Senior Cyber Security Analyst

S&C Electric CompanyChicago, IL
$105,940 - $140,376Remote

About The Position

The Information Technology team is responsible for designing, implementing, and maintaining a robust technology infrastructure to support the organization’s operations. Within IT, the IT Risk Management team improves cyber and information security and troubleshoots technical issues to drive innovation through modern solutions. ITRM ensures secure, reliable, and efficient systems aligned with business objectives. The Senior Cyber Security Operations Analyst is responsible for advanced cyber security monitoring, security analysis, incident response, case management, endpoint protection support, threat and vulnerability management support, identity and access management support, and information security process improvement. This role strengthens the Cyber Security Operations Center (CSOC) by performing Tier 2 and Tier 3 investigations, improving Microsoft Sentinel and Microsoft Defender XDR detections, using Kusto Query Language (KQL) to support investigations and reporting, supporting threat hunting and threat intelligence workflows, and collaborating with the MDR provider and internal teams to improve response quality and reduce security risk.

Requirements

  • Bachelor’s degree in Business Information Systems, Cyber Security, Computer Science, Computer Engineering, Business, or equivalent experience.
  • 5+ years of demonstrated experience working as a cyber security analyst or related role, with a track record of establishing, executing, improving, and/or assessing cyber security processes.
  • Demonstrated experience triaging security alerts, working cyber security cases, documenting investigations, and supporting incident response activities in a SOC, CSOC, MSSP, MDR, or enterprise security operations environment.
  • Proficient with Advanced Endpoint Detection and Response (AEDR), Security Information and Event Management (SIEM), and Microsoft security technologies such as Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID, and Microsoft collaboration applications.
  • Experience writing, reviewing, or using Kusto Query Language (KQL) for cyber security investigations, alert validation, hunting, reporting, and detection improvement.
  • Working knowledge of incident response, threat hunting, detection tuning, security monitoring, threat and vulnerability management, endpoint security, identity security, and cyber security case management practices.
  • Working knowledge of security-related frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-61, NIST 800-171, IEC 62443, NERC CIP, and Cybersecurity Model Certification (CMMC).
  • Familiarity with relevant privacy regulations, including the California Consumer Protection Act (CCPA), other U.S. State privacy laws, the European Union’s General Data Protection Regulation (GDPR), and other international privacy regulations.
  • Strong analytical skills related to cyber security threats, incident response, problem resolution, change management, and data-driven decision making.
  • Strong communication skills (written, verbal, listening, and presentation); able to translate technical findings into clear operational and business risk language for internal and external stakeholders.
  • Ability to independently collaborate with team members, subject matter experts, cross-functional teams, vendors, and stakeholders while following established escalation paths, RACIs, and operating procedures.
  • Strong customer service orientation with the ability to take initiative in pursuit of improved service, operational consistency, and measurable process improvement.
  • Excellent organizational skills and ability to prioritize tasks, manage ticket queues, meet deadlines, and communicate risks or blockers proactively.
  • Embraces change and has the ability to coach junior team members through change, ambiguity, and complex security investigations.
  • Experience developing process workflow diagrams using Visio or an equivalent tool.
  • Ability to travel as required.

Nice To Haves

  • Relevant cybersecurity certifications (e.g., CompTIA Security+, CySA+, Microsoft SC-200, Microsoft SC-100, GIAC GCIH, GCFA, GCTI, SSCP, CISSP, CCNA, or equivalent.)
  • Experience with Microsoft Sentinel content management, detection lifecycle practices, Advanced Hunting, ASIM, automation rules, Logic Apps, or related SOAR capabilities.
  • Experience with cyber threat hunting, MITRE ATT&CK mapping, threat intelligence analysis, and translating threat intelligence or penetration test findings into monitoring improvements.
  • Experience in command line scripting and implementation using PowerShell, Python, or similar scripting languages for automation, enrichment, and analysis.
  • Experience using internal penetration testing, breach-and-attack simulation, or security validation platforms such as Horizon3 Node Zero or similar tools.
  • Experience working alongside a Managed Detection and Response (MDR) provider in a shared-responsibility operating model.
  • Exposure to operational technology (OT), industrial control system (ICS), manufacturing, energy, or critical infrastructure environments.

Responsibilities

  • Perform cybersecurity analysis and reporting from security monitoring tools, triage security events, determine operational impact, and participate in or coordinate incident response actions as necessary.
  • Work Tier 2 and Tier 3 CSOC queue, including escalations, alerts, security events, and incidents.
  • Use incident response tooling and related security telemetry to investigate alerts, validate activity, document findings, and support response actions.
  • Develop, tune, test, and document security detections, hunting queries, and reporting logic using Kusto Query Language (KQL), Advanced Hunting, MITRE ATT&CK mapping, and approved change control or peer review practices.
  • Monitor the cybersecurity threat landscape for emerging threats and trends, support threat hunting and threat intelligence workflows, and collaborate with stakeholders to ensure relevant risks and indicators are incorporated into monitoring and response activities.
  • Collaborate with internal stakeholders to improve security posture through security policy and configuration reviews, validating patch and vulnerability management activities, and ensuring continuing monitoring for policy and control compliance.
  • Develop and maintain standard operating procedures, operating aids, runbooks, and knowledge base content to ensure cyber security monitoring and incident response activities are effective, efficient, repeatable, and consistent.
  • Collaborate with security assessments, internal penetration testing, audits, tabletop exercises, ransomware readiness activities, and other continuous improvement initiatives to validate and improve the effectiveness of security controls, processes, and response capabilities.
  • Collaborate with internal stakeholders to improve and perform Identity and Access Management (IAM) operations including monitoring, provisioning, access review support, and process improvement.
  • Train and coach team members performing information security roles, review work and practices, and help junior analysts improve investigation quality, ticket handling, documentation, escalation discipline, and technical decision making.
  • Understand and comply with all applicable Company policies and rules.
  • Maintain regular and punctual attendance.
  • Attend in-person or virtual meetings as requested or required.
  • Communicate effectively and respectfully with others.
  • Other responsibilities as assigned.

Benefits

  • Medical & Prescription
  • Dental
  • Vision
  • Health Care and Dependent Care Flexible Spending Accounts
  • Health Savings Account (HSA)
  • Group Life Insurance
  • Optional Supplemental Life and AD&D Insurance
  • Wellbeing Resources including Employee Assistance Program
  • Family Forming Benefits (i.e., Adoption and Fertility support)
  • Vacation Time
  • Sick Time
  • Paid Holidays
  • Company Shutdown days
  • Short-Term Disability
  • Long-Term Disability
  • Other Leaves
  • Paid Parental Time
  • Military Leave
  • 401(k) Retirement Savings and Employee Stock Ownership Plan (KSOP) offering traditional and Roth 401(k) options and an Employee Stock Ownership Plan (ESOP) component
  • Annual incentive plan (AIP)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service