Security Analyst
Cloud Platforms
Cyber Threat Analysis
Cybersecurity Tools
Edr And Xdr
Endpoint Security
Identity and Access Management
Incident Response
Information Security
InfoSec
Investigative Skills
Log Management
Microsoft Defender
Microsoft Sentinel
Osint
Security Automation
Security Detection
Security Detections
Security Information And Event Management
Security Investigation
Security Monitoring
Security Operations
Security Threat Detection
Splunk
Threat Intelligence
Job Description
Join Johnson Controls in Milwaukee, WI (onsite) as a Security Analyst focused on investigation, incident response, and improving detection and response capabilities.
Responsibilities
- Investigate and respond to security alerts and incidents, performing root cause analysis and driving corrective actions
- Lead and support incident response efforts, coordinating across teams to contain and remediate threats
- Continuously improve detection and response through automation, runbook development, and SOP creation
- Identify and strengthen threat detection and prevention capabilities
- Integrate threat intelligence into operational workflows to help address emerging threats proactively
- Collaborate with Security, IT, and Business teams to enhance readiness and resilience through joint response planning
Requirements
- Extensive experience in Security Operations and Incident Response, with a strong track record handling complex incidents
- Proficiency with modern cybersecurity tools including EDR, SIEM, firewalls, WAF, identity, and cloud security platforms
- Experience operationalizing threat intelligence and building detection strategies for evolving threats
- Strong analytical and problem-solving skills with process rigor and continuous improvement focus
- Ability to drive action and influence outcomes in fast-paced, cross-functional environments
- Excellent communication and collaboration skills, with a team-first mindset and mentoring capabilities
- 1–5 years in a SOC, incident response, IT security operations, or adjacent role (for example: EDR admin, blue team intern/co-op)
- Experience with at least one of: SIEM, EDR/XDR, secure email gateway, or cloud security tools such as M365 Defender suite, Defender for Endpoint, Sentinel, Splunk, CrowdStrike, Palo Alto, Zscaler
- Familiarity with core investigation concepts: event correlation, user/host baselining, MITRE ATT&CK, common malware/TTPs, phishing indicators
- Strong communication skills to explain technical issues to non-technical users and document clearly and concisely
- Understanding of basic networking (TCP/IP, DNS, HTTP, VPN) and Windows/Linux fundamentals (processes, services, logs, registry, authentication)
- Ability to work in a ticket-driven environment with SLAs and handoffs to an MSSP
- Inquisitive personality that supports asking questions and conducting research
- Minimum experience: 1 years
Technologies
- EDR, SIEM, firewalls, WAF, identity, cloud security platforms, EDR/XDR
- Secure email gateway; M365 Defender suite; Defender for Endpoint; Sentinel; Splunk; CrowdStrike; Palo Alto; Zscaler
- MITRE ATT&CK; TCP/IP; DNS; HTTP; VPN; Windows; Linux; PowerShell; Python
- KQL; SOAR; VirusTotal; Shodan; Censys; CyberChef
- ICS/SCADA; Purdue model; OSINT; OSINT Tools
- AAD; MFA; conditional access
Benefits
- Competitive salary
- Paid vacation/holidays/sick time
- Comprehensive benefits package including 401K, medical, dental, and vision care
- On the job/cross training opportunities
- Encouraging and collaborative team environment
- Dedication to safety through the Zero Harm policy
Preferred
- Exposure to manufacturing/OT environments, including ICS/SCADA basics, Purdue model, segmentation concepts, and remote access risks
- Experience enriching investigations with OSINT Tools (VirusTotal, Shodan, Censys, CyberChef, etc.)
- Experience with SOAR workflows and playbooks; basic scripting (PowerShell, Python, KQL) for triage automation
- Knowledge of identity security (AAD, MFA, conditional access), email security, and cloud log sources
- Certifications: Security+, CySA+, Microsoft SC-200, GSEC, or equivalent