> Markdown version of [/jobs/ext/1918739-cybersecurity-operations-analyst](https://www.wearedevelopers.com/jobs/ext/1918739-cybersecurity-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Operations Analyst - **Company:** Versant Health - **Location:** Troy, MI, United States - **Experience:** Expert - **Salary:** $138,000.0 - $154,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Apple Mac Systems, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Information Leak Prevention, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Information Security Management, Intrusion Detection and Prevention, Network Security, Performance Tuning, Red Team (Cyber Security), Zero Trust Network Access, Web Application Security, Security Information and Event Management, TCP/IP, Strategies of Testing, Web Traffics, Cloud Platform System, Cybercrime, Purple Team (Cyber Security), Firewall Services Module, Blue Team (Cyber Security) - **Published:** August 4, 2026 - **Apply:** https://www.dice.com/job-detail/899f5cc2-55eb-4a58-973b-94204f4136da ## About the Role Bachelor's degree from an accredited college or university, or equivalent professional experience. 5 Years Required 5+ years of experience in cybersecurity, with a strong focus on security operations and incident response Technical Expertise Deep hands-on experience administering and maintaining SIEM, EDR, and related security tools Strong understanding of networking concepts, TCP/IP, Active Directory, DNS, DHCP, and network defense technologies Proficiency with Windows, Linux, and macOS operating systems Experience with cloud security platforms (e.g., AWS, Azure) Knowledge of secure engineering principles and technical security testing methodologies. CEH, OSCP, CHFI, GCIH, CISM, CISSP, or equivalent industry certifications ## Description The Senior Cybersecurity Operations Analyst supports and advances the organization's Information Security program by protecting the enterprise against evolving cyber threats. This role is responsible for leading incident response activities, investigating and analyzing security events, optimizing security controls, and collaborating cross-functionally to strengthen the organization's overall security posture. The Senior Cybersecurity Operations Analyst provides hands-on technical leadership through proactive threat hunting and the continuous enhancement of detection and response capabilities. This position contributes to the ongoing evolution of Versant Health's cybersecurity operations by leveraging leading security technologies, partnering with internal stakeholders, and staying current on emerging threats and attack methodologies. Where you will have an impact Security Hygiene & Control Validation * Routinely audit and validate security control coverage (e.g., XDR, ZTNA, DLP) to ensure tools are operating effectively and protect 100% of intended assets. * Partner with the SOC to ensure log integrity across security and non-security systems; validate alert scope, fidelity, and thresholds. * Monitoring the health and performance of security tools, performing root cause analysis when agents fail or policies are not properly applied. Incident Response, Event Monitoring, & Threat Hunting * Serve as the Tier 2 escalation point for the SOC and lead the full incident response lifecycle, from containment through recovery. * Conduct proactive threat hunting using threat intelligence, SOC findings, and behavioral analysis to identify threats that bypass automated controls. * Analyze threat intelligence to inform defensive strategies and continuously improve detection capabilities. * Collaborate with the SOC to develop, refine, and maintain incident response playbooks aligned to business context. * Monitor and analyze security alerts from SIEM, EDR, and other tools to identify and respond to potential threats. * Implement and enforce security controls, policies, and procedures to protect organizational assets. Blue, Red, and Purple Team Activities * Lead the development and execution of recurring security wargames, including scenario design and cross functional participation. * Actively participate in and lead blue team activities focused on defensive security, detection, and incident response. * Collaborate in purple team exercises to validate detection and response effectiveness against real world attack scenarios. * Participate in internal red team exercises, penetration tests, and simulated attacks to identify security gaps and control weaknesses. * Perform adversary emulation by modeling tactics, techniques, and procedures (TTPs) of known threat actors. * Share insights, lessons learned, and intelligence across teams to continuously improve security posture. * Use findings from offensive testing to optimize SIEM rules, EDR/CASB/SWG policies, firewall configurations, and other security controls. Security Tool Management Configure, maintain, and optimize a broad portfolio of security technologies, including: Security Information and Event Management (SIEM): Log aggregation, correlation, tuning, and alerting. Endpoint Detection and Response (EDR): Threat detection and response across endpoint environments. Attack Surface & Exposure Management (ASM/AEM): Continuous discovery and prioritization of vulnerabilities and exposures. Cloud Access Security Broker (CASB): Enforcement of security controls for cloud applications and services. Secure Web Gateway (SWG): Inspection of web traffic and protection against web-based threats. Data Loss Prevention (DLP): Design, implementation, and management of policies to prevent unauthorized data exfiltration across endpoints, networks, and cloud environments. Security Operations & Support Respond to and resolve security related tickets and user inquiries. Provide guidance and best practice recommendations to end users and IT partners. Troubleshoot security tool issues and perform root cause analysis. Documentation, Reporting, & Communication Create and maintain detailed documentation for incident response procedures, security tool configurations, and security advisories. Generate and present reports on security incidents, trends, and overall security posture to management. Communicate clearly and effectively with stakeholders during and after security incidents. Mentorship & Collaboration Serve as a mentor to junior analysts, providing technical guidance, coaching, and training. Actively solicit feedback from peers and partners to improve operational effectiveness and team maturity. Support special projects and other duties as assigned. What's necessary to do the job? Bachelor's Degree ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)