defender for Cloud, Entra ID/Azure AD sign-in logs)
  • Basic scripting/automation skills (PowerShell, Python, or Bash) for investigation and enrichment tasks
  • Familiarity with network security concepts, protocols (TCP/UDP, DNS, HTTP/S, TLS, proxies, VPNs), and packet/log analysis
  • Threat hunting experience and building detections based on behavioral analytics
  • Experience with vulnerability management and remediation tracking
  • MSSP experience
  • A bachelor’s/master's degree in cyber security or related field, or equivalent level of experience within IT
  • Security certifications (nice-to-have): Security+, CySA+, GCIH, GCIA, SC-200, or equivalent
Lyra Technology Group

Lyra Technology Group

View

Lyra Technology Group is a portfolio-based parent that builds a network of managed IT service providers (MSPs) across North America. It acquires MSPs and provides them with permanent capital, shared resources, and a community of peers, while allowing each acquired company to keep its brand, leadership, and culture and operate independently under its existing management. The group also operates Lyra Recovery, a division focused on ransomware and data breach remediation. Its approach centers on decentralized decision-making by local leaders, continuous growth through acquisitions, and ensuring that the independent MSPs retain their identity while benefiting from the backing and infrastructure of Lyra and Evergreen Services Group. The ultimate goal is to expand a large, coast-to-coast MSP network serving more than 10,000 organizations, by adding leading MSPs and supporting their growth without divestment, using permanent capital from its backers.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Chicago, Illinois

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Over 100 MSPs generate predictable recurring revenue from subscriptions.
  • Acquired DKBinnovative on June 27, 2024, bolstering cybersecurity.
  • Alpine Cyber Program enhances portfolio cybersecurity capabilities.

What critics are saying

  • Integration failures across 100 MSPs erode service quality now.
  • Kaseya captures 25% more SMB share with unified AI platforms.
  • Alpine exits Lyra by 2027, hitting 5x return target.

What makes Lyra Technology Group unique

  • Lyra preserves MSP brands, employees, and cultures post-acquisition.
  • Decentralized model enables independent operations by local management.
  • Permanent capital from Evergreen avoids divestitures unlike peers.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Lyra Technology Group who can refer or advise you

Benefits

Health Insurance

Unlimited Paid Time Off

Flexible Work Hours

Remote Work Options

Paid Vacation

401(k) Retirement Plan

401(k) Company Match

Wellness Program

Mental Health Support

Conference Attendance Budget

Professional Development Budget

Stock Options

Company Equity

Phone/Internet Stipend

Home Office Stipend