Sr Information Security Analyst

Scorpion Therapeutics

Michigan

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work two days from home
Career development opportunities

Job summary

Scorpion Therapeutics is seeking a Senior Cyber Defense professional to lead investigations, incident response, threat hunting, and continuous improvement of security operations. You will work across endpoint, identity, email, cloud, and data security technologies to detect, contain, and remediate threats.

You will mentor analysts, own key Cyber Defense capabilities, and enhance DLP/data security monitoring while coordinating with security, privacy, legal, and engineering teams.

Qualifications

  • Bachelor’s in Cybersecurity/IT (or related) or equivalent experience.
  • 7+ years relevant cybersecurity experience (hands-on security ops, incident response, detection, or hunting).
  • Ability to independently lead complex incident investigations.
  • Hands-on SIEM and EDR/XDR experience.
  • Strong understanding of endpoint, identity, network, email, and cloud attack techniques.
  • Working knowledge of Active Directory and Microsoft Entra ID security.
  • Strong analytical/troubleshooting/documentation/communication skills.

Responsibilities

  • Lead investigations, containment, remediation, and post-incident reviews across endpoint, identity, email, cloud, and network.
  • Investigate suspicious activity using SIEM/EDR/XDR, identity, and email telemetry.
  • Create incident timelines; determine scope and root cause; document findings and recommendations.
  • Conduct proactive threat hunting to improve detection and response.
  • Mentor analysts and act as escalation point.

Skills

Incident response
Threat hunting
SIEM/EDR
Investigation
Mentoring
Data security/DLP

Education

Bachelor’s in Cybersecurity/IT

Tools

CrowdStrike Falcon
Splunk
Cortex XSOAR
Microsoft Sentinel
Microsoft Entra ID
PowerShell
Python

Job description

Description Overview
  • Senior individual contributor in Cyber Defense responsible for leading security investigations, incident response, threat detection and hunting, and continuous improvement of enterprise security operations.
  • Works across endpoint, identity, email, cloud, and data security technologies to identify, contain, and remediate threats.
  • Hands-on lead for complex investigations; improves detections/response, mentors analysts, and owns key Cyber Defense capabilities. DLP/data security experience strongly preferred.
Scope of the Role
Security Operations & Incident Response
  • Lead investigation, containment, remediation, and post-incident review across endpoint, identity, email, cloud, and network.
  • Investigate suspicious activity using SIEM, EDR/XDR, identity, email security, and other telemetry.
  • Create incident timelines; determine scope/root cause; document findings; communicate risk/recommendations.
  • Conduct proactive threat hunting to improve detection/response coverage.
  • Serve as escalation point and mentor.
Detection, SIEM & Automation
  • Develop/tune security detections and correlation logic.
  • Use SIEM to investigate, hunt, and improve monitoring coverage.
  • Support orchestration/automation (playbooks for investigation, enrichment, containment, notification).
  • Identify SOC processes to automate/streamline.
Endpoint, Identity & Cloud Threat Detection
  • Investigate endpoint threats (CrowdStrike Falcon or comparable EDR/XDR).
  • Investigate identity-based attacks (AD, Microsoft Entra ID, auth, privileged accounts, OAuth apps, session/token abuse).
  • Analyze Microsoft 365/cloud events and coordinate containment/remediation.
  • Use TI/IOCs to scope incidents and proactively hunt.
Data Security & DLP
  • Support/improve enterprise DLP and data security monitoring across endpoint, email, cloud, collaboration.
  • Investigate data-loss/sensitive exposure/policy violations; coordinate response.
  • Tune DLP policies/workflows to improve quality and reduce business impact.
  • Partner with security, privacy, legal, business as needed.
Cyber Defense Program Improvement
  • Identify gaps from incidents/threat hunting/analysis and recommend improvements.
  • Develop/maintain investigation procedures, response playbooks, and documentation.
  • Collaborate with engineering/IAM/network/cloud teams to strengthen controls.
  • Own assigned Cyber Defense technologies/operational capabilities and drive maturity.
Experience Required
  • Bachelor’s in Cybersecurity/IT (or related) or equivalent experience.
  • 7+ years relevant cybersecurity experience (hands-on security ops, incident response, detection, or hunting).
  • Ability to independently lead complex incident investigations.
  • Hands-on SIEM and EDR/XDR experience.
  • Strong understanding of endpoint, identity, network, email, and cloud attack techniques.
  • Working knowledge of Active Directory and Microsoft Entra ID security.
  • Strong analytical/troubleshooting/documentation/communication skills.
Desired Technical Experience
  • CrowdStrike Falcon (EDR and/or Identity Protection).
  • Splunk Enterprise Security, CrowdStrike Next-Gen SIEM, Microsoft Sentinel, or comparable SIEM.
  • Cortex XSOAR or comparable SOAR/security automation.
  • Microsoft 365/Entra ID security investigations.
  • Enterprise DLP/data security (Proofpoint, Microsoft Purview, or similar).
  • Email security and account-takeover investigations.
  • PowerShell/Python/SPL/KQL or similar scripting/query languages.
  • Threat intelligence, vulnerability/exposure management, hybrid enterprise environments.
Benefits
  • Competitive compensation; benefits to support you and your family; career development opportunities.
  • Hybrid working: ability to work two days per week from home in many roles.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Information Security Analyst
Information Security Analyst

Jobtailor • Atlanta (GA)

On-site
USD 85,000 - 120,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Senior Information Security Analyst
Senior Information Security Analyst

Perrigo Company plc • United States

Hybrid
USD 120,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Senior Identity Protection Specialist
Senior Identity Protection Specialist

Jobtailor • Morrisville (NC)

On-site
USD 140,000 - 190,000