Senior Cybersecurity Analyst

Fluence Energy PolandArlington, VirginiaOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

Fluence (Nasdaq: FLNC) is a global market leader delivering intelligent energy storage and optimization software for renewables and storage. Our solutions and operational services are helping to create a more resilient grid and unlock the full potential of renewable portfolios. With gigawatts of successful implementations across nearly 50 markets, we are transforming the way we power our world for a more sustainable future. For more information, please visit  fluenceenergy.com .

Job Description:

Role Overview

The Senior Cybersecurity Analyst is a hands-on, senior individual contributor within Fluence's Global Cybersecurity team, responsible for detecting, investigating, and responding to threats across our corporate, cloud, and product environments. Working primarily in Microsoft Sentinel and Microsoft Defender XDR, this person leads complex, multi-telemetry investigations, drives proactive threat hunting informed by threat intelligence, and turns lessons learned into stronger detections, automation, and preventive controls. The role partners daily with IT infrastructure, DevOps, risk and compliance, and business teams, and interacts with managed service and vendor partners during escalations. The ideal candidate brings at least five years of security operations experience, deep hands-on skill with Microsoft security tooling and query languages such as KQL, a strong automation mindset, and a clear track record of taking ownership of incidents and improvement initiatives from start to finish. The Senior Cybersecurity Analyst also mentors junior analysts and helps set the technical standard for how the security operations team works.

Key Responsibilities

Threat Monitoring, Detection and Investigation

- Conduct threat monitoring and analysis using threat detection, investigation and response (TDIR) tooling, including security information and event management (SIEM) and extended detection and response (XDR) platforms such as Microsoft Sentinel and Microsoft Defender XDR.
- Lead multi-telemetry investigations across endpoint, identity, email, network, and cloud signals to identify threats originating inside and outside the organization.
- Triage alerts from detection platforms, eliminate false positives, and escalate confirmed attacks with clear, evidence-based findings.
- Drive advanced, hypothesis-led threat hunting using KQL and current threat intelligence on adversary tactics, techniques, and procedures.
- Operationalize threat intelligence by translating indicators, campaign reporting, and MITRE ATT&CK mappings into hunts, detections, and briefings for stakeholders.
- Maintain and extend cloud security monitoring, including the integration of cloud telemetry into SIEM and XDR platforms.
- Perform analysis and testing to identify vulnerabilities, misconfigurations, and other exposures, and to validate the effectiveness of user and security policies.

Incident Response, Root Cause Analysis and Reporting

- Take end-to-end ownership of assigned incidents, from first alert through containment, eradication, recovery, and closure, keeping stakeholders informed at every step.
- Document formal technical incident reports for infrastructure teams and senior leadership, including timelines, impact, and evidence.
- Provide infrastructure teams with incident support, including mitigating actions to contain activity and advisory guidance for remediation.
- Carry out root cause analysis and follow-up investigations to recommend prevention mechanisms and configuration changes, and track those actions to completion.
- Support the development and delivery of reporting for compliance and infrastructure teams, as well as performance reporting for the security operations team.
- Develop and present security metrics and incident trends to senior leadership, with clear recommendations.
- Work efficiently to meet Fluence-specific SOC metrics and service level agreements.

Detection Engineering and Automation

- Partner with detection content development teams to tune existing detections and create new detection content that reduces noise and improves coverage.
- Design and build automation using scripting (PowerShell, Python) and security orchestration tooling such as Logic Apps or comparable SOAR platforms to accelerate triage, enrichment, and response.
- Own the lifecycle of assigned detection and automation use cases, including requirements, testing, documentation, and measurable outcomes.
- Recommend improvements to security architecture, controls, and processes based on root cause analysis, testing results, and emerging threats.

Security Awareness, Training and Simulation Campaigns

- Own the day-to-day management of the security awareness and training program, including the annual campaign calendar, content selection, and communications to employees and contractors.
- Design and run phishing and social engineering simulation campaigns using platforms such as Hoxhunt, Microsoft Defender for Office 365 Attack Simulation Training, or comparable tools, including scenario selection, targeting, scheduling, and follow-up.
- Manage training assignments through the learning management system, including role-based and risk-based curricula, onboarding and annual refresher courses, due dates, reminders, and escalation for overdue completions.
- Automate the assignment and tracking of training by integrating awareness platforms with identity and HR data sources so that curricula stay aligned to department, role, and manager hierarchy.
- Build and deliver awareness reporting, including simulation click and report rates, repeat-clicker trends, completion rates, and audit-ready evidence for compliance and certification requirements.
- Deliver targeted training and coaching for high-risk groups and individuals identified through simulation results, incidents, or user-reported phishing trends.
- Use incident and threat intelligence findings to keep awareness content current, and continuously improve campaign design based on measured outcomes and employee feedback.
- Partner with HR, Legal, Communications, and business leaders to align awareness activities with company policies, onboarding processes, and regional requirements.

Leadership, Collaboration and Continuous Improvement

- Lead and mentor junior analysts in threat detection, investigation, and incident response, including case reviews and hands-on coaching.
- Act as escalation point and incident lead during major investigations, coordinating technical workstreams and communications.
- Collaborate with IT, risk, compliance, and business units to ensure holistic security coverage across corporate, cloud, and product environments.
- Participate in and lead incident simulations, tabletop exercises, and red, blue, and purple team activities.
- Maintain current knowledge of security technologies, attacker techniques, and mitigations, and share that knowledge across the team.
- Foster a culture of continuous improvement and professional development within the security operations team.

Required Qualifications

- Bachelor's or master's degree in computer science, information security, cybersecurity, or a related field, or equivalent practical experience.
- Minimum 5 years of experience in security operations analysis, incident response, red teaming, penetration testing, IT audit, network operations, or enterprise risk management, with a majority of that time in a hands-on security operations role.
- Minimum 4 years of experience working with regulatory compliance and information security management frameworks such as ISO 27001, NIST CSF, or NIST SP 800-53.
- Hands-on experience monitoring and operating SIEM platforms, with demonstrated depth in Microsoft Sentinel, including analytics rules, workbooks, and data connectors.
- Hands-on experience with Microsoft Defender XDR (Defender for Endpoint, Identity, Office 365, and Cloud Apps) and with network and security technologies such as firewalls and IDS/IPS.
- Strong hands-on skills with analytical and query tools, including Kusto Query Language (KQL), SQL, and Microsoft Excel, to support investigations, alert analysis, reporting, and continuous detection improvement.
- Demonstrated experience building automation for security operations using scripting such as PowerShell or Python and orchestration tooling such as Logic Apps or a comparable SOAR platform.
- Practical experience applying threat intelligence, including adversary tracking, indicator management, and MITRE ATT&CK-based analysis, to detection and response work.
- Hands-on experience configuring and using vulnerability assessment technologies such as Tenable or Nessus.
- Experience managing security work and incidents through ticketing and workflow platforms such as ServiceNow or Jira.
- Hands-on experience running security awareness and training programs, including phishing simulation platforms such as Hoxhunt or Attack Simulation Training, learning management system administration, training assignment tracking, and campaign reporting.
- CompTIA CySA+ or Microsoft Certified: Security Operations Analyst Associate (SC-200), or an equivalent certification.
- Demonstrated ownership mindset, with a track record of driving investigations and improvement initiatives to completion with limited supervision.
- Strong report writing, investigative technique, and communication skills, including the ability to present technical findings to large and non-technical audiences.

Preferred Qualifications

- Master's degree in cybersecurity, information security, or a related technical field.
- Additional certifications such as GCIA, GCIH, GCFA, GCTI, CISSP, or Microsoft SC-100.
- Experience securing and monitoring cloud environments such as Azure, GCP, or AWS, including onboarding cloud telemetry into a SIEM.
- Experience with detection-as-code practices, version control, and CI/CD pipelines for security content.
- Exposure to operational technology or industrial control system environments, ideally in energy, utilities, or manufacturing.
- Experience mentoring analysts or leading a shift, queue, or major incident bridge.
- Experience working with managed security service providers or global, follow-the-sun SOC models.

Key Competencies

- Ownership and accountability, taking full responsibility for investigations, actions, and outcomes from start to finish.
- Strong decision-making under pressure, with a proven ability to weigh the relative costs and benefits of potential actions and select the most appropriate one.
- Influence and stakeholder engagement, with the ability to shape the opinions, plans, and behaviors of technical and business partners.
- Strong problem-solving, critical thinking, and troubleshooting skills applied to complex, incomplete, or conflicting evidence.
- Automation and continuous improvement mindset, consistently looking for ways to remove manual effort and strengthen controls.
- Business alignment, demonstrated through a clear understanding of Fluence's mission, values, and goals and consistent application of that knowledge.

Collaboration and mentorship, establishing and maintaining effective working relationships and developing others on the team.

Our Culture

At Fluence, our culture is the foundation that drives our ambitious growth strategy and fuels our mission to transform the future of energy. Our core cultural pillars empower us to innovate, collaborate, and lead with purpose, ensuring we continue to deliver unparalleled value to our customers and the world.

Unleash Voices

We believe every voice matters. We encourage openness, active listening, and decisive action to create a culture where everyone has the opportunity to contribute to our success. We foster an environment where diverse perspectives are heard and valued, driving innovation and progress.

Customer Fluent

Our customers are at the heart of everything we do. We’re committed to delivering exceptional value that exceeds expectations by understanding our customers' needs and adapting swiftly to meet them. Our deep focus on customer satisfaction drives us to continuously improve and innovate.

Infinite Impact

We are committed to creating the impossible. We push boundaries to deliver sustainable, game-changing solutions that shape a brighter, more energy-efficient future for all. Our team is passionate about making a lasting impact that will resonate for generations to come.

All In

We are all in for growth. Our teams are relentlessly focused on identifying and seizing opportunities that propel us forward. We embrace an ownership mindset, pushing ourselves and each other to accelerate progress and create lasting success.

Equal Opportunity Employer
At Fluence, we believe great teams are built on a collaborative and connected culture. We’re proud to be an Equal Opportunity Employer and welcome qualified applicants of all backgrounds. Employment decisions are made without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, veteran status, gender identity or expression, genetic information, or any other status protected by law.

Work Authorization
To join our team, you’ll need to be legally authorized to work in the United States at the time of application and throughout your employment, without the need for employer sponsorship. Please note that Fluence does not sponsor work visas for this position.