> Markdown version of [/jobs/ext/2617559-cyber-security-operations-analyst](https://www.wearedevelopers.com/jobs/ext/2617559-cyber-security-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Operations Analyst - **Company:** S&C Electric Company - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $105,940.0 - $140,376.0 - **Contract:** Temporary contract - **Skills:** Software System Penetration Testing, Command-Line Interface, Cloud Computing, CompTIA Security+, Cyber Security, Computer Engineering, Decision Support Systems, Identity and Access Management, Python (Programming Language), Microsoft Security Essentials, Microsoft Office, Microsoft Visio, Microsoft Software, Node.Js, Windows PowerShell, Azure Active Directory, Kusto Query Language, Runbook, Security Information and Event Management, Software Vulnerability Management, Scripting, Microsoft Power Automate, Mitre Att&ck, Azure Security Center, Information Technology, Cybercrime, Process Control Systems, Microsoft Sentinel, Operational Systems, 3-tier Architectures - **Published:** August 1, 2026 - **Apply:** https://www.dice.com/job-detail/86261e5e-e897-4524-8c48-3e0e801dbdd7 ## About the Role Bachelor's degree in Business Information Systems, Cyber Security, Computer Science, Computer Engineering, Business, or equivalent experience. Preferred Relevant cybersecurity certifications (e.g., CompTIA Security+, CySA+, Microsoft SC-200, Microsoft SC-100, GIAC GCIH, GCFA, GCTI, SSCP, CISSP, CCNA, or equivalent.) What you''ll need to succeed: * 5+ years of demonstrated experience working as a cyber security analyst or related role, with a track record of establishing, executing, improving, and/or assessing cyber security processes. * Demonstrated experience triaging security alerts, working cyber security cases, documenting investigations, and supporting incident response activities in a SOC, CSOC, MSSP, MDR, or enterprise security operations environment. * Proficient with Advanced Endpoint Detection and Response (AEDR), Security Information and Event Management (SIEM), and Microsoft security technologies such as Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID, and Microsoft collaboration applications. * Experience writing, reviewing, or using Kusto Query Language (KQL) for cyber security investigations, alert validation, hunting, reporting, and detection improvement. * Working knowledge of incident response, threat hunting, detection tuning, security monitoring, threat and vulnerability management, endpoint security, identity security, and cyber security case management practices. * Working knowledge of security-related frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-61, NIST 800-171, IEC 62443, NERC CIP, and Cybersecurity Model Certification (CMMC). * Familiarity with relevant privacy regulations, including the California Consumer Protection Act (CCPA), other U.S. State privacy laws, the European Union's General Data Protection Regulation (GDPR), and other international privacy regulations. * Strong analytical skills related to cyber security threats, incident response, problem resolution, change management, and data-driven decision making. * Strong communication skills (written, verbal, listening, and presentation); able to translate technical findings into clear operational and business risk language for internal and external stakeholders. * Ability to independently collaborate with team members, subject matter experts, cross-functional teams, vendors, and stakeholders while following established escalation paths, RACIs, and operating procedures. * Strong customer service orientation with the ability to take initiative in pursuit of improved service, operational consistency, and measurable process improvement. * Excellent organizational skills and ability to prioritize tasks, manage ticket queues, meet deadlines, and communicate risks or blockers proactively. * Embraces change and has the ability to coach junior team members through change, ambiguity, and complex security investigations. * Experience developing process workflow diagrams using Visio or an equivalent tool. * Ability to travel as required. Preferred * Experience with Microsoft Sentinel content management, detection lifecycle practices, Advanced Hunting, ASIM, automation rules, Logic Apps, or related SOAR capabilities. * Experience with cyber threat hunting, MITRE ATT&CK mapping, threat intelligence analysis, and translating threat intelligence or penetration test findings into monitoring improvements. * Experience in command line scripting and implementation using PowerShell, Python, or similar scripting languages for automation, enrichment, and analysis. * Experience using internal penetration testing, breach-and-attack simulation, or security validation platforms such as Horizon3 Node Zero or similar tools. * Experience working alongside a Managed Detection and Response (MDR) provider in a shared-responsibility operating model. * Exposure to operational technology (OT), industrial control system (ICS), manufacturing, energy, or critical infrastructure environments. ## Description Are you passionate about Senior Cyber Security Operations? The Information Technology team is responsible for designing, implementing, and maintaining a robust technology infrastructure to support the organization's operations. Within IT, the IT Risk Management team improves cyber and information security and troubleshoots technical issues to drive innovation through modern solutions. ITRM ensures secure, reliable, and efficient systems aligned with business objectives., The Senior Cyber Security Operations Analyst is responsible for advanced cyber security monitoring, security analysis, incident response, case management, endpoint protection support, threat and vulnerability management support, identity and access management support, and information security process improvement. This role strengthens the Cyber Security Operations Center (CSOC) by performing Tier 2 and Tier 3 investigations, improving Microsoft Sentinel and Microsoft Defender XDR detections, using Kusto Query Language (KQL) to support investigations and reporting, supporting threat hunting and threat intelligence workflows, and collaborating with the MDR provider and internal teams to improve response quality and reduce security risk, * Perform cybersecurity analysis and reporting from security monitoring tools, triage security events, determine operational impact, and participate in or cordinate incident response actions as necessary. * Work Tier 2 and Tier 3 CSOC queue, including escalations alerts, security events, and incidents. * Use incident response tooling and related security telemetry to investigate alerts, validate activity, document findings, and support response actions. * Develop, tune, test, and document security detections, hunting queries, and reporting logic using Kusto Query Language (KQL), Advanced Hunting, MITRE ATT&CK mapping, and approved change control or peer review practices. * Monitor the cybersecurity threat landscape for emerging threats and trends, support threat hunting and threat intelligence workflows, and collaborate with stakeholders to ensure relevant risks and indicators are incorporated into monitoring and response activities. * Collaborate with internal stakeholders to improve security posture through security policy and configuration reviews, validating patch and vulnerability management activities, and ensuring continuing monitoring for policy and control compliance. * Develop and maintain standard operating procedures, operating aids, runbooks, and knowledge base content to ensure cyber security monitoring and incident response activities are effective, efficient, repeatable, and consistent. * Collaborate with security assessments, internal penetration testing, audits, tabletop exercises, ransomware readiness activities, and other continuous improvement initiatives to validate and improve the effectiveness of security controls, processes, and response capabilities. * Collaborate with internal stakeholders to improve and perform Identity and Access Management (IAM) operations including monitoring, provisioning, access review support, and process improvement. * Train and coach team members performing information security roles, review work and practices, and help junior analysts improve investigation quality, ticket handling, documentation, escalation discipline, and technical decision making. * Understand and comply with all applicable Company policies and rules. Additional Functions: * Maintain regular and punctual attendance. * Attend in-person or virtual meetings as requested or required. * Communicate effectively and respectfully with others. * Other responsibilities as assigned., * Sitting: Continuously required to remain in a stationary position and perform desk-based tasks for hours at a time * Walking: Continuously required to remain in a stationary position and perform desk-based tasks for hours at a time * Communication: Frequently required to talk and hear, in person and by phone/conference calls. * Travel: Frequently required to travel and work extended hours when necessary. Required to travel overnight. * Observation/Eyesight: Infrequently required to observe details at close range including depth perception, peripheral vision, and the ability to differentiate between colors. * Lifting: Infrequently required to solo lift supplies weighing from 5 to 20 pounds and some operation of hand carts. * Enviromental & Hazardous Conditions * Frequently working indoors in an air-conditioned office-based environment., On the (Admin, HR, General Management, Strategy, IT, F&A, HSE, S&L) team, we are responsible for several core business functions and collaborate with departments across S&C to collectively achieve S&C''s mission. We are key players in facilitating how S&C provides long-term value to our employee owners. Always focused on the big picture of revolutionizing the energy sector, we take pride in the impact we have on S&C by empowering our team members to succeed. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)