Sr Information Security Analyst
Job in
Farmington Hills, Oakland County, Michigan, USA
Listed on 2026-08-30
Listing for:
Scorpion Therapeutics
Full Time
position Listed on 2026-08-30
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
Description Overview
- Senior individual contributor in Cyber Defense responsible for leading security investigations, incident response, threat detection and hunting, and continuous improvement of enterprise security operations.
- Works across endpoint, identity, email, cloud, and data security technologies to identify, contain, and remediate threats.
- Hands-on lead for complex investigations; improves detections/response, mentors analysts, and owns key Cyber Defense capabilities. DLP/data security experience strongly preferred.
- Lead investigation, containment, remediation, and post-incident review across endpoint, identity, email, cloud, and network.
- Investigate suspicious activity using SIEM, EDR/XDR, identity, email security, and other telemetry.
- Create incident timelines; determine scope/root cause; document findings; communicate risk/recommendations.
- Conduct proactive threat hunting to improve detection/response coverage.
- Serve as escalation point and mentor.
- Develop/tune security detections and correlation logic.
- Use SIEM to investigate, hunt, and improve monitoring coverage.
- Support orchestration/automation (playbooks for investigation, enrichment, containment, notification).
- Identify SOC processes to automate/streamline.
- Investigate endpoint threats (Crowd Strike Falcon or comparable EDR/XDR).
- Investigate identity-based attacks (AD, Microsoft Entra , auth, privileged accounts, OAuth apps, session/token abuse).
- Analyze Microsoft 365/cloud events and coordinate containment/remediation.
- Use TI/IOCs to scope incidents and proactively hunt.
- Support/improve enterprise DLP and data security monitoring across endpoint, email, cloud, collaboration.
- Investigate data-loss/sensitive exposure/policy violations; coordinate response.
- Tune DLP policies/workflows to improve quality and reduce business impact.
- Partner with security, privacy, legal, business as needed.
- Identify gaps from incidents/threat hunting/analysis and recommend improvements.
- Develop/maintain investigation procedures, response playbooks, and documentation.
- Collaborate with engineering/IAM/network/cloud teams to strengthen controls.
- Own assigned Cyber Defense technologies/operational capabilities and drive maturity.
- Bachelor’s in Cybersecurity/IT (or related) or equivalent experience.
- 7+ years relevant cybersecurity experience (hands-on security ops, incident response, detection, or hunting).
- Ability to independently lead complex incident investigations.
- Hands-on SIEM and EDR/XDR experience.
- Strong understanding of endpoint, identity, network, email, and cloud attack techniques.
- Working knowledge of Active Directory and Microsoft Entra .
- Strong analytical/troubleshooting/documentation/communication skills.
- Crowd Strike Falcon (EDR and/or Identity Protection).
- Splunk Enterprise Security, Crowd Strike Next-Gen SIEM, Microsoft Sentinel, or comparable SIEM.
- Cortex XSOAR or comparable SOAR/security automation.
- Microsoft 365/Entra investigations.
- Enterprise DLP/data security (Proofpoint, Microsoft Purview, or similar).
- Email security and account-takeover investigations.
- Power Shell/Python/SPL/KQL or similar scripting/query languages.
- Threat intelligence, vulnerability/exposure management, hybrid enterprise environments.
- Competitive compensation; benefits to support you and your family; career development opportunities.
- Hybrid working: ability to work two days per week from home in many roles.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×