Cybersecurity AnalystApplication due date: June 21, 2026
Location: Maple Grove, MN
(This position is eligible for a hybrid work arrangement based on business needs. The role participates in an on-call rotation and requires the ability to respond to critical incidents, including reporting onsite within one hour when necessary.)
We are the people we power. As Minnesota's not-for-profit electric cooperative, our member-owners and their members impact every decision we make. Because their needs are our needs, and their dreams are our dreams.
Summary:We are expanding our team! GRE is seeking an experienced Cybersecurity Analyst to help strengthen and mature our cybersecurity operations program through proactive monitoring, advancing threat detection and response capabilities, and continuous improvement initiatives.
In this role, you will be responsible for monitoring, investigating, and responding to cybersecurity threats and incidents leveraging our SIEM, Splunk. This role includes continuously enhancing threat detection capabilities, collaborating across the organization to strengthen overall security posture, and supporting cybersecurity strategic initiatives. This position plays a critical role in ensuring the confidentiality, integrity, and availability of enterprise infrastructure and operating environments.
Total Rewards:A typical starting range for this position is $105,000 - $144,000 annually. We offer competitive market base pay and adjust our offer accordingly based upon the value of the candidate's knowledge, skills, and experience. In addition, our Total Rewards strategy focuses on recognizing individual performance and rewarding business results. Our robust Total Rewards package includes exceptional benefits and retirement, recognition, personal and professional development, and an emphasis on work-life effectiveness.
Responsibilities:- Monitor, investigate, and respond to cybersecurity alerts and suspicious events across the organization.
- Perform log analysis, event correlation, and threat detection activities using SIEM technologies, with a strong focus on Splunk.
- Build, tune, and optimize Splunk alerts, dashboards, searches, and detection content to improve monitoring effectiveness and reduce false positives.
- Develop detection logic patterns aligned to the MITRE ATT&CK framework.
- Research emerging threats and tactics, techniques, and procedures (TTPs).
- Participate in incident response activities including investigation, containment, eradication, recovery, and post-incident activity.
- Write and maintain operational playbooks, response procedures, and standard operating documentation.
- Identify opportunities to improve security monitoring, alerting, automation, and response workflows.
- Partner with IT and business teams to address gaps and strengthen security posture.
- Assist with security metrics, reporting, and communication of cybersecurity risks and trends to leadership and stakeholders.
- Leverage scripting and automation tools, including Python, to improve operational efficiency and security response capabilities.
- Ability to quickly analyze large amounts of data to identify gaps, patterns, and opportunities for proactive defense improvements.
- Support integration and automation efforts across cybersecurity tooling and workflows.
Qualifications: - Bachelor's degree in cybersecurity, information technology, computer science, or related field and 3+ years of cybersecurity experience
OR - Associate degree or equivalent post-secondary education in a technology-related field and 5+ years of cybersecurity experience.
Required Experience:- Hands-on expert experience using Splunk with intermediate level query language.
- Experience working within a security operations, incident response, or cyber monitoring environment.
- Demonstrated experience applying MITRE ATT&CK framework in threat detection and incident analysis.
- Proficient in writing operational playbooks, procedures, and response documentation.
- Experience with a scripting language such as Python and PowerShell.
- Proven experience with behavioral analytics, anomaly detection, and detection engineering, with strong proficiency in host, network, web, and forensic analysis.
- Background in investigating and responding to cloud-based security threats.
- Familiarity with the NIST 800 Special Publication Frameworks and regulatory/compliance environments such as NERC CIP.
Knowledge, Skills & Abilities:- Strong analytical and problem-solving skills with the ability to investigate complex security events.
- Ability to correlate data across systems, networks, endpoints, and applications to identify potential threats.
- Strong written and verbal communication skills with ability to explain technical concepts to non-technical audiences.
- Ability to effectively manage time and multiple priorities in a fast-paced operational environment.
- Collaborative approach with the ability to work effectively across teams and business units.
- Certifications such as GIAC, GCIA, GCIH, GCFA, CISSP, Security+ are a plus.
Apply: Qualified candidates please apply at www.greatriverenergy.com (under the Careers tab) by June 21, 2026. GRE values diversity, equity and inclusion and we are an equal employment opportunity employer.