Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber incident response analyst 4

$70 - $85 per hour

Randstad

job summary:
Security Alert Management/Threat Hunting

Monitor and analyze network, host, cloud posture, identity, attack surface, intelligence, and email based security events and logs to identify potential security threats.

Prioritize and differentiate between potential intrusion attempts, false alarms, and risks.

Properly respond to alerts that require incident response review.

Develop and tune threat detection policies, rules, and intelligence.

Incident Response

Lead the management of complex information security incidents from triage through resolution.

Ability to manage multiple investigations concurrently.

Lead a cross-functional team of experts to resolve the incident investigation.

Provide timely and relevant updates to appropriate stakeholders and decision makers.

Conduct root cause analysis and partner with functional experts to determine the remediation path for incident resolution. Root cause analysis may include, but is not limited to malware analysis, computer forensic analysis, log analysis, personnel interviews, and technical troubleshooting. The CIRT Analyst IV will evaluate controls at each level of security defense, from end-point to perimeter.

Provide findings to relevant business leadership to help improve information security posture.

Validate and maintain incident response plan and playbooks to address the evolving threat landscape.

Create and maintain strong relationships with key partners in the incident response ecosystem and ensure efficient alignment during the investigation process.

Compile and analyze data for management reporting and metrics.

Provide rotational on-call support for assessing potentially critical alerts escalated by off-hours monitoring team.

Threat Management

Manage and analyze threat intelligence data received from cyber threat vendors.

Monitor information security related websites (e.g., US-CERT, SANS Internet Storm Center) and mailing lists (e.g., SANS NewsBites, etc.) to stay current on the latest malicious code trends, exploits, and malware.

Participate in working groups that assess Iron Mountain's risk posture.

Analyze the potential impact of new threats and communicate risks to relevant business units.

Develop advanced threat detection rules based on analysis of intelligence.

Qualifications

Ten or more years of technical experience in the information security field, preferably in a Security Operations Center (SOC), Network Operations Center (NOC), or Computer Emergency/Incident Response Team (CERT/CIRT)

Eight or more years of practical Cyber Incident Management and Threat Hunting experience.

Advanced knowledge of information systems security concepts and technologies, including SIEM technologies, network architecture, database concepts, intrusion detection, cloud security, endpoint detection and response ( EDR), email protection, malware remediation; and computer forensic tools such as EnCase and open source alternatives.

Familiarity with security frameworks, such as NIST, and compliance standards such as HIPAA, GDPR, PCI, and FedRAMP.

Strong understanding of incident, problem, and change management is preferred.

Advanced knowledge and experience with the Windows and Linux operating systems.

Working knowledge and experience with investigating malicious code.

Demonstrated ability to apply technical and analytical skills in a security environment

Ability to work extremely well under pressure while maintaining a professional image and approach

Exceptional data analytics abilities; can perform independent analysis and distill relevant findings and root cause

Strong analytical writing skills; can articulate complex ideas clearly and effectively; experience creating and presenting documentation and management reports

Team player with proven ability to work effectively with other business units, IT management and staff, Legal, vendors, and consultants

Strong communication skills; can plan and lead effective meetings, conduct structured interviews to collect information, and present to a variety of audiences, including key stakeholders and decision makers

Experience in the following or similar tools: Chronicle Backstory,, Crowdstrike Falcon, Prisma Cloud, Check Point Next Generation Appliances, Tenable, Tanium, Google Cloud Platform, AWS, Azure.

Working understanding of threat intelligence, SOAR, and attack surface platforms.

location: Telecommute
job type: Contract
salary: $70 - 85 per hour
work hours: 8am to 5pm
education: Bachelors


responsibilities:
Security Alert Management/Threat Hunting

Monitor and analyze network, host, cloud posture, identity, attack surface, intelligence, and email based security events and logs to identify potential security threats.

Prioritize and differentiate between potential intrusion attempts, false alarms, and risks.

Properly respond to alerts that require incident response review.

Develop and tune threat detection policies, rules, and intelligence.

Incident Response

Lead the management of complex information security incidents from triage through resolution.

Ability to manage multiple investigations concurrently.

Lead a cross-functional team of experts to resolve the incident investigation.

Provide timely and relevant updates to appropriate stakeholders and decision makers.

Conduct root cause analysis and partner with functional experts to determine the remediation path for incident resolution. Root cause analysis may include, but is not limited to malware analysis, computer forensic analysis, log analysis, personnel interviews, and technical troubleshooting. The CIRT Analyst IV will evaluate controls at each level of security defense, from end-point to perimeter.

Provide findings to relevant business leadership to help improve information security posture.

Validate and maintain incident response plan and playbooks to address the evolving threat landscape.

Create and maintain strong relationships with key partners in the incident response ecosystem and ensure efficient alignment during the investigation process.

Compile and analyze data for management reporting and metrics.

Provide rotational on-call support for assessing potentially critical alerts escalated by off-hours monitoring team.

Threat Management

Manage and analyze threat intelligence data received from cyber threat vendors.

Monitor information security related websites (e.g., US-CERT, SANS Internet Storm Center) and mailing lists (e.g., SANS NewsBites, etc.) to stay current on the latest malicious code trends, exploits, and malware.

Participate in working groups that assess Iron Mountain's risk posture.

Analyze the potential impact of new threats and communicate risks to relevant business units.

Develop advanced threat detection rules based on analysis of intelligence.

Qualifications

Ten or more years of technical experience in the information security field, preferably in a Security Operations Center (SOC), Network Operations Center (NOC), or Computer Emergency/Incident Response Team (CERT/CIRT)

Eight or more years of practical Cyber Incident Management and Threat Hunting experience.

Advanced knowledge of information systems security concepts and technologies, including SIEM technologies, network architecture, database concepts, intrusion detection, cloud security, endpoint detection and response ( EDR), email protection, malware remediation; and computer forensic tools such as EnCase and open source alternatives.

Familiarity with security frameworks, such as NIST, and compliance standards such as HIPAA, GDPR, PCI, and FedRAMP.

Strong understanding of incident, problem, and change management is preferred.

Advanced knowledge and experience with the Windows and Linux operating systems.

Working knowledge and experience with investigating malicious code.

Demonstrated ability to apply technical and analytical skills in a security environment

Ability to work extremely well under pressure while maintaining a professional image and approach

Exceptional data analytics abilities; can perform independent analysis and distill relevant findings and root cause

Strong analytical writing skills; can articulate complex ideas clearly and effectively; experience creating and presenting documentation and management reports

Team player with proven ability to work effectively with other business units, IT management and staff, Legal, vendors, and consultants

Strong communication skills; can plan and lead effective meetings, conduct structured interviews to collect information, and present to a variety of audiences, including key stakeholders and decision makers

Experience in the following or similar tools: Chronicle Backstory,, Crowdstrike Falcon, Prisma Cloud, Check Point Next Generation Appliances, Tenable, Tanium, Google Cloud Platform, AWS, Azure.

Working understanding of threat intelligence, SOAR, and attack surface platforms.

Education/Certifications

Bachelor's degree in information systems, computer science, or related discipline desired.

Postgraduate degrees and certificate programs in relevant areas that demonstrate analytical and technical background will also be considered.

SANS certifications (GSEC, GCIH, GCFA, GCFR, or GCIA).

qualifications:
Qualifications

Ten or more years of technical experience in the information security field, preferably in a Security Operations Center (SOC), Network Operations Center (NOC), or Computer Emergency/Incident Response Team (CERT/CIRT)

Eight or more years of practical Cyber Incident Management and Threat Hunting experience.

Advanced knowledge of information systems security concepts and technologies, including SIEM technologies, network architecture, database concepts, intrusion detection, cloud security, endpoint detection and response ( EDR), email protection, malware remediation; and computer forensic tools such as EnCase and open source alternatives.

Familiarity with security frameworks, such as NIST, and compliance standards such as HIPAA, GDPR, PCI, and FedRAMP.

Strong understanding of incident, problem, and change management is preferred.

Advanced knowledge and experience with the Windows and Linux operating systems.

Working knowledge and experience with investigating malicious code.

Demonstrated ability to apply technical and analytical skills in a security environment

Ability to work extremely well under pressure while maintaining a professional image and approach

Exceptional data analytics abilities; can perform independent analysis and distill relevant findings and root cause

Strong analytical writing skills; can articulate complex ideas clearly and effectively; experience creating and presenting documentation and management reports

Team player with proven ability to work effectively with other business units, IT management and staff, Legal, vendors, and consultants

Strong communication skills; can plan and lead effective meetings, conduct structured interviews to collect information, and present to a variety of audiences, including key stakeholders and decision makers

Experience in the following or similar tools: Chronicle Backstory,, Crowdstrike Falcon, Prisma Cloud, Check Point Next Generation Appliances, Tenable, Tanium, Google Cloud Platform, AWS, Azure.

Working understanding of threat intelligence, SOAR, and attack surface platforms.

Education/Certifications

Bachelor's degree in information systems, computer science, or related discipline desired.

Postgraduate degrees and certificate programs in relevant areas that demonstrate analytical and technical background will also be considered.

SANS certifications (GSEC, GCIH, GCFA, GCFR, or GCIA).

Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.

At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact View email address on click.appcast.io.


Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).


This posting is open for thirty (30) days.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cyber incident response analyst 4 in United States vacancy
  • $45.7 per hour

     ...Role: Bilingual GIR (Global Incident Response) Analyst - Japanese Bilingual Client : MUFG...  ...Work location : Tempe, AZ (Hybrid. 4 days onsite per week) Pay Rate...  ...Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related... 
    Cyber
    Contract work

    Pasona NA

    Tempe, AZ
    1 day ago
  •  ...Cyber Incident Responder Detect-Response performs all procedures necessary to ensure the safety of information systems assets and to protect systems from...  ...-based security. Shift work may be required . Level 4 : Investigates, analyzes, and responds to cyber incidents... 
    Cyber
    Shift work

    IC-CAP, LLC

    Washington DC
    5 days ago
  •  ...Alignerr is seeking an Incident Response Analyst to work on cutting-edge cybersecurity AI. In this fully remote role, you will analyze realistic...  ...security incidents, contribute to AI's capability to detect cyber threats, and provide feedback that shapes AI's reasoning in... 
    Cyber
    Contract work
    Remote work

    Alignerr

    New York, NY
    1 day ago
  • $60 per hour

     ...Description Tyto Athene is searching for a Part-Time Tier 2 Incident Response Analyst (IR) to support a law enforcement customer in Washington,...  ...our tools, triaging alerts, and investigating potential cyber threats. As a SOC team member, you will also serve as the initial... 
    Cyber
    Part time
    Remote work
    Worldwide
    Shift work
    Night shift
    Weekend work
    Day shift

    Tyto Athene, LLC

    Washington DC
    2 days ago
  • $135k - $150k

     ...RMC is hiring a Tier 3 Incident Response Senior Analyst to support an active government contract in Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government's mission... 
    Cyber
    Full time
    Contract work
    Work experience placement
    Relocation package
    Monday to Friday
    Shift work
    Day shift

    Resource Management Concepts

    Quantico, VA
    3 days ago
  • $162k - $203k

     ...As a Principle Incident Response Analyst at Honeywell Aerospace, you will be instrumental in conducting detailed analysis and providing insights...  ...You will report directly to our Sr. Director of Cyber Security, and work out of our Phoenix, AZ location or REMOTE... 
    Cyber
    Permanent employment
    Temporary work
    Work experience placement
    Remote work
    Flexible hours

    Honeywell Aerospace

    Phoenix, AZ
    2 days ago
  • $30 - $60 per hour

     ...Incident Response Analyst $30-60/hr Remote Freelance STEM About the Role We're partnering with leading AI research labs to build and refine...  ...will directly shape how AI handles the next generation of cyber threats. What You'll Do Analyze realistic security... 
    Cyber
    Ongoing contract
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    9 hours ago
  • $120.8k - $151k

     ...Advanced Cyber Incident Response Leader This role provides leadership and expertise in advanced cyber incident response, forensic investigations, and security operations automation. The position is responsible for investigating and coordinating responses to cybersecurity... 
    Cyber

    Sony Pictures Entertainment

    Culver City, CA
    5 days ago
  •  ...technology. The opportunity: Senior Incident Responder Provide primary objectives and responsibilities for the role. Focus on the role...  ...orchestration following the cyber technical incident response...  ...GIAC Certified Forensic Analyst - GCFA GIAC Certified Forensic... 
    Cyber

    Smurfit Westrock

    Atlanta, GA
    4 days ago
  •  ...Sentar is seeking a Tier 3 Incident Response Senior Analyst in Quantico, VA! Role Description: Sentar is hiring a Tier 3 Incident Response...  ...Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. Additionally,... 
    Cyber
    Contract work
    Temporary work
    For contractors
    Work experience placement
    Remote work
    Flexible hours
    Weekend work

    Sentar

    Quantico, VA
    2 days ago
  • $131.3k - $237.35k

     ...and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland...  ...to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The... 
    Cyber
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Arlington, VA
    4 days ago
  •  ...Sr Analyst, Governance Risk and Compliance TransUnion is a major credit reference...  ...We're looking for an Analyst, Global Incident Response to join our growing Global Incident Response...  ...industry knowledge around insurance, cyber security, identity protection and/or government... 
    Cyber
    Full time
    Contract work
    Part time
    Bank staff
    Remote work
    Flexible hours

    TransUnion

    United States
    12 hours ago
  • $80k - $92k

     ...This is a contingent position based upon customer approval. SkyePoint Decisions is seeking an experienced Tier 2 Analyst for the Cyber Incident Response Team to support our customer's Federal Strategic Cyber Mission program. This is not a remote position. This... 
    Cyber
    Contract work
    Local area

    SkyePoint Decisions

    Beltsville, MD
    a month ago
  •  ...Information Security Incident Response Analyst Make an impact with NTT DATA. Join a company that is pushing the boundaries of what is possible...  ...OT protocols and system behavior, and assess the impact of cyber incidents on physical processes. Certifications ~... 
    Cyber
    Remote work

    NTT DATA

    United States
    10 hours ago
  •  ...identify potential security threats. Prioritize and differentiate between potential intrusion attempts, false alarms, and risks. Properly respond to alerts that require incident response review. Develop and tune threat detection policies, rules, and intelligence. Incident... 
    Cyber

    Randstad

    Boston, MA
    2 days ago
  •  ..., a leading Fortune 100 transportation company in Memphis, TN, is looking for a Senior Cyber Security Incident Response Analyst. The successful candidate will manage Tier 3 and Tier 4 cyber security incidents, conduct thorough investigations, and develop automated response... 
    Cyber
    Remote work

    Insight Global

    Memphis, TN
    5 days ago
  •  ...Cybersecurity Incident Response Coordinator The Cybersecurity Incident Response Coordinator at...  ...crisis management ~ Familiarity with cyber incident response processes, including detection...  ...EDUCATION - Bachelor's or 4 years of work experience above the minimum... 
    Cyber
    Work experience placement

    Baylor University Medical Center

    Dallas, TX
    9 hours ago
  •  ...Exploitation Analyst Opportunity Sentar is dedicated to developing...  ..., programming, information/cyber/network security,...  ...Determines EA Level 1, 2, 3, or 4) ~ Bachelor's Computer Science...  ...intrusion detection, threat hunting, incident response) Multiple analytical focus... 
    Cyber
    For contractors

    Sentar

    Honolulu, HI
    4 days ago
  •  ...is seeking a mid-level resource to support Cyber Operations with a non-profit client. This role demands expertise in incident response and vulnerability management using tools like...  ...Microsoft Security suite. The ideal candidate has 2–4 years of experience, excellent... 
    Cyber

    Rapid Strategy

    New York, NY
    4 days ago
  •  ...Senior Incident Response Analyst Location: Remote (USA-based, on-call support required) Employment Type: Full-time The Senior Incident...  ...and security best practices Required Qualifications ~4-6 years of incident response and cybersecurity experience,... 
    Full time
    Remote work
    Shift work

    Veracity

    United States
    2 days ago
  • $7.5k

     ...Forensic Analyst 4 Location: Central Maryland Security Clearance...  ...Scientists, Cryptologic Cyber Planners, Intrusion Analysts,...  ...Analysts and Reverse Engineers, responsible for improving, protecting,...  ...investigate computer security incidents in order to derive useful intelligence... 
    Cyber
    Contract work
    Work experience placement
    Immediate start
    Flexible hours

    RealmOne

    Baltimore, MD
    1 day ago
  •  ...Senior Cybersecurity Incident Response Administrator This position is contingent upon contract...  ...practices. The engineer will review Army Cyber Tasking Orders (CTOs), coordinate with Army...  ...by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). These... 
    Cyber
    Contract work
    For contractors
    For subcontractor
    Work at office

    Janus Research Group

    Radford, VA
    3 days ago
  •  ...Secured Cyber is looking to fill several SOC analyst positions IMMEDIATELY to perform duties related to Incident Response at the Drug Enforcement Administration Security Operation Center in...  ...Information Technology discipline OR 4 additional years experience. EXPERIENCE... 
    Cyber
    Work experience placement
    Immediate start
    Monday to Friday
    Night shift
    Weekend work
    Day shift

    Secured Cyber

    Fairfax, VA
    1 day ago
  •  ...company headquartered in Memphis, TN is looking for a Senior Cyber Security Incident Response Analyst. The Cyber Incident Response Analyst will report to the...  ...and will be responsible for handling Teir 3 and Teir 4 level cyber security incidents. This role ensures timely... 
    Cyber
    Remote work

    Insight Global

    Memphis, TN
    2 days ago
  • $70 per hour

     ...environment. This role joins an existing team of 4 and is focused on execution, helping...  ..., triage, and remediate endpoint-related incidents, with a heavy emphasis on DLP (50% of...  ...remainder across endpoint security, incident response, and vulnerability management. This is... 
    Cyber

    Insight Global

    Boston, MA
    2 days ago
  •  ...Description Hybrid 4+ days onsite in New York, NY Our client seeks a cybersecurity...  ...with strong digital forensics and incident response experience to support a 24x7 operations...  ...Responsibilities Support a 24x7 cyber operations center through cyber incident... 
    Cyber

    Eliassen Group

    New York, NY
    5 hours ago
  •  ...Job Description Job Description Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public Trust (or eligibility to obtain) We... 
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy Consulting Group

    Washington DC
    19 days ago
  • $65 - $68 per hour

     ...leading organization in the energy industry, is seeking a Cyber Security Analyst - Incident Response to join their team. As a Cyber Security Analyst -...  ...Needed?8+ years of experience in a cyber defense role or 4+ years with a relevant bachelor's degree.Proficiency with... 
    Cyber
    Remote work
    Flexible hours

    ManpowerGroup Global, Inc.

    Chickasha, OK
    2 days ago
  •  ...Cybersecurity Incident Response Engineer, Mid The Cybersecurity Incident Response Engineer, Mid...  ...Qualifications Assumption: Typically 4–7 years of hands-on experience in...  ...management platforms integrated with SOC and cyber defense functions. Certifications... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Remote work

    ASM Research

    United States
    11 hours ago
  • $104k - $166k

     ...Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS Job Locations US-VA-Arlington Requisition ID 2026-163...  ...relevant experience; Master's degree and 3 years. An additional 4 years of relevant experience will be considered in lieu of... 
    Cyber
    Contract work
    Currently hiring
    Shift work
    1 day per week

    Peraton

    Arlington, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber incident response analyst 4. Be the first to apply!