Incident Responder
$90.5k - $128.6kJetBlue
Position Summary:
At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment.
We are seeking an experienced Incident Response Analyst to support the Cyber Security Incident Response function through escalated alert triage, investigation, containment support, and response activities. The ideal candidate has hands-on experience analyzing security telemetry across multiple tools, can work independently through ambiguous investigations, and can clearly document findings, risk, and recommended next steps.
Essential Responsibilities:
- Monitor, triage, and investigate escalated security alerts and cases from internal tools, managed security providers, and other reporting channels.
- Analyze telemetry from multiple sources, including SIEM, endpoint detection and response tools, identity platforms, email security tools, cloud platforms, network devices, CDNs, and WAF technologies.
- Investigate suspicious or malicious activity, including phishing, malware, suspicious authentication, anomalous network activity, unauthorized access, endpoint compromise, and potential data exposure.
- Perform investigative scoping to identify affected users, hosts, accounts, applications, indicators, timelines, and potential business impact.
- Support incident response activities, including evidence gathering, containment support, remediation validation, and communication of technical findings.
- Execute approved response actions in accordance with established procedures, including account, endpoint, email, URL/domain, or indicator-based response steps.
- Create clear, defensible case notes and incident documentation, including observed activity, entities involved, timeframe, scope, conclusion, and remediation or follow-up actions.
- Collaborate with Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, and other stakeholders during investigations.
- Identify detection gaps, logging gaps, process breakdowns, recurring alert patterns, and opportunities to improve security monitoring and response capabilities.
- Build or support dashboards, searches, playbooks, reports, process documentation, and other operational improvements that improve incident response efficiency and quality.
- Provide guidance and support to less experienced analysts during triage, investigation, documentation, and escalation activities.
- Other duties as assigned.
Minimum Experience and Qualifications:
- Bachelor's Degree in Cyber Security, Computer Science, Information Technology, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience on a SOC, Incident Response, Threat Detection, or cyber security operations team.
- Three (3) years of hands-on experience performing alert triage, security investigations, incident response support, or similar technical security operations work.
- Demonstrated ability to analyze disparate data sources such as network logs, endpoint activity, authentication logs, cloud logs, email data, and SIEM events to assess suspicious or malicious activity.
- Experience investigating common security events such as phishing, malware, suspicious logins, anomalous network traffic, unauthorized access, suspicious process execution, or endpoint compromise.
- Ability to assess risk, determine likely impact, scope activity, and make appropriate escalation recommendations based on available evidence.
- Strong problem-solving and analytical skills, including the ability to work through ambiguous or incomplete information.
- Ability to demonstrate a high level of critical thinking and sound judgment during technical investigations.
- Ability to pass a live skills demonstration or technical interview on-site with JetBlue Crew Members.
- Experience with scripting, querying, or automation languages such as PowerShell, Python, KQL, SPL, or similar technologies.
- Ability to manage multiple cases and priorities in a fast-paced operational environment.
- Excellent written and verbal communication skills, including the ability to clearly document investigations and summarize technical findings.
- Available and willing to participate in periodic on-call duties and off-hours Incident Response as required.
- Available for occasional overnight travel (10%).
- Must pass a ten (10) year background check and pre-employment drug test.
- Must be legally eligible to work in the country in which the position is located.
- Authorization to work in the United States is required. This position is not eligible for visa sponsorship.
- Must be eligible to hold a US government security clearance if JetBlue deems it relevant to the role.
Preferred Experience and Qualifications:
- Five (5) or more years of experience in a SOC, Incident Response, Threat Detection, cybersecurity operations, or similar blue team function.
- Experience triaging and investigating security incidents in an enterprise environment or managed security services environment.
- Hands-on experience with SIEM platforms such as Splunk and EDR tools such as SentinelOne, CrowdStrike, Microsoft Defender, or similar technologies.
- Experience with SOAR or case management platforms, including documenting investigations, tracking actions, and following structured playbooks.
- Thorough understanding of networking principles such as DNS, TCP/IP, proxies, firewalls, VPNs, and how they relate to security investigations.
- Basic knowledge of one or more cloud environments such as AWS, Azure, or Google Cloud and related cloud security investigation concepts.
- Experience with identity and access investigations, including MFA events, session activity, privileged access, and account compromise indicators.
- Familiarity with common attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK.
- Experience supporting phishing, business email compromise, malware, endpoint compromise, suspicious authentication, web application, or data exposure investigations.
- Experience building dashboards, saved searches, alert logic, scripts, or other investigative content in security tooling.
- Airline, transportation, critical infrastructure, or large-enterprise experience in Security Operations, Incident Response, Threat Detection, or Threat Intelligence.
- Strong sense of urgency, ownership, and drive to continuously improve the craft of incident response.
Crewmember Expectations:
- Regular attendance and punctuality.
- Potential need to work flexible hours and be available to respond on short notice.
- Able to maintain a professional appearance.
- When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft.
- Organizational fit for the JetBlue culture, that is, exhibit JetBlue's values of Safety, Caring, Integrity, Fun and Passion.
- Promote JetBlue's #1 value of safety as a Safety Ambassador, supporting JetBlue's Safety Management System (SMS) components, Safety Policy and behavioral standards.
- Must fulfill safety accountabilities as prescribed by JetBlue's Safety Management System.
- Responsible for adhering to all applicable laws, regulations (FAA, OSHA, DOT, etc.) and Company policies, procedures and risk controls.
- Responsible for ensuring crewmembers have requisite training, resources and support to achieve safety objectives.
- Identify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue's confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR)).
- The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.
Equipment:
- Computer and other office equipment.
Work Environment:
- Traditional office environment.
Physical Effort:
- Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)
Compensation:
- The base pay range for this position is between$90,500.00 and $128,600.00 per year. Base pay is one component of JetBlue's total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.
#LI-AC1
#LI-Hybrid
$91.1k - $170.4k
...experience.Information Security (InfoSec) - InfoSec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and... ...The opportunityThe Cyber & Investigative Services (CIS) Junior Incident Coordinator will exercise strong incident management techniques...SuggestedSummer holidayLocal areaRemote workFlexible hours$134.6k - $210.1k
...punctualityPotential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible...SuggestedTemporary workWork experience placementWork at officeImmediate startRemote workFlexible hoursNight shift$105.6k - $150.4k
...punctualityPotential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible...SuggestedTemporary workWork at officeImmediate startFlexible hoursNight shift$80k - $132k
...corrective/ mitigating action implementation. Reviews safety incidents and regulatory escapes, conducts investigation as required by... .... Potential need to work flexible hours and be available to respond on short-notice. Able to maintain a professional appearance....SuggestedTemporary workWork experience placementWork at officeImmediate startFlexible hoursNight shift$88k - $132k
...punctuality Potential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearance When... ...standards Identify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever...SuggestedTemporary workWork at officeImmediate startFlexible hoursNight shift$116.5k
...punctualityPotential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible...Contract workTemporary workWork at officeImmediate startFlexible hoursNight shift$89k - $133k
...punctualityPotential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible...Temporary workWork experience placementWork at officeImmediate startFlexible hoursNight shift$134.6k - $210.1k
...punctuality Potential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standards Identify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever...Temporary workWork at officeImmediate startFlexible hoursNight shift$80k - $132k
...punctuality Potential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever...Temporary workWork at officeImmediate startFlexible hoursNight shift$88k - $132k
...punctuality Potential need to work flexible hours and be available to respond on short-notice Able to maintain a professional appearance When... ...standards Identify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever...Temporary workWork experience placementWork at officeImmediate startFlexible hoursNight shift$118k
...punctualityPotential need to work flexible hours and be available to respond on short noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible...Temporary workWork at officeImmediate startFlexible hoursNight shift$114k - $170k
...punctualityPotential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible...Contract workTemporary workWork at officeImmediate startFlexible hoursShift workNight shift$114k - $170k
...weekends as needed, to support a 24/7 operationAvailability to respond to operational issues on short noticeAble to maintain a professional... ...standardsIdentify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible...Temporary workWork at officeImmediate startAll shiftsFlexible hoursShift workNight shift$118.8k - $177.1k
...outcomes to identify opportunities for continuous improvement.Lead incident response, production support, root cause analysis, and... ...punctuality Potential need to work flexible hours and be available to respond on short noticeAble to maintain a professional appearanceWhen...Temporary workWork at officeImmediate startRemote workFlexible hours$114k - $170k
...punctualityPotential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible...Temporary workWork at officeImmediate startFlexible hoursNight shift$240k - $330k
...plus Experience managing regulatory investigations, cybersecurity incidents, or crisis response International legal experience across... ...available Potential need to work flexible hours and be available to respond on short noticeAble to maintain a professional appearance When...Temporary workWork at officeImmediate startRemote workFlexible hoursNight shift$114k - $170k
...punctualityPotential need to work flexible hours and be available to respond on short noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and/or security concerns, issues, incidents, or hazards that should be reported and report them whenever possible...Temporary workWork at officeFlexible hoursNight shift$114k - $170k
...punctualityPotential need to work flexible hours and be available to respond on short-noticeAble to maintain a professional appearanceWhen... ...standardsIdentify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible...Temporary workWork at officeImmediate startFlexible hours- ...routes, schedules, and eligibility status. Review and close out incident reports using ServiceNow (SNOW) system. Monitor bus... ...reporting. Provide support in employee workforce management. Respond to and manage incidents, ensuring documentation and follow-up....Work at office
- Meriplex Communications seeks a Cyber Incident Responder to lead high-severity incident response for client environments. This senior role combines hands-on containment with leadership across SOC, service desk, and client teams. You will investigate endpoint, identity,...
$20 per hour
...into all applicable systems and databases. Answer phone calls and respond to emails in a timely and professional manner. Maintain accurate and up-to-date records and files (POs, receipts, incident reports, accident reports, etc.) in compliance with YMCA of Greater...Hourly payFull timePart time- ...Psychologist) Minimum of a master's degree in mental health Malpractice and Professional Liability Insurance coverage of $1,000,000/$3,000,000 Willing to complete R3C's Critical Incident Response training or proof of approved CIR training #J-18808-Ljbffr R3 ContinuumExtra incomeContract workLocal areaFlexible hours
$25 per hour
...Job Description Job Description Workplace Safety Responder — Part-Time Part-Time · $25.00 / hour · $200.00 daily minimum · Frequent Travel required - Must have a valid drivers license mhdhealth.com Help American workers go home safe. OSHA-required compliance...Hourly payPart timeLive inWork at officeLocal areaSleeping nightsMonday to FridayNight shiftWeekend workDay shiftAfternoon shiftWeekday work- ...require 24/7 support and on call responsibilities. Job Summary The Incident Manager is responsible for leading the timely restoration of... ...impact. •Executing structured processes to detect, assess, respond to, and recover from incidents, while coordinating across technical...Work experience placementWork at officeRemote workNight shiftWeekend work
- ...Priority Responder (Fire Chaser) 1-800 Water Damage of NYC is currently interviewing candidates to add to our growing Emergency Response Team. The position of Priority Responder (Fire Chaser) will respond upon real-time active emergency situations caused by fire or flooding...Local areaImmediate startNight shiftWeekend workDay shift
- We are seeking a highly skilled Incident Manager to lead Major Incident Management (MIM) and ensure rapid restoration of services during critical outages. This role is responsible for minimizing business impact, driving structured incident response, and continuously improving...
- ...is best for our customers. Brown & Brown is seeking a Technical Incident Commander to join our growing team in Daytona Beach, FL or... ...operational excellence, setting the standard for how the organization responds to, learns from, and prevents critical service disruptions. How...Local area
$18 - $19 per hour
...communication systems; report unusual activity, maintenance concerns, or access-control issues to appropriate personnel. Respond to incidents, resident concerns, and critical situations in a calm, professional, problem-solving manner, following established site procedures...Full timePart timeFor contractorsWork at officeLocal areaFlexible hoursShift work- ...client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.The analyst for Incident Response Planning and Operations is responsible for cyber security wargaming and incident readiness program. While the focus is...Full timeWork experience placementWork at officeLocal areaRemote workHome office1 day per week
- We are hiring for: Manager of Incidents & Investigations Type: Regular If you are a positive and personable individual looking for a satisfying and fun opportunity to make a real difference in the lives of people with intellectual, developmental disabilities, and people...Full timeContract workWork at officeLocal areaNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Responder. Be the first to apply!

