Incident Response Analyst
Date: Feb 5, 2025
Location: JACKSON, MI, US
Company: Consumers Energy
Consumers Energy is Michigan’s largest energy provider, providing natural gas and/or electricity to 6.8 million of the state’s 10 million residents in all 68 Lower Peninsula counties. Consumers Energy knows job number one is to keep the lights on for customers. We are committed to delivering reliable, clean, and affordable energy to our customers 24/7.
Location: The successful candidate will be expected to work in a hybrid status of reporting to any Consumers Energy Service Center every Monday, Tuesday, and Thursday with home office flexibility on Wednesday and Friday.
General Summary of Job Responsibilities
Essential Duties and Responsibilities
- Performs identification, analysis, containment, eradication, and recovery of security incidents triggered by security platforms and escalated by associate incident response analysts and the Security Monitoring team.
- Researches and analyzes large amounts of structured and unstructured data from internal Cyber Threat Intelligence (CTI), open source intelligence (OSINT), and internal security tooling to develop detection rules and support incident response activities.
- Supports audit and regulatory compliance efforts by gathering evidence of security control implementation, documenting existing security controls, and preparing reports to fulfill audit requests.
- Executes structured, documented threat hunting activities to identify risky or malicious behavior occurring within the network. Triaging and classifying any results for additional analysis
- Routinely develop and update incident response documentation, playbooks, and process to ensure Incident Response team activities align with best practices, minimize gaps in response, and provide comprehensive mitigation of threats
- Develops and maintains automation for routine tasks via SOAR platforms and scripting (e.g., PowerShell, Python)
- Create, update, and monitor key performance indicators and metrics leveraging PowerBI and Excel.
- Other duties as assigned or may be necessary
Knowledge/Skills/Abilities
- Knowledge of the tools, methodologies, and techniques for identifying, prioritizing, and classifying cyber incidents, especially NIST 80053 or SANS incident handling frameworks.
- Understanding of network security architecture concepts, including topology, protocols, components, and principles.
- Knowledge of system and application security threats and vulnerabilities.
- Skilled with standard security tools (SIEM, EDR, IDS)
- Able to participate in after-hours incident response, including weekly 24x7 on-call rotation.
- Able to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) for risk assessment, investigation, and response.
- Able to work both independently and within a team under minimal supervision.
- Able to work in a team-based environment
- Working knowledge of one or more scripting/programming languages (PowerShell, Python, C#)
Education & Experience
- Bachelor's Degree in Security, Computer Science, or related field with 2 years in One or more of the following: Incident response, digital forensics, threat hunting, detection engineering, security engineering OR
- Associate's Degree in Security, Computer Science, or related field with 4 years in Two or more of the following: Incident response, digital forensics, threat hunting, detection engineering, security engineering OR
- High School Diploma or GED with 6 years in following: Incident response, digital forensics, threat hunting, detection engineering, security engineering.
Why should you join our team?
At Consumers Energy, we offer more than just a place to work. We foster a culture that supports career development, growth, and stability, and we take pride in offering our co-workers excellent benefits and compensation packages. We are deliberately creating an inclusive culture that makes our diverse team of co-workers feel valued, supported, and empowered every day. We're a company made up of thousands of people, all with different stories to share and work to do, but we stand united in our company purpose: world class performance delivering hometown service.
What we offer:
- Competitive compensation packages
- Medical, Dental and Vision
- 401k with company match
- Paid parental leave
- Up to 13 paid Holidays
- Paid time off
- Educational Assistance Program
Diversity, Equity & Inclusion:
We, at CMS Energy, value Diversity, Equity, & Inclusion. It is part of our DNA. We treat our employees with respect, we treat each other fairly and we value the opinions of others. We are passionate about building and nurturing an environment where everyone feels included. We don’t discriminate. We seek to learn about each other and better understand our unique differences. Our uniqueness makes us authentic. We create safe spaces where everyone can be who they truly are. We invite difficult conversations and uncomfortable topics. We value diverse perspectives; this is what makes us great together. We harbor an inclusive environment where employees feel empowered to share their backgrounds, experiences, and ideas. Our Employee Resource Groups, Women in Energy (WE), Minority Advisory Panel (MAP), Pride Alliance of Consumers Energy (PACE), GENERGY, capABLE, Interfaith and Veterans Advisory Panel (VAP) are key enablers to living the values of our company culture: Caring, Empowered, Deliberate, Agility, and Ownership.
All qualified applicants will not be discriminated against and will receive consideration for employment without regard to protected veteran status, disability, race, color, religion, sex, age, sexual orientation, gender identity or national origin.
Job Segment:
Computer Science, Open Source, Compliance, Law, Engineer, Technology, Legal, Engineering