IT Security Analyst
Ai Security
Analytics
Cyber Security
Cybersecurity Tools
Data Loss Prevention
Data Platform
Data Processing
Data Security
Digital Marketing
Endpoint Security
Facilities Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Management
Risk Management
Security
Security Automation
Security Information And Event Management
Security Monitoring
Security Operations
Splunk Siem
Job Description
BorgWarner is seeking an IT Security Analyst to join its Security Operations team in Auburn Hills, MI. This onsite role supports global cybersecurity operations by improving how the organization detects, analyzes, and responds to threats across enterprise systems and data. You will help build and optimize security tooling, automate investigation workflows, and strengthen detection and response capabilities using modern security operations platforms.
What you’ll do
- Respond to, remediate, and coordinate incident response actions with internal and external stakeholders on a day-to-day basis
- Monitor security alerts and logs from SIEM and other security alerting tools
- Create searches and reports to prevent disruption or unavailability of information assets and to assess impact
- Analyze security attacks and decide or advise on solutions, including configuring new security tools
- Use AI-powered security operations platforms to investigate, correlate, and triage security events
- Develop, validate, and optimize AI-assisted detection and response workflows
- Evaluate AI-generated findings and ensure accuracy through analyst verification
- Partner with engineering teams to automate investigation and response processes using agentic workflows
- Develop and maintain technical runbooks and process documents
- Perform in-depth analysis of suspicious activity and attempted attacks during and after incidents, including malware, packets, alerts, and logs
- Monitor and investigate security events across cloud platforms and SaaS applications
- Investigate identity-based attacks, account compromise, MFA bypass attempts, and privilege escalation events
- Stay current with incident response technology, methodology, and legal requirements
- Develop scripts and automation to streamline security operations tasks
- Ensure investigations follow regulatory requirements and internal corporate policies, standards, and procedures
- Provide metrics and periodic intelligence reports, including lessons learned on threat actors and IOCs
- Continuously improve relevant intelligence sources and methods, recommending new tools and procedures to detect threats and protect intellectual property and assets
- Maintain and optimize security tools including endpoint protection, EDR, DLP, and Email Security
- Support formal investigations and/or inquiries related to insider threat matters and acceptable use policy violations
- Identify internal process improvement opportunities and possible solutions
- Work with the Security Operations Lead to define and document standard operating procedures for security incident handling, malware analysis, and vulnerability management
- Maintain confidentiality related to professional secrets and the security of documents handled and administered
What you bring
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
- 2+ years of experience in IT Security with a focus on Incident Response and security operations
- Strong understanding of security principles, threat landscapes, and incident response
- Experience with SIEM, EDR, DLP, VM, Email Security, and Threat Intelligence platforms
- Relevant certifications are preferred (examples: Sec+, GSEC, GCIA, CEH, CISSP)
- Fluent English in written and verbal communication
- Deep understanding of security systems, firewalls, authentication systems, log management, content filtering, and network security/networking technologies
- Experience working with and managing at least one of: SIEM, EDR, DLP, VM, Email Security
- Proven knowledge across advanced threats, information security incident detection and response, and forensic investigative practices
- Experience developing, collecting, and analyzing threat intelligence
- Experience in AI and autonomous response
- Experience with cyber intelligence analytic methodologies including Kill Chain, threat modelling, and threat hunting
- Relevant experience in an international environment
- Ability to identify problems, recognize significant threats and risks, and connect data to trace possible causes
- Ability to investigate relevant data and uphold generally accepted social and ethical standards in job-related activities
- Strong written, oral, and presentation skills
Technologies you’ll work with
- SIEM, EDR, DLP, VM, Email Security
- Threat Intelligence platforms
- AI-powered security operations platforms
- Agentic workflows
- Kill Chain, threat modelling, threat hunting
Location and salary
Onsite role based at World Headquarters in Auburn Hills, MI, USA.
Salary: USD $62,000 - $85,250 per year.