Security Operations Remote Jobs in Michigan (US)
This page tracks remote security operations openings that are location-eligible for Michigan.
This page tracks remote security operations openings that are location-eligible for Michigan.
Open jobs
223
Hiring companies this week
8
Salary sample
$88,000 - $245,000
Jobs added last hour
0
223 Jobs
175 Companies
• Monitor, investigate and respond to security events, alerts and incidents across corporate, QA, staging and production environments • Execute vulnerability operations including intake, prioritization, tracking and remediation coordination in an AI-forward environment • Support IAM program through access changes, privileged access controls, access reviews and control validation • Maintain and improve security runbooks, workflows, documentation and operational procedures • Identify operational gaps and recommend practical improvements that strengthen coverage, response and alignment to best practices • Partner with IT, Engineering and business teams to address security issues across internal and customer-facing environments • Manage work in Jira, including ticket updates, prioritization, workflow discipline and backlog execution • Participate in on-call incident response as needed
• Utilizes SIEM/XDR/EDR tools (AlienVault USMA/LevelBlue, LogRhythm, Microsoft Sentinel, Splunk CrowdStrike, etc.) to monitor alerts and security events of client networks and systems. • Identifies, analyzes, and responds to security incidents as they occur. • Collaborates and leverages their cybersecurity knowledge working alongside a team of skilled analysts to address potential threats within a 24x7 SOC. • Crafts escalations to clients for potential threats that include value-added and root cause analysis with recommendations for remediation. • Continually improves cybersecurity and information security expertise. • Performs other related duties as assigned.
• Helping to develop architectural requirements and corresponding engineering processes and technologies to support Collibra’s cloud-native platform • Design and tune cloud-native detection rules and threat models for AWS GuardDuty, Microsoft Defender for Cloud, and GCP Security Command Center • Conduct continuous vulnerability assessments of cloud workloads, container images, and serverless functions • Develop, continuously improve, and ensure compliance with controls built for the cloud-native platform • Partner with engineering teams to prioritize and drive remediation of cloud security findings • Plan, organize, and manage multiple responsibilities from various stakeholders and sometimes competing requests to achieve desired objectives • Maintain and update CloudFlare WAF rules to work with the Collibra product. • Evaluate and deploy cloud workload protection platforms (CWPP) and container security tooling • Assist with technical response efforts for cloud security incidents, perform forensic analysis, and contribute to root-cause investigation • Write production-quality code in Python, Golang/Go, or similar languages to build internal security tooling and automation • Integrate security tooling into developer workflows to reduce friction while improving security outcomes • After hours on-call support may occasionally be required
Consulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.
Role Description At ProArch, a leader in IT security consulting with presence in the US, UK, and India, we are looking for a skilled L3 SOC Analyst / Incident Response Analyst to join our Security Operations Center (SOC) team. In this critical role, you will be responsible for advanced incident detection, investigation, and response to complex cybersecurity threats. Leveraging your extensive experience and expertise, you will lead incident response activities, perform deep-dive analysis, and coordinate with cross-functional teams to mitigate risks and strengthen our security posture. This role is heavily focused on: - Incident Response - Threat Investigation - Detection Engineering - DFIR Operations - SOC Automation - Threat Hunting - Security Platform Engineering - Response Workflow Optimization The ideal candidate combines strong incident response expertise, deep Microsoft security platform knowledge, hands-on detection engineering capability, and SOC automation experience within a fast-paced MSSP environment. This is not a traditional alert-monitoring SOC Analyst role. The position requires strong investigative, analytical, and response-oriented cybersecurity capabilities. Key Responsibilities - Incident Response & Threat Investigation - Lead and support advanced security incident investigations across multiple customer environments - Perform: - Threat triage and validation - IOC analysis and threat correlation - Endpoint and identity investigations - Email security investigations - Cloud security incident analysis - Root cause analysis - Investigate and respond to: - Account compromise incidents - Business Email Compromise (BEC) - Malware and ransomware activity - Privilege escalation - Lateral movement activity - Suspicious cloud and identity-based attacks - Advanced phishing and social engineering campaigns - Coordinate containment, remediation, and recovery activities with customer and internal teams - Support high-severity incident escalation handling and response coordination - Provide detailed investigation findings, timelines, impact assessments, and response recommendations - Conduct proactive threat hunting and threat validation activities where required - Support digital forensics and evidence collection activities when applicable - Detection Engineering & SIEM Operations - Design, develop, and maintain advanced detection rules across: - Microsoft Sentinel - Microsoft Defender XDR - Develop and optimize: - KQL queries - Analytics rules - Correlation logic - Detection use cases - Perform: - Detection tuning - False positive reduction - Behavioral baselining - Threat-based detection improvements - Build and maintain reusable detection content and query libraries - Support proactive detection engineering initiatives aligned with emerging threats and attacker techniques - Leverage threat intelligence and MITRE ATT&CK mapping to improve detection coverage - SOC Automation & SOAR Engineering - Design and implement SOC automation workflows using: - Microsoft Sentinel Playbooks - Logic Apps - SOAR platforms - API-driven integrations - Build workflows for: - Alert enrichment - Incident routing - Automated containment actions - Threat intelligence enrichment - Ticket synchronization - Investigation acceleration - Develop scalable automation frameworks to improve SOC operational efficiency - Support continuous optimization of SOC workflows and automation coverage - Create automation standards and reusable workflow templates across customer environments - Microsoft Security Platform Operations - Provide hands-on operational support, investigation, tuning, administration, and engineering for: - Microsoft Defender for Endpoint (MDE) - Microsoft Defender XDR - Microsoft Defender for Identity (MDI) - Microsoft Defender for Office 365 (MDO) - Microsoft Defender for Cloud Apps (MDCA) - Microsoft Purview - Microsoft Identity Protection / Entra ID - Microsoft Sentinel - Additional technologies include: - CrowdStrike Falcon - Threat Intelligence platforms - Email security solutions - Endpoint Detection & Response (EDR) platforms - Identity and authentication platforms - Cloud security solutions - Ticketing platforms (Datto Autotask preferred) - AI Security & Modern Threat Operations - Support detection and response activities related to: - AI-orchestrated attacks - Identity-based attacks - Cloud-native threats - Advanced phishing and social engineering campaigns - Leverage AI-assisted SOC operations and automation capabilities where applicable - Support modern detection strategies aligned with evolving attacker techniques - Evaluate opportunities to integrate AI-driven efficiencies into detection, investigation, and response workflows - Client & Operational Support - Participate in customer incident discussions and escalation calls when required - Support onboarding of new customer environments and security integrations - Maintain: - Investigation playbooks - SOPs - Workflow documentation - Operational runbooks - Detection documentation - Collaborate closely with: - SOC Operations - Security Engineering - Vendors - Consulting teams - Customer stakeholders - Support operational improvement initiatives across SOC and DFIR functions Qualifications - Bachelor’s Degree / Graduation in: Computer Science/Information Technology/Cybersecurity or related technical field is mandatory - Relevant cybersecurity and automation-focused certifications will be considered an added advantage. - 6-9 years of overall cybersecurity experience - Strong hands-on experience in: - Incident Response - Threat Investigation - SOC Operations - Detection Engineering - DFIR activities - Prior Incident Response Analyst experience is highly preferred - Experience working within MSSP environments preferred - Experience supporting or collaborating with US-based teams/vendors preferred - Proven hands-on experience with SOAR platforms in enterprise or MSSP environments - Strong experience designing and implementing SOC automation workflows from scratch - Experience supporting enterprise Security Operations Center (SOC) environments - Experience with detection engineering and SIEM rule development Requirements - Strong hands-on experience with: - Microsoft Defender for Endpoint (MDE) - Microsoft Defender XDR - Microsoft Defender for Identity (MDI) - Microsoft Defender for Office 365 (MDO) - Microsoft Defender for Cloud Apps (MDCA) - Microsoft Purview - Microsoft Identity Protection / Entra ID - CrowdStrike Falcon - Threat Intelligence platforms - Microsoft Sentinel (Mandatory) - Defender XDR SIEM operations (Mandatory) - Graph API - Datto Autotask or equivalent ticketing systems - Email security solutions - Endpoint Detection & Response (EDR) platforms - Identity and authentication platforms - Cloud security technologies - Strong experience creating: - Detection rules - Analytics rules - KQL queries - Detection tuning and fine-tuning - Experience with: - SOC workflow design - SOC automation - SOAR engineering - API integrations - Workflow orchestration - Understanding of: - MITRE ATT&CK - Threat detection methodologies - Threat hunting methodologies - AI-driven attack techniques - AI use cases in SOC operations - Preferred experience with: - PowerShell - Python - REST APIs - Logic Apps - KQL (Mandatory) Preferred Certifications - Microsoft SC-200 - Microsoft SC-401 - Microsoft AZ-500 - Microsoft SC-900 - Microsoft SC-100 - CISSP - Security Automation / SOAR Automation / SOAR Certifications Soft Skills & Work Style - Strong verbal and written communication skills with the ability to work effectively across technical and non-technical teams - Excellent collaboration and stakeholder coordination skills across SOC Operations, Engineering, Consulting, Vendors, and Leadership teams - Strong documentation and technical writing capabilities for investigations, workflows, SOPs, and operational procedures - Ability to work independently in a remote-first, multicultural, and fast-paced MSSP environment - Self-driven, proactive, and highly organized with strong ownership and accountability - Strong analytical, troubleshooting, and problem-solving skills - Comfortable managing multiple projects, priorities, and operational initiatives simultaneously - Team-oriented mindset with the ability to operate effectively as an individual contributor - Professional communication and coordination skills for working with US-based teams and vendors - Adaptable and flexible to evolving operational and business requirements Working Model - Rotational Shift (US Business Hours or After Hours) - Remote-first operational model - Participation in on-call escalation rotation for critical incidents when required What Success Looks Like - High-quality incident investigations and response handling - Improved detection fidelity and reduced false positives - Increased SOC automation coverage and operational efficiency - Faster containment and response coordination - Consistent and high-quality incident response across customer environments - Strong collaboration across SOC, Engineering, and Customer teams - Continuous improvement of detection, automation, and DFIR capabilities
Fresenius Medical Care provides dialysis treatments, products, and services for individuals living with chronic kidney diseases (CKD). Founded as a result of the 1996 merger of Fre
Role Description - Monitor and assess alerts, cases, and reports for potential privacy incidents (e.g., unauthorized access, data exfiltration, misdirected communications). - Perform initial triage to classify incidents involving Personal Data (PII/PHI). - Lead or support end-to-end investigation of privacy incidents. - Analyze impacted data elements, systems, and individuals; determine root cause and scope of exposure. - Document incident findings in accordance with legal and compliance requirements. - Evaluate breach thresholds under regulations (HIPAA, GDPR, state breach laws). - Coordinate with Legal on breach notification obligations. - Support preparation of regulatory filings and communications to affected individuals. - Participate in incident response war rooms and crisis management efforts. - Ensure alignment between technical containment and privacy obligations. - Maintain detailed incident records and case documentation. - Track incident metrics (e.g., time to detect/respond, incident trends). - Provide reporting to leadership, regulators, and audit teams. - Enhance privacy incident response playbooks and workflows. - Conduct tabletop exercises and training sessions. - Contribute to privacy program maturity and continuous improvement initiatives. - Participate in projects collaborating with stakeholders as needed. - Monitor the Privacy Office inbox and provide timely guidance and responses to inquiries. - Develop and deliver privacy training and awareness initiatives to promote a culture of data protection and compliance. - Draft and review privacy policies and procedures to ensure alignment with applicable regulations and organizational standards. Qualifications - Bachelor’s degree in Cybersecurity, Information Security, Law, Privacy, Healthcare or related field (or equivalent experience). Requirements - 5+ years of experience in Privacy Operations. - Experience building or leading a Privacy Incident Response function preferred. - Direct interaction with regulators or auditors. - Knowledge of data mapping, data governance, and privacy engineering. - Handling data breach or privacy incidents. - Strong understanding of data protection regulations (HIPAA, GDPR, CCPA, etc.). - Familiarity with privacy principles and data classification. - Understanding of the incident response lifecycle (NIST/SANS framework familiarity). - Certifications such as: - CIPP (US/E, or equivalent) - CIPM / CIPT - CISSP, CISM, or GIAC (GCIA, GCIH) - Certified Healthcare Compliance Professional (CHC) or Certified Healthcare Privacy Compliance (CHPC) - Experience in healthcare or other regulated industries. Benefits - Comprehensive benefits package including medical, dental, and vision insurance. - 401(k) with company match. - Paid time off. - Parental leave. Company Description Fresenius Medical Care is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sexual orientation, gender identity, parental status, national origin, age, disability, military service, or other non-merit-based factors.
DSV is a global leader in transport and logistics, evolving to become the world's 3rd largest supplier of global solutions within transport and logistics. We operate in more than 80 countries, ensuring a steady supply of goods to production lines, outlets, stores, and consumers worldwide.
Role Description The Director of Network Security Operations will lead the strategy, governance, implementation, and operational sustainment of physical and operational security programs across DSV’s North American Contract Logistics network, High Tech 2 vertical. This role is responsible for ensuring facilities, infrastructure, systems, and operational practices comply with enterprise and customer security standards — particularly for high-security warehousing environments supporting critical infrastructure, sensitive inventory, and restricted operational zones. The leader will drive a scalable and audit-ready security operating model across a geographically dispersed logistics network while partnering closely with operations, engineering, IT, facilities, customer security teams, and third-party security providers. The role requires strong leadership through influence across highly matrixed stakeholder groups. Key Responsibilities - Security Operations & Governance - Develop and maintain security governance programs aligned to customer and enterprise security requirements - Ensure operational compliance with: - Zone-based access control methodologies - Critical component handling protocols - Chain-of-custody standards - Security incident management procedures - Physical infrastructure protection requirements - Establish scalable security standards across site-types, supporting varying operational risk profiles - Security Systems & Infrastructure - Lead strategy and operational oversight for: - Access control systems - CCTV/video surveillance infrastructure - Intrusion detection systems - Alarm monitoring - Security command center operations - Ensure security systems meet operational and compliance standards for: - Video retention - DORI coverage requirements - Environmental monitoring - UPS and generator-backed resiliency - Network segregation requirements - Partner with IT and engineering teams to ensure secure deployment and sustainment of: - Security hardware - Approved device standards - Integrated monitoring solutions - Access management systems - Oversee security vendor relationships, system integrators, and guard force providers - Incident Response & Risk Management - Lead development and execution of network-wide: - Security incident response plans - Escalation procedures - Business continuity support protocols - Emergency response coordination - Ensure all incidents involving restricted areas, critical components, or infrastructure are investigated, documented, and resolved in accordance with defined protocols - Establish risk assessment and audit programs supporting: - Quarterly physical security assessments - Security system testing - Compliance reviews - Corrective action management - Lead root cause analysis and mitigation planning for security vulnerabilities or operational gaps - Operational Partnership & Stakeholder Management - Drive accountability across operational partners with and without direct authority - Partner closely with: - Site Operations Leadership - IT & Infrastructure teams - Engineering & Facilities - Customer security organizations - Legal, HR, and Compliance teams - Support customer audits, compliance reviews, and security program presentations - Continuous Improvement & Program Development - Establish KPIs and scorecards for: - Security compliance - Incident trends - Access management - Audit performance - Security system uptime - Drive continuous improvement initiatives focused on: - Risk reduction - Process standardization - Security automation - Operational scalability - Develop long-term security roadmap supporting business growth, customer requirements, and evolving threat landscapes Qualifications - 10–15+ years in physical security, security operations, supply chain security, or critical infrastructure protection - 5+ years leading enterprise or multi-site security operations programs - Experience supporting: - High-security warehousing environments - Critical infrastructure operations - Data center or technology supply chain security - Regulated or highly controlled operational environments - Proven experience implementing and sustaining: - Zone-based security frameworks - Access control governance - CCTV and surveillance programs - Security incident management processes - Experience driving compliance within matrixed operational organizations - Strong executive presence and stakeholder management capability - Ability to drive operational compliance through both influence and direct ownership - Excellent crisis management and decision-making capability - Strong analytical and risk-based problem-solving skills - Ability to balance operational efficiency with stringent security requirements Technical & Functional Skills - Strong understanding of: - Physical access control systems - CCTV/video surveillance platforms - Security Operations Center (SOC) environments - Alarm monitoring systems - Critical infrastructure protection - Experience with: - Badge access systems - Dual-authentication security controls - Chain-of-custody processes - Security audit and compliance programs - Incident response management - Familiarity with: - WMS and warehouse operational environments - Network/server room security controls - UPS and environmental monitoring systems - Security system resiliency standards - Advanced proficiency in: - Excel - Power BI/Tableau - Security reporting and incident management platforms Travel - Expected 20-30% travel Compensation For this position, the expected base pay range is $160,783.00 – $200,979.00 Annual. Actual compensation will be determined based on job-related factors such as relevant experience, skills, education, certifications, and geographic location, in accordance with applicable laws and company policy. Benefits Information regarding DSV’s benefits offerings, including eligibility, coverage options, and plan details, is available through the DSV Benefits Showcase. Benefits, programs, and eligibility may vary by location and division in accordance with applicable state and local laws. Company Description DSV - Global transport and logistics In 1976, ten independent hauliers joined forces and founded DSV in Denmark. Since then, DSV has evolved to become the world's 3rd largest supplier of global solutions within transport and logistics. Today, we add value to our customers' entire supply chain by transporting, storing, packaging, re-packaging, processing and clearing all types of goods. We work every day from our many offices in more than 80 countries to ensure a steady supply of goods to production lines, outlets, stores and consumers all over the world. Our reach is global yet our presence is local and close to our customers.
• Conduct threat modeling and security design reviews for new features • Perform secure code reviews and provide actionable feedback • Deploy and maintain security tooling across the development lifecycle • Partner with platform engineering on infrastructure and environment security • Contribute to incident response for security events • Drive vulnerability triage and prioritization across teams • Partner with sales and legal responding to customer and vendor questionnaires • Support compliance audit cycles by gathering evidence and documenting controls • Monitor and respond to alerts from endpoint, cloud, and application security tools • Maintain and improve security runbooks and process documentation
Phreesia empowers patients to take an active role in their health and achieve better outcomes.
• Own enterprise-wide security incident response —ensure the team can detect, triage, contain, eradicate, and recover from incidents across cloud, on-prem, SaaS, and endpoint environments with speed and precision. • Maintain and continuously improve the incident response plan, playbooks, escalation procedures, and communication templates, ensuring they are tested, current, and aligned to NIST CSF 2.0. • Serve as incident commander or executive sponsor for high-severity incidents; make real-time decisions on containment and remediation under pressure. • Coordinate threat response across US and India teams, ensuring consistent coverage, quality, and process regardless of geography. • Own the security and IT tooling portfolio across the company: endpoint management (MDM, EDR), identity infrastructure, SIEM/SOAR, network security, vulnerability scanning, email security, cloud security posture management, and related platforms. • Build and maintain operational metrics and dashboards that provide the CISO and leadership with clear visibility into incident trends, MTTD/MTTR, tool health, SLA performance, and infrastructure posture.
• Work closely with system owners to ingest new log feeds for security monitoring • Enhance and maintain our Detection and Response platforms • Build in workflows with AI analysis to automatically investigate and triage issues • Be on the frontlines of Incident Response, actively investigating issues and protecting Upstart • Build common response workflows to expedite investigation and response using AI and SOAR Technology
Role Description Are you a seasoned VP of Security Operations who has built a world-class SOC organization for a fast-growing service provider? Fortra is seeking a visionary leader to elevate our global Security Operations function and strengthen the protection of our customers against an ever-evolving threat landscape. In this pivotal role, you will shape the future of our detection and response capabilities, drive operational excellence, and position Fortra as the industry leader in threat disruption. WHAT YOU'LL DO - Operational Leadership: - Lead our global 24x7 Managed Security Operations Centers, ensuring effective monitoring, threat detection, incident response, and remediation across networks, endpoints, email, and brand protection services. - Build and execute a strategy that strengthens detection capabilities, service performance, and customer experience. - Drive operational excellence through process improvement, automation, and optimized tooling. - Serve as an executive escalation point for critical security incidents and major customer issues. - Establish and nurture executive-level relationships with domain registrars, hosting providers, ISPs, cloud platforms, and major digital service providers to accelerate takedown response times. - Develop collaboration frameworks with threat intelligence vendors, anti-abuse networks, and takedown service providers to enhance evidence quality and streamline takedown workflows. - Partner closely with Product, Engineering, Sales, and Customer Success to evolve our services and support customer needs. - Recruit, mentor, and develop high-performing SOC leaders across a global footprint. - Ensure service readiness, resilience, and compliance with security frameworks. - Strategic Leadership: - Set and execute the long-term vision for Operations, ensuring alignment with business goals and growth objectives. - Foster a culture of engagement, inclusion, high performance, and continuous development. - Lead complex change initiatives, securing stakeholder buy-in and driving organizational adoption. - Champion a high-performance culture through clear standards, empowered accountability, and sustained focus on operational excellence and outcomes. - Drive business agility, reallocating resources as priorities evolve. - Apply strong business and financial acumen to influence decisions and drive long-term value. Qualifications - 15+ years of cybersecurity experience with 10+ years leading a large global Security Operations teams. - Proven ability to scale SOC operations and improve detection/response outcomes in a high-volume environment. - Previous success in leveraging external partnerships to establish expedited takedown channels and emergency escalation protocols for high-severity threats. - Deep connections with industry threat-mitigation groups (e.g. APWG, M3AAWG, etc.) to enable early access to emerging threat intelligence and coordinated takedown actions. - Strong communication skills with the ability to engage executives, customers, and technical teams. - Experience building high-performing global teams and operating in a 24x7 service model. Requirements - Compensation: 200,000 USD - 225,000 USD Benefits - Health, dental, and vision coverage as of hire. - Immediate enrollment in 401(k), HSA, and FSA plans. - Flexible PTO policy. - Tuition and personal enrichment reimbursement. - Option to enroll in ID Theft Protection Program.
213more opportunities are still waiting for you.Log in now and take your next shot before someone else does.
Cloud, AWS, Python, Azure, Google Cloud Platform, Linux