As an S&C Electric team member, you’ll work on projects that have real-world impact. You’ll help transform the grid for resilient and reliable power worldwide. S&C has more than a 100-year history of innovation and has been 100% employee-owned since 2012. We continue this legacy as a trusted, forward-thinking leader in the electrical industry. You will advance a safer, more reliable, and more resilient electrical grid. Our products help the grid adapt to severe weather and transition to clean energy. We’re big enough to be a respected industry leader but small enough for you to impact our company directly. Our commitment gives you opportunities to impact on and off the job positively.
Join S&C to make an impact on tomorrow’s energy challenges and become an employee-owner!
Hours
- 8:00 am-5:00 pm (Monday-Friday) Remote
- Hybrid option available for Chicago-area candidates
- 365 days a year support
Compensation
At S&C, we are dedicated to providing competitive and equitable compensation for all our team members, and we are committed to transparency in our pay practices. The estimated annual base salary range for this position is $105,940-$140,375.80. Individual pay within this salary range is determined by several compensable factors, including performance, knowledge, job-related skills and experience, and relevant education or training. This role is also eligible for S&C’s annual incentive plan (AIP), subject to eligibility criteria.
Join Our Team as a Senior Cyber Security Operations Analyst!
Are you passionate about Senior Cyber Security Operations? The Information Technology team is responsible for designing, implementing, and maintaining a robust technology infrastructure to support the organization’s operations. Within IT, the IT Risk Management team improves cyber and information security and troubleshoots technical issues to drive innovation through modern solutions. ITRM ensures secure, reliable, and efficient systems aligned with business objectives.
The Senior Cyber Security Operations Analyst is responsible for advanced cyber security monitoring, security analysis, incident response, case management, endpoint protection support, threat and vulnerability management support, identity and access management support, and information security process improvement. This role strengthens the Cyber Security Operations Center (CSOC) by performing Tier 2 and Tier 3 investigations, improving Microsoft Sentinel and Microsoft Defender XDR detections, using Kusto Query Language (KQL) to support investigations and reporting, supporting threat hunting and threat intelligence workflows, and collaborating with the MDR provider and internal teams to improve response quality and reduce security risk
Job Responsibilities:
- Perform cybersecurity analysis and reporting from security monitoring tools, triage security events, determine operational impact, and participate in or cordinate incident response actions as necessary.
- Work Tier 2 and Tier 3 CSOC queue, including escalations alerts, security events, and incidents.
- Use incident response tooling and related security telemetry to investigate alerts, validate activity, document findings, and support response actions.
- Develop, tune, test, and document security detections, hunting queries, and reporting logic using Kusto Query Language (KQL), Advanced Hunting, MITRE ATT&CK mapping, and approved change control or peer review practices.
- Monitor the cybersecurity threat landscape for emerging threats and trends, support threat hunting and threat intelligence workflows, and collaborate with stakeholders to ensure relevant risks and indicators are incorporated into monitoring and response activities.
- Collaborate with internal stakeholders to improve security posture through security policy and configuration reviews, validating patch and vulnerability management activities, and ensuring continuing monitoring for policy and control compliance.
- Develop and maintain standard operating procedures, operating aids, runbooks, and knowledge base content to ensure cyber security monitoring and incident response activities are effective, efficient, repeatable, and consistent.
- Collaborate with security assessments, internal penetration testing, audits, tabletop exercises, ransomware readiness activities, and other continuous improvement initiatives to validate and improve the effectiveness of security controls, processes, and response capabilities.
- Collaborate with internal stakeholders to improve and perform Identity and Access Management (IAM) operations including monitoring, provisioning, access review support, and process improvement.
- Train and coach team members performing information security roles, review work and practices, and help junior analysts improve investigation quality, ticket handling, documentation, escalation discipline, and technical decision making.
- Understand and comply with all applicable Company policies and rules.
Additional Functions:
- Maintain regular and punctual attendance.
- Attend in-person or virtual meetings as requested or required.
- Communicate effectively and respectfully with others.
- Other responsibilities as assigned.
Education and Certifications/Licenses
Required
Bachelor’s degree in Business Information Systems, Cyber Security, Computer Science, Computer Engineering, Business, or equivalent experience.
Preferred
Relevant cybersecurity certifications (e.g., CompTIA Security+, CySA+, Microsoft SC-200, Microsoft SC-100, GIAC GCIH, GCFA, GCTI, SSCP, CISSP, CCNA, or equivalent.)
What you''ll need to succeed:
- 5+ years of demonstrated experience working as a cyber security analyst or related role, with a track record of establishing, executing, improving, and/or assessing cyber security processes.
- Demonstrated experience triaging security alerts, working cyber security cases, documenting investigations, and supporting incident response activities in a SOC, CSOC, MSSP, MDR, or enterprise security operations environment.
- Proficient with Advanced Endpoint Detection and Response (AEDR), Security Information and Event Management (SIEM), and Microsoft security technologies such as Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID, and Microsoft collaboration applications.
- Experience writing, reviewing, or using Kusto Query Language (KQL) for cyber security investigations, alert validation, hunting, reporting, and detection improvement.
- Working knowledge of incident response, threat hunting, detection tuning, security monitoring, threat and vulnerability management, endpoint security, identity security, and cyber security case management practices.
- Working knowledge of security-related frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-61, NIST 800-171, IEC 62443, NERC CIP, and Cybersecurity Model Certification (CMMC).
- Familiarity with relevant privacy regulations, including the California Consumer Protection Act (CCPA), other U.S. State privacy laws, the European Union’s General Data Protection Regulation (GDPR), and other international privacy regulations.
- Strong analytical skills related to cyber security threats, incident response, problem resolution, change management, and data-driven decision making.
- Strong communication skills (written, verbal, listening, and presentation); able to translate technical findings into clear operational and business risk language for internal and external stakeholders.
- Ability to independently collaborate with team members, subject matter experts, cross-functional teams, vendors, and stakeholders while following established escalation paths, RACIs, and operating procedures.
- Strong customer service orientation with the ability to take initiative in pursuit of improved service, operational consistency, and measurable process improvement.
- Excellent organizational skills and ability to prioritize tasks, manage ticket queues, meet deadlines, and communicate risks or blockers proactively.
- Embraces change and has the ability to coach junior team members through change, ambiguity, and complex security investigations.
- Experience developing process workflow diagrams using Visio or an equivalent tool.
- Ability to travel as required.
Preferred
- Experience with Microsoft Sentinel content management, detection lifecycle practices, Advanced Hunting, ASIM, automation rules, Logic Apps, or related SOAR capabilities.
- Experience with cyber threat hunting, MITRE ATT&CK mapping, threat intelligence analysis, and translating threat intelligence or penetration test findings into monitoring improvements.
- Experience in command line scripting and implementation using PowerShell, Python, or similar scripting languages for automation, enrichment, and analysis.
- Experience using internal penetration testing, breach-and-attack simulation, or security validation platforms such as Horizon3 Node Zero or similar tools.
- Experience working alongside a Managed Detection and Response (MDR) provider in a shared-responsibility operating model.
- Exposure to operational technology (OT), industrial control system (ICS), manufacturing, energy, or critical infrastructure environments.
Physical Requirements
- Sitting: Continuously required to remain in a stationary position and perform desk-based tasks for hours at a time
- Walking: Continuously required to remain in a stationary position and perform desk-based tasks for hours at a time
- Communication: Frequently required to talk and hear, in person and by phone/conference calls.
- Travel: Frequently required to travel and work extended hours when necessary. Required to travel overnight.
- Observation/Eyesight: Infrequently required to observe details at close range including depth perception, peripheral vision, and the ability to differentiate between colors.
- Lifting: Infrequently required to solo lift supplies weighing from 5 to 20 pounds and some operation of hand carts.
- Enviromental & Hazardous Conditions
- Frequently working indoors in an air-conditioned office-based environment.
Disclaimers
This job description is not an exhaustive list of all functions that the team member may be required to perform, and the team member may be required to perform additional functions either temporarily or on an ongoing basis.
The Company reserves the right to revise this job description at any time and to change or eliminate this position.
The team member must be able to perform the essential functions of the position satisfactorily.
Team Member Acknowledgment
I have read this job description, and I understand my responsibilities and the job’s essential functions. I am able to perform the essential functions and responsibilities outlined. I understand that the responsibilities, duties, and essential functions of this job may change on a temporary or ongoing basis according to the Company’s needs or business decisions, and that, if so, I may be required to perform additional duties, responsibilities, and functions. If I have questions about duties, responsibilities, and functions, I may discuss them with my supervisor or an appropriate member of the HR team.
No Fixed Deadline.