Do you want to be part of a fast-growing company in the leading field of cybersecurity? We are looking for the top people to help us be the best.
KAMIND is a fast-growing MSSP (Managed Security Services Company), a Microsoft Direct AOS-G partner, a CMMC L2 C3PAO-certified company, a CMMC RPO and a 6 year Inc 5000 award winning company. KAMIND builds secure connections between people and Microsoft Office 365 and Azure cloud services. A KAMIND professional is a member of a close-knit team with a focus on client success in the deployment of Office 365 and Microsoft security services. KAMIND clients are growing businesses that adapt and change to be more competitive in the market and build their business on Microsoft software and security standards.
Job Purpose: Security Analyst II
The Security Analyst Level II is a senior individual contributor who designs and delivers advanced Microsoft cloud security solutions for KAMIND IT and our clients. This role sits at the leading edge of where we — and our clients — are investing today: securing AI workloads, Data Security Posture Management (DSPM), Microsoft Purview (including data lake integration), and expanding Microsoft Sentinel through third-party service integrations.
You will build solutions end-to-end — from discovery and design through implementation guidance and validation — for commercial and AOS-G/CMMC clients across Microsoft 365, Azure, and hybrid environments. This is a technical security analyst role, not a management position. Success is measured by the quality, security, and innovation of the architectures you deliver. This is a full-time, in-person role in our Lake Oswego office, reporting to the Security Lead.
Responsibilities and Duties
AI & Data Security Architecture (Primary Focus Areas)
- Design and build AI security solutions for KAMIND and client environments — securing Microsoft 365 Copilot, Azure OpenAI, and other AI workloads (identity, data exposure, prompt/response risks, governance, and acceptable-use guardrails).
- Design and deliver DSPM (Data Security Posture Management) architectures to discover, classify, and reduce risk across client data estates.
- Build Microsoft Purview deployments across its full feature set: Information Protection, Data Loss Prevention, Insider Risk, eDiscovery, Compliance Manager, Communication Compliance, and Records Management.
- Design Purview integration with client data lakes (Fabric/OneLake, Azure Data Lake, third-party) to extend classification, sensitivity labeling, and governance to structured and unstructured data.
Microsoft Sentinel Architecture
- Deploy advanced Microsoft Sentinel solutions — including integration of third-party services (SaaS platforms, network devices, identity providers, EDR/XDR, threat intel, ITSM) via connectors, Logic Apps, and custom ingestion.
- Design KQL analytics, workbooks, SOAR playbooks, and detection strategies aligned to MITRE ATT&CK.
- Contribute architectural direction to advanced threat hunting and post-incident improvements.
Client Architecture & Innovation
- Serve as the security analyst on client engagements — leading design workshops, producing architecture artifacts, and guiding implementation teams.
- Translate client business requirements, compliance obligations (CMMC, NIST 800-171, ISO, SOC 2, PCI, HIPAA), and risk tolerance into concrete Microsoft security architectures.
- Bring new ideas to emerging security challenges — evaluate new Microsoft capabilities and third-party technologies and shape them into repeatable KAMIND service offerings.
- Advance CMMC and related compliance architectures for commercial and AOS-G (GCC High) clients.
- Prepare executive-level architecture briefings, decision documents, and risk analyses for client and internal stakeholders.
- Author technical blogs, reference architectures, KBs, and client-facing collateral that showcase KAMIND thought leadership.
- Engage directly with client stakeholders (technical through executive); occasional travel to client sites.
- Acquire and maintain relevant Microsoft security certifications.
Qualifications and Skills
Required
- US Citizen (US DOD/ITAR requirement).
- In-person, Lake Oswego, OR office.
- 5+ years of hands-on IT security experience, with demonstrated architect-level ownership of Microsoft cloud security designs.
- Deep expertise across the Microsoft Defender XDR suite, Microsoft Sentinel, Microsoft Purview, and Microsoft Entra.
- Proven experience with CMMC, ITAR, and CUI handling; strong command of NIST 800-171/800-53.
- Hands-on architecture experience with AI security controls, DSPM programs, and Purview data governance at scale, including data lake integration.
- Advanced KQL and scripting proficiency (PowerShell, Python) sufficient to prototype detections and automations.
- Incident response architecture experience.
- Hardening Azure Virtual Machines using Microsoft security best practices
- Designing and securing Azure Virtual Desktop (AVD) environments.
- Implementing network segmentation using VNets, NSGs, Azure Firewall, and Private Endpoints.
· Design, deploy, and manage Microsoft Intune solutions including:
- Windows 10/11 device enrollment and lifecycle management
- Mobile Device Management (MDM) and Mobile App Management (MAM)
- Device compliance and configuration policies
- Microsoft Defender for Endpoint integration
- SC-500 required, plus at least two of: SC-100, SC-200, SC-300, SC-400. AZ-104 highly desirable.
- Bachelor's degree or higher from an accredited college/university.
- Experience producing Information Governance and Security Strategy assessments against CMMC, ISO, NIST, SOC 2, PCI, and HIPAA.
- Authorized to work in the US without current or future visa sponsorship.
Key Attributes
- Exceptional attention to detail — precision in design, documentation, and risk analysis is non-negotiable at this level.
- Bringing new ideas to security challenges — curiosity, initiative, and a track record of proposing and piloting novel approaches.
- Strong change management orientation.
- Advanced written and verbal communication; comfortable presenting architectures to executive and technical audiences.
- Collaborative, team-oriented individual contributor.
Due to Federal ITAR requirements, KAMIND IT is required to restrict our hiring to persons who are US Citizens, lawful permanent residents, or green card holders. KAMIND IT provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. You will NEED to bring your Driver's License and Birth Certificate or Passport along with the completed Employment Application with you if called for an interview.
Recruiters
This is not a solicitation or a request for service. Do not contact KAMIND or supply candidates.
Work Remotely
- This is an on site position in Lake Oswego, Oregon.
Job Type: Full-time
Pay: $70,000.00 - $90,000.00 per year
Benefits:
- Dental insurance
- Employee assistance program
- Flexible spending account
- Health insurance
- Paid time off
- Professional development assistance
- Referral program
- Vision insurance
Education:
Experience:
- Security analysis: 3 years (Required)
Language:
License/Certification:
- SC-500 certification (Required)
Location:
- Lake Oswego, OR 97035 (Required)
Ability to Commute:
- Lake Oswego, OR 97035 (Required)
Work Location: In person