Security Operations Analyst — Cloud & Incident Response

Barton Malow

Michigan

On-site

USD 85,000 - 115,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Barton Malow is seeking a Cybersecurity Analyst to strengthen our proactive security posture across enterprise IT. The role emphasizes timely threat response, incident handling, and collaboration with stakeholders to reduce risk.

You will work with cloud security, SIEM/MDR integration, and automation while applying framework knowledge to enhance defenses and governance. Ideal candidates have 2–3 years in security operations, strong AWS IAM and cloud monitoring skills, and a track record of clear

Qualifications

  • Bachelor's degree in computer science, cybersecurity or related field or equivalent work experience.
  • 2-3 years of experience in security operations, vulnerability management, security engineering, incident response, or offensive security required.
  • Conceptual and technical knowledge of modern IT environments such as server configuration/architecture, cloud, database management/configuration, networking protocols/designs, and access management/access controls.
  • Working knowledge of AWS security fundamentals, including IAM (users, roles, policies, permission boundaries, and federation), the shared responsibility model, and core security services such as CloudTrail, GuardDuty, Security Hub, Config, and KMS.
  • Familiarity with cloud identity and access management concepts — least-privilege design, role assumption (STS), policy evaluation logic, and detecting over-permissioned or stale credentials.
  • Experience monitoring cloud environments for security events and correlating cloud logs with broader SIEM/MDR data sources is preferred.
  • Strong technical skills with knowledge of a wide variety of tools, and technologies, and experience deploying and monitoring these capabilities to identify cyber threats.
  • Knowledge of common cybersecurity frameworks and how to apply them, e.g., NIST 2.0 CSF, MITRE ATT&CK (including the ATT&CK Cloud matrix).
  • Demonstrated interpersonal skills and ability to work effectively and collaboratively with a wide range of stakeholders.
  • Demonstrated confidence and ease in delivering clear, effective verbal and written communication.
  • Experience in scripting and programming languages such as PowerShell, Bash, or Python is preferred.
  • Cybersecurity training or certifications from organizations such as CompTIA, TCM, SANS/GIAC, OffSec, ISC(2) is preferred; AWS certifications (e.g., AWS Certified Security – Specialty or Solutions Architect Associate) are a plus.

Responsibilities

  • Investigate and respond to tickets generated by the organization's MDR provider.
  • Actively engage in incident response and root cause analysis. Participate in incident response activities to analyze and remediate cyber threats.
  • Perform internal security audits to assess the organization's security posture, identify potential weaknesses, and recommend corrective measures.
  • Monitor and assess the security of cloud environments (AWS), including review of IAM policies, roles, and permissions to enforce least-privilege access and identify misconfigurations or privilege escalation paths.
  • Analyze cloud security telemetry — including AWS CloudTrail, GuardDuty, Security Hub, CloudFormation Guard and CloudWatch — to detect, investigate, and respond to suspicious activity and policy violations.
  • Educate and raise awareness among the user community about various security threats, best practices, and measures to mitigate risk.
  • Prioritize risk reduction and remediation tasks to support a vulnerability management program.
  • Develop and maintain technical procedures and playbooks focused on incident handling.
  • Communicate effectively with technical and non-technical teams while working to improve overall cybersecurity effectiveness.
  • Participate in tabletop exercises designed to simulate potential cybersecurity incidents.
  • Conduct research, analysis, and correlation of events across a wide variety of data sources.
  • Demonstrate the ability to effectively leverage AI and LLMs to drive value while proactively identifying and mitigating emerging risks.

Skills

Security operations
Vulnerability management
Incident response
Cloud security (AWS)
IAM & least-privilege
Cloud monitoring
Scripting (PowerShell/Python/Bash)
Networking concepts
Communication skills
Certifications helpful

Education

Bachelor's degree in computer science or cybersecurity

Tools

AWS Security Services
CloudTrail
GuardDuty
Security Hub
Config
KMS
SIEM/MDR

Job description

Barton Malow is seeking a Cybersecurity Analyst to strengthen our proactive security posture across enterprise IT. The role emphasizes timely threat response, incident handling, and collaboration with stakeholders to reduce risk.

You will work with cloud security, SIEM/MDR integration, and automation while applying framework knowledge to enhance defenses and governance. Ideal candidates have 2–3 years in security operations, strong AWS IAM and cloud monitoring skills, and a track record of clear

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Operations Analyst: Cloud & Incident Response
Cybersecurity Operations Analyst: Cloud & Incident Response

Barton Malow Co. • Southfield (MI)

On-site
USD 85,000 - 120,000
Cybersecurity Analyst: Cloud & Incident Response Pro
Cybersecurity Analyst: Cloud & Incident Response Pro

Barton Malow Builders • Southfield (MI)

On-site
USD 80,000 - 110,000
Cybersecurity Analyst (AWS Cloud Security)
Cybersecurity Analyst (AWS Cloud Security)

Barton Malow Builders • Southfield (MI)

On-site
USD 80,000 - 110,000
Cybersecurity Analyst (AWS Cloud Security)
Cybersecurity Analyst (AWS Cloud Security)

Barton Malow • Michigan

On-site
USD 85,000 - 115,000
Security Operations Architect - Cloud & Incident Response
Security Operations Architect - Cloud & Incident Response

Softpath System LLC • Redwood City (CA)

On-site
USD 90,000 - 120,000
Cybersecurity Analyst – Cloud & Incident Response
Cybersecurity Analyst – Cloud & Incident Response

TurnPoint Services • Louisville (KY)

On-site
USD 70,000 - 100,000
Security Operations Analyst - Cloud IAM & Automation
Security Operations Analyst - Cloud IAM & Automation

ALVARIA • Lombard (IL)

On-site
USD 90,000 - 130,000
Security Operations Analyst — SIEM & Incident Response
Security Operations Analyst — SIEM & Incident Response

myBridge Corporation • Chicago (IL)

On-site
USD 85,000 - 120,000
401K
Medical Insurance
Dental Insurance
+2
Senior Cloud Security Analyst & SIEM Engineer
Senior Cloud Security Analyst & SIEM Engineer

CMA • United States

On-site
USD 90,000 - 130,000
Cybersecurity Analyst (AWS Cloud Security)
Cybersecurity Analyst (AWS Cloud Security)

Barton Malow Co. • Southfield (MI)

On-site
USD 85,000 - 120,000