Blackpoint Cyber→
Cloud MDR Analyst SkillBridge Intern… at Blackpoint… · Location…
InternshipHybridNot specified
Skills
cloud securitysecurity operationsmicrosoft 365 security featuresmicrosoft defender for office 365microsoft defender for identitymicrosoft entra id (azure ad)conditional access policiesmicrosoft unified audit loggoogle workspace security capabilitiesgoogle workspace admin consolecontext-aware accessdlp policiesgoogle workspace audit & investigation toolcloud identity attack vectorscredential stuffingmfa bypass techniquesoauth phishingtoken theftcloud incident responsesoc operationscloud threat huntingsaas security posture management (sspm)driveanalytical skills
Job Description
Summary: Blackpoint Cyber is the leading provider of world-class cybersecurity threat hunting, detection and remediation technology. They are seeking a Cloud MDR Analyst to monitor, investigate, and respond to threats targeting cloud environments, working alongside seasoned analysts in a dynamic security operations center.
Responsibilities:
- Monitor and analyze anomalous behavior across Microsoft 365, Google Workspace and Cisco Duo environments, including suspicious sign-ins, OAuth application abuse, mailbox rule manipulation, data exfiltration indicators, and identity-based attacks
- Follow standardized Cloud Response playbooks to triage, escalate, and respond to security events across SaaS platforms, including account containment, session revocation, and admin remediation actions
- Investigate cloud-specific attack techniques such as Business Email Compromise (BEC), adversary-in-the-middle (AiTM) phishing, OAuth consent grant abuse, and privilege escalation via misconfigured cloud permissions
- Collaborate with Senior Analysts to research and investigate emerging cloud threat tradecraft and contribute recommendations for new detection logic targeting M365 and Google Workspace telemetry
- Proactively identify and mitigate false positives across cloud alert pipelines by working with senior analysts to suppress noisy or low-fidelity detections
- Collaborate with customers to review cloud security incidents and assist with detection, prevention, and mitigation strategies — including guiding clients through Microsoft Secure Score improvements and Google Workspace security posture reviews
- Leverage cloud-native audit logs — including Microsoft Unified Audit Log, Azure AD Sign-in Logs, and Google Workspace Admin Reports — to reconstruct attacker timelines and scope incidents
- Bring your observant and curious mindset to cloud investigations and security events!
Required Qualifications:
- Motivation and drive to work in a fast-paced and dynamic external SOC environment with a focus on cloud and SaaS security
- Minimum of 1-2 years of experience in an information security role; progressive relevant training and/or certification may be substituted for one year of the experience requirement
- Working knowledge of Microsoft 365 security features including Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Entra ID (Azure AD), Conditional Access Policies, and the Microsoft Unified Audit Log
- Familiarity with Google Workspace security capabilities including Google Workspace Admin Console, Context-Aware Access, DLP policies, and Google Workspace Audit & Investigation Tool
- Understanding of cloud identity attack vectors such as credential stuffing, MFA bypass techniques (AiTM, SIM-swapping), OAuth phishing, and token theft
- Some knowledge of cloud-adjacent tradecraft including Living off the Land techniques applied to cloud environments, lateral movement via federated identity, and cloud persistence mechanisms
- Excellent problem-solving skills, critical thinking, and analytical skills with the ability to deconstruct issues and hunt anomalous patterns in cloud telemetry
- Excellent verbal and written communication skills to effectively summarize and present cloud incident findings to both technical and non-technical stakeholders
- Ability to work independently or as a member of a team in a shift-based environment
Preferred Qualifications:
- Experience working in a SOC with cloud incident exposure preferred
- Experience with CTF platforms or cloud security labs such as TryHackMe, PwnedLabs, or Microsoft Learn security paths are a plus
Required Skills: Cloud Security, Security Operations, Microsoft 365 security features, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Entra ID (Azure AD), Conditional Access Policies, Microsoft Unified Audit Log, Google Workspace security capabilities, Google Workspace Admin Console, Context-Aware Access, DLP policies, Google Workspace Audit & Investigation Tool, Cloud identity attack vectors, Credential stuffing, MFA bypass techniques, OAuth phishing, Token theft, Cloud incident response, SOC operations, Cloud threat hunting, SaaS Security Posture Management (SSPM), Drive, Analytical skills
Benefits: Health, Vision, Dental, and Life Insurance plans, Robust 401k plan, Discretionary Time Off, Other minor perks
Benefits
Health, Vision, Dental, and Life Insurance plans
Robust 401k plan
Discretionary Time Off
Other minor perks