
Security Operations Senior Analyst
- Detroit, MI
- Permanent
- Full-time
- Respond to, investigate, and analyze security events to determine appropriate actions
- Analyze security system logs, security tools, and available data sources on to identify attacks against the enterprise and report on irregularities, issues related to improper access patterns, trending, and event correlations
- Conduct and apply detection engineering concepts to analyze, create, and tune detection logic and telemetry to ensure effective coverage and detection of existing and emerging threats
- Perform security posture analysis to improve overall IT ecosystem utilizing telemetry from security tools (Secure Score, KQL analysis, custom reporting etc.)
- Gather information from other IT and non-IT staff to obtain information regarding security problems to networks, servers, endpoints, and applications
- Perform incident response activities and ensure that proper protection or corrective measures have been taken when an incident has been discovered
- Assist with administration of information security controls and software such as endpoint protection, endpoint detection and response, intrusion detection/prevention (IDS/IPS), security incident and event management (SIEM), and physical security systems
- Expected to stay current on security industry trends, new threats and attack techniques, mitigation techniques, and emerging security technologies
- Provide insight and participate in security projects to evaluate and recommend security products for various applications and platforms throughout the organization while supporting business initiatives
- Assist with the development, maintenance of, and training on technical documentation and Standard Operating Procedures (SOP)
- Improve security efficiency and streamline/automate work processes while working collaboratively with other team members and IT staff to accomplish objectives
- Participate in critical incidents and implementation reviews
- Additional responsibilities as identified. This description is not designed to encompass a comprehensive listing of required activities, duties, or responsibilities
- Highly motivated to work in information security
- Minimum four (4) years of Information Security experience
- Bachelor's degree in Information Technology or related field preferred; work experience and background may be considered in lieu of formal education
- Proven experience creating detection logic, SIEM rules, custom detections within EDR tools, etc.
- Cloud security experience within Azure or other platforms (AWS, GCP)
- Collaborative interpersonal skills with the ability to work well as an individual and as part of a team
- Ability to provide formal reports and presentations to people at all levels
- Proficient knowledge of information systems security concepts and current information security trends and practices
- Working knowledge of infrastructure security tools such as firewalls, network security monitoring, anti-malware, OS hardening, etc.
- Experience integrating security tools through scripting, using API's and improving existing processes through automated methods are a plus
- Incident Response, Forensics, and Malware Analysis experience is a plus
- System administration and security hardening experience is a plus
- Data analytics / data science techniques and understanding is a plus
- Security Certifications such as the following are a plus (Security+, CISSP, SANS GIAC certifications, Microsoft Security certifications)
- High attention to detail with the ability to be organized and prioritize tasks so work is completed in an accurate and timely manner under time constraints
- Excellent written and verbal communication skills in English.
- Core working hours are generally 8:30 AM - 5:30 PM, Monday - Friday; willingness to work outside of normal U.S. business hours, and as unique projects/needs arise.
- Ability to work full time in an office and remote environment; physically able to sit/stand at a computer and work in front of a computer screen for significant portions of the workday.
- Must become familiar with, and promote and abide by, our Core Values as defined by the AlixPartners'