Sr Information Security Analyst

PerrigoAllegan Township, MI
Hybrid

About The Position

The Senior Information Security Analyst is a senior individual contributor within the Cyber Defense team responsible for leading security investigations, incident response, threat detection and hunting, and the continuous improvement of enterprise security operations. The role works across endpoint, identity, email, cloud, and data security technologies to identify, contain, and remediate threats. The successful candidate will be an experienced, hands-on security professional who can independently lead complex investigations, improve detections and response processes, mentor other analysts, and take ownership of key Cyber Defense capabilities. Experience with data loss prevention (DLP) and data security is strongly preferred.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field, or equivalent professional experience
  • 7+ years of relevant cybersecurity experience, including significant hands-on security operations, incident response, threat detection, or threat hunting experience
  • Demonstrated ability to independently investigate and lead complex cybersecurity incidents
  • Hands-on experience with enterprise SIEM and EDR/XDR technologies
  • Strong understanding of endpoint, identity, network, email, and cloud attack techniques
  • Working knowledge of Active Directory and Microsoft Entra ID security concepts
  • Strong analytical, troubleshooting, documentation, and communication skills

Nice To Haves

  • CrowdStrike Falcon, including EDR and/or Identity Protection
  • Splunk Enterprise Security, CrowdStrike Next-Gen SIEM, Microsoft Sentinel, or comparable enterprise SIEM platforms
  • Cortex XSOAR or comparable SOAR/security automation platforms
  • Microsoft 365 and Entra ID security investigations
  • Enterprise DLP/data security technologies such as Proofpoint, Microsoft Purview, or comparable platforms
  • Email security and account-takeover investigation
  • PowerShell, Python, SPL, KQL, or other scripting/query languages used for security investigation and automation
  • Threat intelligence, vulnerability/exposure management, and hybrid enterprise environments

Responsibilities

  • Lead investigation, containment, remediation, and post-incident review of cybersecurity incidents across endpoint, identity, email, cloud, and network environments
  • Investigate suspicious activity using SIEM, EDR/XDR, identity, email security, and other enterprise security telemetry
  • Develop incident timelines, determine scope and root cause, document findings, and communicate risk and recommended actions to technical and leadership stakeholders
  • Perform proactive threat hunting and identify opportunities to improve detection and response coverage
  • Serve as an escalation point and mentor for other security analysts during complex investigations
  • Develop, tune, and improve security detections and correlation logic based on threats, incidents, and observed control gaps
  • Use enterprise SIEM platforms to investigate threats, hunt across security telemetry, and improve monitoring coverage
  • Support security orchestration and automation use cases, including playbooks for investigation, enrichment, containment, and notification
  • Identify repetitive SOC processes that can be automated or streamlined
  • Investigate endpoint threats using CrowdStrike Falcon or comparable enterprise EDR/XDR platforms
  • Investigate identity-based attacks involving Active Directory, Microsoft Entra ID, authentication, privileged accounts, OAuth applications, and session/token abuse
  • Analyze Microsoft 365 and cloud security events and work with engineering and infrastructure teams on containment and remediation
  • Use threat intelligence and indicators of compromise to scope incidents and proactively hunt for related activity
  • Support and improve enterprise DLP and data security monitoring across endpoint, email, cloud, and collaboration platforms
  • Investigate potential data-loss, sensitive-data exposure, and policy-violation events and coordinate appropriate response
  • Assist with tuning DLP policies and workflows to improve detection quality while reducing unnecessary business impact
  • Partner with security, privacy, legal, and business stakeholders as appropriate during sensitive-data investigations
  • Identify gaps discovered through incidents, threat hunting, and operational analysis and recommend practical improvements
  • Develop and maintain investigation procedures, response playbooks, and operational documentation
  • Collaborate with Security Engineering, IAM, Network, Cloud, and other technology teams to strengthen preventive and detective controls
  • Take ownership of assigned Cyber Defense technologies or operational capabilities and drive their continued maturity

Benefits

  • Competitive compensation
  • Benefits tailored to supporting you and your family
  • Career development opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service