> Markdown version of [/jobs/ext/2212676-cyber-security-incident-response-team-analyst](https://www.wearedevelopers.com/jobs/ext/2212676-cyber-security-incident-response-team-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Incident Response Team Analyst - **Company:** Stellantis - **Location:** Auburn Hills, MI, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Information Systems, Databases, Information Sciences, Intrusion Detection and Prevention, Log Analysis, Performance Tuning, Security Information and Event Management, Web Services, Firewalls (Computer Science), Information Technology, Cybercrime, Microsoft Sentinel - **Published:** August 24, 2026 - **Apply:** https://jobs.mitalent.org/job-seeker/job-details/JobCode/403898931 ## About the Role Have a solid understanding of enterprise environments including networking, web services, database, operating systems, etc. Experience with MITRE Attack is a plus. Provide documentation as needed, such as playbooks, to be shared with other team members. Ability to work from high level direction and then collaborate with the rest of the CSIRT and other Products within CDOC team., BS/BA degree in Computer Science, Data Science, Engineering, Information Science, Statistics, Information Systems, or other relevant disciplines from an accredited university or recognized higher education institution. Equivalent international qualifications such as a BSc, MSc, or Diplome d'ingenieur (Europe), or regionally accredited degrees (North America) are also acceptable. Minimum 3 years of overall experience working as a Security Analyst in enterprise environments. Minimum 2 years of hands-on experience with SIEM Sentinel, including configuration, tuning, and incident investigation. Strong understanding of SIEM (Security Information and Event Management) concepts, architecture, and operational workflows. Proven experience supporting and maintaining SIEM platforms in complex, large-scale enterprise infrastructures. Excellent analytical and problem-solving skills, with the ability to troubleshoot and resolve security-related issues effectively. Strong communication skills, with the ability to clearly articulate technical concepts to both technical and non-technical stakeholders, including management and cross-functional teams., Have a solid understanding of enterprise environments including networking, web services, database, operating systems, etc. Experience with MITRE Attack is a plus. Provide documentation as needed, such as playbooks, to be shared with other team members. Ability to work from high level direction and then collaborate with the rest of the CSIRT and other Products within CDOC team. At Stellantis, we assess candidates based on qualifications, merit, and business needs. We welcome applications from all people without regard to sex, age, ethnicity, nationality, religion, sexual orientation, disability, or any characteristic protected by law. We believe that diverse teams reflect our identity as a global company, enabling us to better address the evolving needs of our customers and care for our future. ## Description The Cyber Security Incident Response Team (CSIRT) Analyst is responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats across the enterprise environment. The role focuses on proactive threat detection, incident investigation, SIEM monitoring, threat hunting, and coordination with global security and infrastructure teams to contain and remediate security incidents. The analyst will leverage enterprise security technologies including SIEM, EDR/XDR, threat intelligence platforms, and security monitoring tools to identify malicious activity, investigate anomalies, and support continuous improvement of the organization's security posture. Role Description: The ideal candidate will have experience in a variety of technologies essential to identifying threats to the Stellantis environment, specifically SIEM Microsoft Sentinel, and use those skills to perform the following: Daily use of SIEM Tool, to analyze data flows and identify potential threats and anomalies. Ability to provide a detailed analysis of logs from security infrastructure (Firewall, IPS, etc). Provide internal threat hunting and policy abuse management based on information gathered in SIEM. Understand how to gather threat intelligence data. Recognize potential successful and unsuccessful intrusion attempts and compromises. Log incidents and track them via incident management tool (Resilient). Provide suggestions for Microsoft Sentinel optimization and source log parsing., Define Sentinel use cases, dashboards, filters etc. as needed. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)