1

Security Operations Center Analyst Jobs in Michigan

Control Center Operator Shift Opening(s): * Full-Time Monday - Sunday Various Days/ 1st, 2nd, and ... DTMB Central Control is a 24/7/365 operation that provides security and life safety systems ...

Scope of the Role Security Operations & Incident Response • Lead investigation, containment ... analysts during complex investigations Detection, SIEM & Automation • Develop, tune, and improve ...

New

In this client-facing role, you will work with security engineers, security operations center teams ... Building automation playbooks, integrations, and workflow enhancements that improve analyst ...

In this client-facing role, you will work with security engineers, security operations center teams ... Building automation playbooks, integrations, and workflow enhancements that improve analyst ...

Senior SOC Analyst - Weekends

Flint, MI · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

About the Role Our Security Operations Center (SOC) is expanding, and we're seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday - Wednesday from 8:00 AM to 5 ...

Senior SOC Analyst - Weekends

Lansing, MI · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

About the Role Our Security Operations Center (SOC) is expanding, and we're seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday - Wednesday from 8:00 AM to 5 ...

Senior SOC Analyst - Weekends

Detroit, MI · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

About the Role Our Security Operations Center (SOC) is expanding, and we're seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday - Wednesday from 8:00 AM to 5 ...

Showing results 41-60

Security Operations Center Analyst information

See Michigan salary details

$15

$32

$61

How much do security operations center analyst jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for security operations center analyst in Michigan is $32.13, according to ZipRecruiter salary data. Most workers in this role earn between $19.71 and $38.12 per hour, depending on experience, location, and employer.

What skills make an effective security operations center analyst?

To thrive as a Security Operations Center Analyst, you need a strong understanding of cybersecurity principles, network protocols, and incident response, often backed by a relevant degree or certifications like CompTIA Security+ or CISSP. Familiarity with SIEM tools (e.g., Splunk, QRadar), intrusion detection systems, and ticketing platforms is essential for effective monitoring and analysis. Attention to detail, analytical thinking, and clear communication help SOC Analysts excel in identifying threats and collaborating with IT teams. These skills are crucial to quickly detecting, investigating, and mitigating security incidents, protecting organizational assets from cyber threats.

What are the most common challenges security operations center analysts face during daily operations?

Security Operations Center (SOC) Analysts often deal with a high volume of alerts, many of which may be false positives, requiring keen analytical skills to prioritize genuine threats. Staying updated on evolving cyber threats and attack patterns is another challenge, as adversaries continuously adapt their tactics. Additionally, SOC Analysts frequently work in high-pressure environments where quick, accurate decision-making is crucial, and collaboration with IT, incident response teams, and management is essential to ensure coordinated defense efforts.

What is a security operations center analyst?

Security Operations Center (SOC) Analysts are cybersecurity professionals who monitor, detect, and respond to security threats within an organization’s IT environment. They analyze security alerts, investigate incidents, and coordinate responses to mitigate risks and protect sensitive data. SOC Analysts use specialized tools to track suspicious activities, implement security measures, and ensure compliance with security policies. Their work is crucial in defending organizations against cyberattacks and maintaining overall information security.

What is the difference between Security Operations Center Analyst vs Security Analyst?

AspectSecurity Operations Center AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA (preferred)
Work EnvironmentMonitoring security alerts in a SOC, 24/7 shiftsAnalyzing security data, conducting risk assessments
Employer & Industry UsagePrimarily in security operations centers, cybersecurity firmsVarious industries including finance, healthcare, government

The Security Operations Center Analyst focuses on real-time monitoring and incident response within a SOC environment, often working in shifts. In contrast, a Security Analyst typically conducts broader security assessments, policy development, and risk analysis across organizations. Both roles require similar certifications and are integral to cybersecurity teams, but their daily tasks and work settings differ.

What does a security operations center analyst do?

A security operations center analyst works on the cybersecurity team at an organization to proactively defend the organization's database, website, servers, and network. In this role you control the security alerts and ensure that each alert is taken care of before the threat of hackers gaining access to your company's information is realized. You may run an investigation if you see similar threats repeatedly to see who is attempting to attack your systems and why. Your other duties may include keeping and analyzing a security log, coordinating with other analysts or security team members, and assessing company vulnerability.

What are the most commonly searched types of Security Operations Center Analyst jobs in Michigan?

The most popular types of Security Operations Center Analyst jobs in Michigan are:

What are popular job titles related to Security Operations Center Analyst jobs in Michigan?

For Security Operations Center Analyst jobs in Michigan, the most frequently searched job titles are:

What job categories do people searching Security Operations Center Analyst jobs in Michigan look for?

The top searched job categories for Security Operations Center Analyst jobs in Michigan are:

What cities in Michigan are hiring for Security Operations Center Analyst jobs?

Cities in Michigan with the most Security Operations Center Analyst job openings:

Infographic showing various Security Operations Center Analyst job openings in Michigan as of August 2026, with employment types broken down into 82% Full Time, 15% Part Time, 1% Temporary, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $66,830 per year, or $32.1 per hour.

Cyber - Google SecOps - Manager

Deloitte

Grand Rapids, MI

Full-time

Posted 16 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

44th of 150 rated financial services


Job description

Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:

  • Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
  • Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
  • Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
  • Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
  • Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
  • 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
  • Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
  • Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
  • Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
  • Experience facilitating scope or build requirement discussions with internal or external stakeholders
  • Experience with threat hunting or cyber threat intelligence fundamentals
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:

  • Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
  • Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
  • Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
  • Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
  • Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
  • 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
  • Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
  • Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
  • Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
  • Experience facilitating scope or build requirement discussions with internal or external stakeholders
  • Experience with threat hunting or cyber threat intelligence fundamentals
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom