Security Analyst II
Novolex · Charlotte, NC · $9B+ revenue · Fortune 200 · scope exceeds title
Acting as lead architect/engineer for a full greenfield enterprise security stack — SIEM, SOAR, EDR, and internal MSSP-style multi-tenant operations. Official title Security Analyst II; ownership and scope are at the architecture-lead level.
- Architecting a multi-tenant Microsoft Sentinel SIEM (delegated workspace model) with tenant isolation, cross-tenant detection federation, and RBAC governance — centralizing operations across independently governed business units.
- Engineering Detection-as-Code pipelines (IaC/GitOps) to version, test, and promote analytic rules, hunt queries, and watchlists across tenants — cutting content-promotion cycle time from days to minutes.
- Designing multi-tenant log ingestion (DCR normalization, per-tenant enrichment, ingestion-tier cost controls) standardizing onboarding and optimizing platform spend.
- Building an internal MSSP-style operating model — standardized tenant onboarding, detection baselines, and SOAR playbooks delivered as repeatable, auditable units.