Staff Incident Response Analyst
BetterCloud
About AlphaSense: The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision‑making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content. The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI‑driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us! About the Role: We are hiring a Staff Incident Response Analyst to serve as the technical escalation point for our L2 SOC analysts and 24/7 managed detection and response (MDR) partner. When a case exceeds what an L2 can handle — complex forensics, multi‑system intrusions, ambiguous attacker behavior, or high‑stakes containment decisions — it lands with you. You are the last line of technical defense before the Security Operations Manager is pulled in. This is a deeply hands‑on role. You will spend the majority of your time in tooling: hunting through the SIEM, pulling host artifacts via EDR remote access, tracing IAM chains in cloud audit logs, and reconstructing attacker timelines from raw evidence. You are expected to know what you are looking at without being told, and to be faster and more thorough than the analysts escalating to you. Core Responsibilities: Escalation Handling & Incident Leadership Receive and own L2 escalations across all severity levels; take over technical lead role on Sev2+ Scope incidents accurately and quickly: determine blast radius, affected assets, and attacker objectives from available telemetry Make and document containment decisions — endpoint isolation, account suspension, token revocation, network block — with clear rationale Maintain a forensically sound incident timeline: ordered evidence, source attribution, and chain‑of‑custody throughout Communicate incident status to the Security Operations Manager with enough fidelity to brief upward without needing to re‑investigate Drive incidents to documented closure: root cause, attacker path, affected assets, and defensive gaps identified Host & Endpoint Forensics Perform deep‑draw endpoint triage via EDR: process tree analysis, remote artifact collection, behavioral event review, and custom detection rule evaluation Reconstruct attacker activity from Windows forensic artifacts: Prefetch, Shimcache, Amcache, MFT, $USNJrnl, event logs (4624, 4688, 4698, 7045), and registry hives Analyze Linux host artifacts: bash history, cron jobs, /tmp and /var/log contents, SUID binaries, and persistence mechanisms Perform memory forensics when warranted: process injection, credential extraction artifacts, and in‑memory malware indicators Extract and analyze malware samples statically and dynamically: PE header review, strings, YARA matching, and sandbox detonation interpretation Cloud Incident Response — AWS & GCP Lead AWS‑based IR: CloudTrail forensics, IAM chain reconstruction, EC2 isolation, S3 access pattern analysis, Lambda execution review Identify and respond to IMDS credential abuse, assumed‑role lateral movement, and cross‑account privilege escalation Investigate container and serverless incidents: ECS task behavior, Lambda invocation logs, and abnormal API call sequences Correlate VPC Flow Logs, native threat detection findings, and S3 access logs against SIEM events to build a complete cloud‑side timeline Handle GCP incidents using Cloud Audit Logs, Cloud Logging, and IAM policy review in a multi‑cloud context Use cloud security posture management (CSPM) findings and runtime data as investigative context during active incidents Identity & SaaS Forensics Investigate identity provider incidents: admin audit log review, session anomaly analysis, suspicious app assignments, MFA bypass patterns, and provisioning events Perform customer identity and access management (CIAM) forensics: authentication log analysis, abnormal grant flows, token misuse, and tenant‑level anomaly investigation Reconstruct identity‑based attack chains across the IdP, cloud IAM, and application layers — from initial credential compromise through lateral movement Identify and respond to OAuth abuse, token theft, session hijacking, and federated identity attacks Threat Hunting & Detection Contribution Conduct structured threat hunts in the SIEM using detection rule logic, event correlation queries, and multi‑source pivoting Hunt for attacker behavior that existing detections miss: living‑off‑the‑land techniques, LOLBins, slow‑and‑low persistence, and C2 beaconing patterns Translate hunt findings and post‑incident learnings into specific detection recommendations or rule drafts for the Security Operations Manager Contribute to ATT&CK coverage visibility by flagging technique gaps surfaced during investigations or hunts L2 Escalation Support & Quality Take escalation handoffs from L2 analysts and the MDR partner; provide technical direction when an analyst is stuck, not just take the case Review escalation packages for completeness and accuracy — push back when context is insufficient and coach on what’s missing Identify recurring escalation patterns and flag them to the Security Operations Manager as potential L2 training gaps or detection tuning needs Document investigation methodology on closed cases in enough detail that an L2 analyst can learn from the approach Required Qualifications: 6+ years of hands‑on incident response experience, with at least 3 years performing technical IR at a senior or staff level Expert‑level EDR proficiency (e.g., CrowdStrike Falcon, SentinelOne, or equivalent): remote triage, process tree analysis, behavioral detections, and custom detection rule authorship Deep AWS IR capability: CloudTrail forensics, IAM chain analysis, EC2 and Lambda investigation, and IMDS/assumed‑role abuse patterns Strong Windows forensics: ability to reconstruct attacker activity from Prefetch, MFT, Shimcache, event logs, and registry artifacts without tooling assistance Solid Linux forensics: persistence mechanisms, cron, SUID analysis, process anomalies, and log artifact interpretation Hands‑on SIEM investigation and detection experience (e.g., Google SecOps/Chronicle, Splunk, Microsoft Sentinel): writing detection logic, pivoting on normalized events, and multi‑event correlation Identity incident response experience in an enterprise IdP (e.g., Okta, Entra ID): audit log forensics, session analysis, app‑layer anomalies, and admin abuse patterns Demonstrated ability to scope and lead Sev1 incidents autonomously, including containment decisions and cross‑functional coordination Strong technical writing: you produce investigation timelines, evidence summaries, and escalation handoffs that are accurate, concise, and unambiguous MITRE ATT&CK fluency: you use it to communicate attacker behavior, not just as a reference Preferred Qualifications: Memory forensics experience using Volatility or equivalent: process injection, credential material in memory, and rootkit indicators Malware analysis capability: static analysis (PE headers, strings, imports), dynamic sandbox review, and YARA rule authorship GCP IR experience using Cloud Audit Logs, VPC Flow Logs, and IAM policy analysis in a live incident context CIAM forensics experience (e.g., Auth0, Cognito): authentication logs, abnormal grant flows, and token misuse investigation Experience receiving and evaluating escalations from an MSSP/MDR, including identifying under‑triaged or misrouted tickets Familiarity with CSPM tooling (e.g., Wiz, Prisma Cloud, Orca) as an investigative data source during cloud incidents DFIR certifications: GCFE, GCFA, GCFR, GREM, GCIH, or equivalent practical forensics credentials Prior experience in a SaaS company, financial services, or other regulated environment handling sensitive customer data AlphaSense is an equal—opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non‑merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination. In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations, and ordinances where a particular employee works. Recruiting Scams and Fraud We at AlphaSense have been made aware of fraudulent job postings and individuals impersonating AlphaSense recruiters. These scams may involve fake job offers, requests for sensitive personal information, or demands for payment. Please note: AlphaSense never asks candidates to pay for job applications, equipment, or training. All official communications will come from an @alpha-sense.com email address. If you’re unsure about a job posting or recruiter, verify it on our Careers page. If you believe you’ve been targeted by a scam or have any doubts regarding the authenticity of any job listing purportedly from or on behalf of AlphaSense, please contact us. Your security and trust matter to us. #J-18808-Ljbffr BetterCloud
- Butler University is seeking an Information Security Analyst for Risk and Incident Response to support vulnerability management, incident response, and risk assessments. You will administer security tools, investigate cybersecurity events, and implement controls to protect...Suggested
- Position Overview The Information Security Analyst for Risk and Incident Response (\"Analyst\") provides technical expertise in support of Butler University... ...assessments. The position also partners with technical staff to integrate security best practices into the design,...SuggestedFull time
- Lilly is seeking a Cyber Threat Intelligence Lead Analyst to drive strategy and maturation of the CTI function across Global Cyber Defense Operations. You will lead threat actor tracking, attribution, and intelligence sharing while guiding brand protection efforts and collaboration...Suggested
- ...Primary Duties Work with a multi‑disciplinary team of analysts and clinical staff in performing analysis of health‑related and financial information... ...Maintain thorough electronic documentation Additional responsibilities as assigned Preferred Qualifications Master’s degree...SuggestedWork experience placementInternshipWork at office
- ...threat hunting, and identification of intrusions and potential incidents.Minimum 2 years of experience in deploying or supporting OT... ...As a business imperative, every person at Accenture has the responsibility to create and sustain an inclusive environment.Inclusion and...SuggestedFull timeWork experience placementLive inWork at officeLocal areaRemote work
- ...Junior SOC Analyst Job Number : 32338 Location : Indianapolis,... ...systems and ensuring continuity in high-responsibility environments. Before you Apply... ...detecting, and responding to Cyber events and incidents under supervision supporting the...Full timeImmediate startFlexible hoursShift work
$40k
...that matter at a national scale. The Junior CIC Analyst supports 24x7 Command and Incident Center operations by executing routine service requests... ...217, T1, Band 4 Job-Specific Essential Duties and Responsibilities: Provide operational support within the Command...Contract workRemote workShift workNight shift- ...Electronic Health Record (EHR) system. Responsible for helping optimize workflow processes... ...systems. Provides second‑level support for incidents and requests related to the Epic... ...cross‑functional teams involving clinical staff, IT professionals, and business leaders....Local area
- ...Security Staff - Part Time - All Shifts Conner Prairie Museum - Fishers, IN 46038... ...Function: The Security Desk Attendant is responsible for monitoring all security systems on site... ...to emergencies, alarms and medical incidents Education and/or Experience: High...Part timeImmediate startAll shiftsShift workNight shiftAfternoon shift
- Job Title People Technology Analyst Overview The People Technology Analyst is a key technical... ...partnership and end‑user advocacy. Responsibilities Configure, maintain, and support... ...system issues, defects, and user‑reported incidents Support mass data loads (EIBs), data corrections...Temporary workWork at officeLocal areaShift work
$81.85k - $100k
...currently hiring for a remote Business Analyst to support the EPA. This position is within... ...United States and is fully remote. Responsibilities As part of the EPA ESSET team,... ...etiquette ~ Follow processes to resolve incidents and problems in a timely, high-quality...Full timeCurrently hiringWork at officeRemote workFlexible hours- ...Systems AnalystJob Overview:Business Systems Analyst assists in requirements gathering and... ..., this is a great learning experience.Responsible for helping to educate the company on our... ..., and report any suspected security incidents to support our information security controls...Night shift
$50 - $55 per hour
...Required: 8-10 EDI Business Analyst Retail Integrations, Order-to-... ...technical discussions. Key Responsibilities Business Analysis & Requirements... ...tools, or scorecard management. ITIL, incident management, problem management, or production...Work at officeRemote workWork from home- The People Technology Analyst is a key technical role that lives within the JD North America... ...Regional Business Services function is responsible for supporting all US businesses within... ...issues, defects, and user-reported incidents in a timely manner Support mass data loads...Temporary workWork at officeShift work
- ...Product Support Analyst T2 Systems is the largest parking, mobility... ...internal teams, with primary responsibility for providing break/fix... ...troubleshooting tools, customer and staff training materials, product... ...needed. Participates in Incident Management and technical...Work at officeRemote workFlexible hoursAfternoon shift
$120.2k - $140k
...GDPR/HIPAA as applicable). Work you’ll do/Responsibilities As a Clinical Data AMS Senior... ...access provisioning, and issue triage. Lead incident, problem, and change management across... ...Lead teams comprising consultants and analysts and drive delivery within the quality and...Permanent employmentLocal areaRemote workVisa sponsorship$74.3k
...GRC Analyst Print ( Apply GRC Analyst Salary $74,295.00 Annually Location... ..., Risk, and Compliance (GRC) Analyst is responsible for implementing the internal control... .... In the event of a security incident, support Incident Manager in completing...Full timeWork experience placementWork at office$101.4k - $152.1k
...highly skilled and motivated SAP Supply chain Analyst to support S/4 HANA solutions. Ideal candidate is responsible for supporting, maintaining, and enhancing Belden... ...Chain Planning processes i.e ePP/DS, & QM Lead incident resolution, problem management, and root cause...Temporary workWork at officeRemote work- ...ability to handle unique situations for all customers. This role is responsible for managing customer orders for the largest Allison customer(... ...and maintain unique customer order processes.Train new order analysts and cross train current analysts for back-up purposesOrganize...Full timeWork at officeLocal areaImmediate startWorldwide
- POSITION SUMMARY Consulting Group Analysts provide exceptional service to our clients and support Financial Advisor(s) (FAs)/ Private... ...reporting and analysis. The Consulting Group Analyst is also responsible for matters of technical policy and standards, presentation materials...Local area
- ...Off12 Paid Holidays + 1 Floating HolidayRobust employee wellness programTuition assistance programJob Description:The Senior Analyst is responsible for leading the consolidated cash flow and capital expenditure reporting processes for a multinational company with...Full timeImmediate startWorldwide
- ...contributionAccrued Paid Time Off12 Paid Holidays + 1 Floating HolidayRobust employee wellness programTuition assistance programJob Description:Responsibilities: Manage the monthly, quarterly, and annual consolidation of the company’s income statement across two business segments....Full timeImmediate startWorldwide
- ...helping our healthcare partners thrive. Position Summary The Principal Database Administrator is a senior technical leader responsible for the design, implementation, optimization, and ongoing support of enterprise database environments that underpin Versiti's...Full timeTemporary workLocal area
- ...resolution of findings. Contribute to improving monitoring tools, templates, and procedures. Assist internal staff and sub awardees with audit preparation and responses. Note: Duties may evolve or be assigned as needed. RequirementsKnowledge of Federal and State laws,...Local area
- The Senior HRIS Analyst plays a critical role in supporting and optimizing HR technology, serving as an experienced functional and... ...integrity while driving operational excellence.Job Duties and Responsibilities:System Maintenance & System Support - 40%Configure, maintain,...Full timeFlexible hours
$18.02 - $34.9 per hour
...initiates an investigation. • Verify (SPV) analytical data of other analysts within the lab as required. Continuous Improvement Initiatives... ...process and any other correspondence will not receive a response.Lilly is proud to be an EEO Employer and does not discriminate...Full timeH1bWork at officeVisa sponsorshipWork visaFlexible hoursNight shift$91.1k - $179.5k
...in a collaborative environment? As an experienced Epic ASAP Analyst, you will have the ability to share new ideas and collaborate... ...competitive for project delivery-focused professionals.Work you’ll do/Responsibilities Lead the implementation and ongoing support of Epic ASAP for...Local areaImmediate startNight shift$53.22k
...Legal Analyst Date Posted: Aug 21, 2026 Requisition ID: 482830 Location: Indianapolis... ...Office of Judicial Administration is responsible for the efficient administration of all... ...The Paralegal supports the work of the Staff Attorneys, the Deputy Directors and the...Full timeWork at officeLocal area- ...Posted 6 Days Agojob requisition id: JR135593The Allocation Analyst provides a compelling assortment of the right product, to the... ...values of Customer, People, Winning, Community, and Financial Responsibility in everything they do while performing the following main duties...Permanent employmentTemporary workWork at officeLocal areaImmediate startShift work
$15 per hour
...what they said! Job Summary Summary: Responsible for patient food service on assigned... ...accurate manner. Interacts with nursing staff to ensure patients' diet prescriptions... ...safety policies and procedures to include incident reporting. Follows facility and...Hourly payFull timePart timeLocal areaImmediate startRemote workMonday to FridayFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Incident Response Analyst. Be the first to apply!
- pay analyst Indianapolis, IN
- design analyst Indianapolis, IN
- internal audit analyst Indianapolis, IN
- production control analyst Indianapolis, IN
- accessibility analyst Indianapolis, IN
- soc analyst Indianapolis, IN
- hybrid analyst Indianapolis, IN
- chargeback analyst Indianapolis, IN
- collection analyst Indianapolis, IN
- senior database analyst Indianapolis, IN

