Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... This role reports to the Manager of Cyber Defense. Location: this role must work on-site, full-time ...
Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... This role reports to the Manager of Cyber Defense. Location: this role must work on-site, full-time ...
Lead SOC Analyst
Grand Rapids, MI · On-site
$90 - $120/hr
Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... This role reports to the Manager of Cyber Defense. The position requires on‑site, full‑time ...
Lead SOC Analyst
Grand Rapids, MI · On-site
$90 - $120/hr
Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... This role reports to the Manager of Cyber Defense. The position requires on‑site, full‑time ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... This role reports to the Manager of Cyber Defense. Location: this role must work on-site, full-time ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security ... This role reports to the Manager of Cyber Defense. Location: this role must work on-site, full-time ...
Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by ... Collaborating with security operations center (SOC) analysts and threat detection engineers to ...
Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by ... Collaborating with security operations center (SOC) analysts and threat detection engineers to ...
Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by ... Collaborating with security operations center (SOC) analysts and threat detection engineers to ...
Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by ... Collaborating with security operations center (SOC) analysts and threat detection engineers to ...
This role also requires the ability to develop, validate, and deploy AI-assisted SOC capabilities ... Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats ...
New
This role also requires the ability to develop, validate, and deploy AI-assisted SOC capabilities ... Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats ...
New
Proficiency developing AI-assisted or Agentic SOC capabilities using generative AI, LLMs, RAG ... Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats ...
New
Proficiency developing AI-assisted or Agentic SOC capabilities using generative AI, LLMs, RAG ... Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats ...
New
Leading the design and deployment of Next-Generation SOC platforms, including Cortex XSIAM ... data analytics, and threat intelligence. The team helps organizations manage dynamic attack ...
Leading the design and deployment of Next-Generation SOC platforms, including Cortex XSIAM ... data analytics, and threat intelligence. The team helps organizations manage dynamic attack ...
Leading the design and deployment of Next-Generation SOC platforms, including Cortex XSIAM ... data analytics, and threat intelligence. The team helps organizations manage dynamic attack ...
Leading the design and deployment of Next-Generation SOC platforms, including Cortex XSIAM ... data analytics, and threat intelligence. The team helps organizations manage dynamic attack ...
Engineer Agentic SOC capabilities, including agent skills, agent-to-tool orchestration, RAG-based ... Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats ...
New
Engineer Agentic SOC capabilities, including agent skills, agent-to-tool orchestration, RAG-based ... Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats ...
New
Cyber Manager - AI SOC
Grand Rapids, MI · On-site
$106K - $144K/yr
As a Manager - Cyber Defense and Resilience, you will play a hands-on role in delivering security ... analytics, and threat intelligence capabilities. The team works with organizations to strengthen ...
Cyber Manager - AI SOC
Grand Rapids, MI · On-site
$106K - $144K/yr
As a Manager - Cyber Defense and Resilience, you will play a hands-on role in delivering security ... analytics, and threat intelligence capabilities. The team works with organizations to strengthen ...
As a Senior Consultant - Cyber Defense and Resilience, you will help deliver security engineering ... Collaborating with security operations center analysts, threat hunters, and client stakeholders to ...
As a Senior Consultant - Cyber Defense and Resilience, you will help deliver security engineering ... Collaborating with security operations center analysts, threat hunters, and client stakeholders to ...
Advanced Threat Analysis: Execute threat modeling and attack vector analysis to quantify risk ... Security Compliance (SOC 2, PCI DSS) * Endpoint Detection & Response (CrowdStrike) * Penetration ...
Quick apply
Advanced Threat Analysis: Execute threat modeling and attack vector analysis to quantify risk ... Security Compliance (SOC 2, PCI DSS) * Endpoint Detection & Response (CrowdStrike) * Penetration ...
... Cyber Defense team responsible for leading security investigations, incident response, threat ... SOC processes that can be automated or streamlined Endpoint, Identity & Cloud Threat Detection ...
... Cyber Defense team responsible for leading security investigations, incident response, threat ... SOC processes that can be automated or streamlined Endpoint, Identity & Cloud Threat Detection ...
... Cyber Defense team responsible for leading security investigations, incident response, threat ... SOC processes that can be automated or streamlined Endpoint, Identity & Cloud Threat Detection • ...
... Cyber Defense team responsible for leading security investigations, incident response, threat ... SOC processes that can be automated or streamlined Endpoint, Identity & Cloud Threat Detection • ...
... Cyber Defense team responsible for leading security investigations, incident response, threat ... SOC processes that can be automated or streamlined Endpoint, Identity & Cloud Threat Detection • ...
... Cyber Defense team responsible for leading security investigations, incident response, threat ... SOC processes that can be automated or streamlined Endpoint, Identity & Cloud Threat Detection • ...
Direct the security operations center (SOC), overseeing threat detection, threat hunting, incident ... Leads cross-functional cyber incident response program and investigations, including tabletop and ...
New
Direct the security operations center (SOC), overseeing threat detection, threat hunting, incident ... Leads cross-functional cyber incident response program and investigations, including tabletop and ...
New
AVP, Information Security
Farmington Hills, MI · On-site
$140 - $190/hr
Leads cross-functional cyber incident response program and investigations, including tabletop and ... Strong analytical skills to identify root causes of security incidents and risks. * Exemplary ...
New
AVP, Information Security
Farmington Hills, MI · On-site
$140 - $190/hr
Leads cross-functional cyber incident response program and investigations, including tabletop and ... Strong analytical skills to identify root causes of security incidents and risks. * Exemplary ...
New
Direct the security operations center (SOC), overseeing threat detection, threat hunting, incident ... Leads cross-functional cyber incident response program and investigations, including tabletop and ...
New
Direct the security operations center (SOC), overseeing threat detection, threat hunting, incident ... Leads cross-functional cyber incident response program and investigations, including tabletop and ...
New
... SOC reports), for both new and renewing vendors. * Maintaining the vendor risk register and ... Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and ...
... SOC reports), for both new and renewing vendors. * Maintaining the vendor risk register and ... Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and ...
Cyber Soc Analyst information
See Michigan salary details
$38.8K - $47.2K
9% of jobs
$47.2K - $55.7K
2% of jobs
$55.7K - $64.1K
6% of jobs
$64.1K - $72.5K
1% of jobs
$76K is the 25th percentile. Wages below this are outliers.
$72.5K - $81K
17% of jobs
$81K - $89.4K
11% of jobs
The median wage is $92.8K / yr.
$89.4K - $97.9K
11% of jobs
$97.9K - $106.3K
17% of jobs
$107.7K is the 75th percentile. Wages above this are outliers.
$106.3K - $114.7K
10% of jobs
$114.7K - $123.2K
13% of jobs
$123.2K - $131.6K
4% of jobs
$38.8K
$93.7K
$131.6K
How much do cyber soc analyst jobs pay per year?
What is a Cyber SOC analyst?
What are the key skills and qualifications needed to thrive as a Cyber SOC analyst?
What are some common challenges faced by Cyber SOC analysts, and how can they effectively manage them?
What is the difference between Cyber Soc Analyst vs Security Analyst?
| Aspect | Cyber Soc Analyst | Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CEH, CISSP (preferred) | CompTIA Security+, CISSP, CISA |
| Work Environment | Security Operations Center (SOC), monitoring security alerts | IT departments, security teams, risk management |
| Employer & Industry Usage | Financial, healthcare, government, tech sectors | Broadly across industries, including corporate and government |
| Primary Focus | Real-time threat detection and incident response | Vulnerability assessment, risk management, policy development |
While both roles focus on cybersecurity, a Cyber Soc Analyst primarily monitors security alerts in a SOC environment, responding to threats in real-time. A Security Analyst often has a broader scope, including vulnerability assessments and security policy development. The roles overlap in certifications and industry usage, but their day-to-day responsibilities differ based on focus and work setting.
Is a Cyber Soc Analyst still in demand?
What are popular job titles related to Cyber Soc Analyst jobs in Michigan?
For Cyber Soc Analyst jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Cyber Soc Analyst jobs in Michigan look for?
The top searched job categories for Cyber Soc Analyst jobs in Michigan are:
What cities in Michigan are hiring for Cyber Soc Analyst jobs?
Cities in Michigan with the most Cyber Soc Analyst job openings:

Lead SOC Analyst
Grand Rapids, MI
7.3
Based on 91 frontline employees who took The Breakroom Quiz
325th of 545 rated manufacturers
People enjoy working here
Good employer
Paid breaks
Recommended by parents
Respectful managers
Full-time
Re-posted 29 days ago
Job description
Job Summary
The Lead SOC Analyst is responsible for leading the daily operations of the Security Operations Center (SOC) while actively participating in threat detection, investigation, and response activities. This role operates in a player/coach capacity, balancing hands-on incident response with team leadership, process development, and SOC maturity initiatives.
The Lead SOC Analyst serves as the primary point of coordination between the internal SOC and external managed detection and response (MDR) provider, ensuring effective monitoring, escalation, and response to security events. This role is also responsible for developing and maintaining SOC processes, playbooks, and documentation to improve the organization's overall security posture.
This role reports to the Manager of Cyber Defense.
Location: this role must work on-site, full-time out of our Grand Rapids, MI office
Principal Duties and Responsibilities
SOC Operations and Incident Response
- Act as the senior escalation point for security incidents, providing hands-on investigation and response.
- Perform advanced threat hunting, incident analysis, and root cause determination.
- Lead and coordinate incident response activities across IT, infrastructure, and application teams.
- Validate and enrich alerts generated by internal tools and external MDR provider.
- Ensure timely containment, remediation, and closure of security incidents.
MDR Vendor Management
- Serve as the primary operational liaison with our MDR provider.
- Manage day-to-day interactions including alert triage alignment, escalation handling, and service quality.
- Review MDR detections, investigations, and recommendations for accuracy and relevance.
- Identify and drive improvements in detection coverage, alert fidelity, and response processes.
- Participate in regular service reviews and ensure deliverables meet organizational expectations.
SOC Leadership and Team Development
- Provide technical leadership and guidance to SOC analysts.
- Lead daily SOC operations including prioritization of alerts, workload management, and escalation decisions.
- Mentor and develop analysts through coaching, training, and knowledge sharing.
- Establish expectations for investigation quality, documentation, and response timelines.
- Support hiring, onboarding, and skill development of SOC team members.
SOC Maturity and Process Development
- Develop, document, and maintain SOC standard operating procedures (SOPs), playbooks, and runbooks.
- Identify gaps in SOC processes and implement improvements to increase consistency and effectiveness.
- Define and track SOC metrics and KPIs (e.g., MTTR, alert volume, false positives, escalation rates).
- Standardize incident documentation and evidence collection to support audit and compliance requirements.
- Drive continuous improvement initiatives aligned to industry best practices and organizational goals.
Detection Engineering and Monitoring
- Collaborate with engineering and security teams to improve detection logic and use cases.
- Develop and tune detection rules within SIEM, XDR, and MDR platforms.
- Identify gaps in logging and telemetry and work with teams to onboard required data sources.
- Ensure monitoring coverage for systems handling sensitive or critical data.
- Contribute to threat modeling and detection strategy development.
Communication and Stakeholder Engagement
- Communicate security incidents, risks, and trends to technical and non-technical stakeholders.
- Provide clear and concise reporting on incident outcomes and lessons learned.
- Partner with infrastructure, application, and business teams to improve security practices.
- Support audit, compliance, and risk management activities as needed.
Qualifications
- Bachelor's degree in computer science, information security, or equivalent experience.
- 7+ years of experience in a SOC, incident response, or cybersecurity operations role.
- Proven experience leading incident investigations and managing escalations.
- Experience working with a managed detection and response (MDR) provider (preferred).
- Strong understanding of security operations tools (SIEM, XDR, EDR, SOAR platforms).
- Experience with detection tuning, threat hunting, and log analysis.
- Demonstrated ability to develop SOC processes, playbooks, and operational documentation.
- Strong leadership, mentoring, and team development skills.
- Excellent analytical, problem-solving, and decision-making capabilities.
- Strong written and verbal communication skills.
Preferred Qualifications
- Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms.
- Experience working in a hybrid SOC model (internal + MDR).
- Familiarity with compliance frameworks (e.g., NIST, CMMC).
- Relevant certifications such as CISSP, GCIA, GCIH, or equivalent.
The Company is an Equal Opportunity Employer.
About UFP Industries
Sourced by ZipRecruiter
Universal Forest Products, Inc., is a U.S.-based global corporation that finds reward in its roots and its hard-earned success. Founded in 1955 as a supplier of lumber to the manufactured housing industry, Universal today is a multibillion-dollar holding company with subsidiaries around the globe that serve three robust markets: retail, industrial and construction. Since 1993, Universal has been publicly traded (Nasdaq: UFPI). We re headquartered in Grand Rapids, Michigan.
Industry
Wood product manufacturing
Company size
10,000+ Employees
Headquarters location
Grand Rapids, MI, US
Year founded
1955
Website
What UFP Industries employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom