Security Operations Senior Analyst
AlixPartnersAbout the role
At AlixPartners, we solve the most complex and critical challenges by moving quickly from analysis to action when it really matters; creating value that has a lasting impact on companies, their people, and the communities they serve. By understanding, respecting, and honoring the needs of our employees, clients, and communities, AlixPartners actively promotes an inclusive environment. We strongly believe in the value that diversity brings to our experiences and are committed to the perpetual enhancements of initiatives, policies, and practices. We hold ourselves accountable by providing the space for authenticity, growth, and equity for everyone.
AlixPartners has embraced a hybrid work model to provide flexibility and support our employees’ work-life integration. Our hybrid model combines a mix of in-person at an AlixPartners office on Tuesday, Wednesday, & Thursday and remote working options for Monday and Friday.
LOCATION: Southfield, MI
What you’ll do
As a member of the Information Security (IS) team, you will contribute to the overall cyber defense of information assets and will conduct security monitoring, detection engineering, threat hunting, security posture analysis, and perform incident response investigations.
The ideal candidate will have technical depth in the Microsoft security stack, which would include practical use of the Kusto Query Language (KQL) to perform day to day work. The AlixPartners Security Operations team heavily uses KQL for detection engineering, threat hunting, performing data analysis to improve security posture, and more. A background in Splunk Search Processing Language (SPL), or similar, may also be considered. Tools a candidate has experience with may include Microsoft Sentinel, Defender for Cloud Apps, Defender for Identity, Secure Score, Defender for Cloud, and a strong understanding of Azure and Entra ID.
The Security Operations Senior Analyst is a full-time position located in Southfield, MI, reporting to the Security Operations Team Lead. Paid relocation is not available.
- Respond to, investigate, and analyze security events to determine appropriate actions
- Analyze security system logs, security tools, and available data sources on to identify attacks against the enterprise and report on irregularities, issues related to improper access patterns, trending, and event correlations
- Conduct and apply detection engineering concepts to analyze, create, and tune detection logic and telemetry to ensure effective coverage and detection of existing and emerging threats
- Perform security posture analysis to improve overall IT ecosystem utilizing telemetry from security tools (Secure Score, KQL analysis, custom reporting etc.)
- Gather information from other IT and non-IT staff to obtain information regarding security problems to networks, servers, endpoints, and applications
- Perform incident response activities and ensure that proper protection or corrective measures have been taken when an incident has been discovered
- Assist with administration of information security controls and software such as endpoint protection, endpoint detection and response, intrusion detection/prevention (IDS/IPS), security incident and event management (SIEM), and physical security systems
- Expected to stay current on security industry trends, new threats and attack techniques, mitigation techniques, and emerging security technologies
- Provide insight and participate in security projects to evaluate and recommend security products for various applications and platforms throughout the organization while supporting business initiatives
- Assist with the development, maintenance of, and training on technical documentation and Standard Operating Procedures (SOP)
- Improve security efficiency and streamline/automate work processes while working collaboratively with other team members and IT staff to accomplish objectives
- Participate in critical incidents and implementation reviews
- Additional responsibilities as identified. This description is not designed to encompass a comprehensive listing of required activities, duties, or responsibilities
What you’ll need
- Highly motivated to work in information security
- Minimum four (4) years of Information Security experience, or experience working in Information Technology
- Bachelor’s degree in Information Technology or related field preferred; work experience and background may be considered in lieu of formal education
- Proven experience creating detection logic, SIEM rules, custom detections within EDR tools, etc.
- Cloud security experience within Azure or other platforms (AWS, GCP)
- Collaborative interpersonal skills with the ability to work well as an individual and as part of a team
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s