Senior Incident Response Analyst
$132.48k - $336.96kTikTok USDS Joint Venture
Responsibilities About the Team The TikTok USDS JV Security Operations Center (SOC) is responsible for global around-the-clock monitoring, response, mitigation, and resolution of critical security events to protect and defend TikTok US data, infrastructure, customers, users, and products. Aside from monitoring TikTok US infrastructure and networks for indicators of anomalies, breach, and/or unauthorized access, the SOC is responsible for leading response efforts to enterprise-wide incidents, including post-incident root-cause analysis and recovery efforts, as well as leading proactive investigations into threats otherwise unidentified, developing and maintaining response plans, playbooks, and procedures. About the Role This role is based in our Converged Security Operations Center in Washington, D.C., working closely in a follow-the-sun model with our global SOC counterparts in London and Sydney. This is a highly proactive, technical, and high-stakes role. It requires a high degree of autonomy and a self-starter mentality - driven by an unwavering passion to defend the enterprise and minimize impact during critical security incidents. As an IR Analyst, you will belong to a team of strong people, processes, and technologies responsible for monitoring, investigation, containing, eradicating, and recovering from sophisticated threats targeting TikTok's US operations, users, and infrastructure. As a key member of the SOC, you will effectively fuse an understanding of the global threat landscape with deep knowledge of our US-based business operations to lead incident identification, investigation, cross-team management, containment strategies, and remediation efforts that make tangible impacts to the security of the business. Responsibilities You will drive technical response actions to protect our stakeholders and US-based users from increasingly fast-paced and AI-driven threats and attackers, including develop and tuning alerts to quickly identify anomalous and/or malicious activity occurring within TikTok USDS JV infrastructure. You will leverage AI-driven and agentic tools and methodologies, paired closely with your investigative and problem-solving skills to conduct comprehensive investigations and root-cause analysis to guide the business in unearthing, evicting, and recovering from attacks from sophisticated threat actors. You will collaborate closely with a variety of partner teams, including the Hunt team, Cyber Threat Intelligence, Digital Forensics, Legal, and Infrastructure teams to coordinate seamless, effective, and efficient operations. To be most successful in this role, you must excel in highly complex, ambiguous situations, transforming chaotic incident signals into clear paths forward to ensure the resiliency of our critical US operational infrastructure, customers, users, and data. Qualifications Minimum Qualifications 5+ years of experience directly triaging, managing, investigating, and remediating high-severity security incidents Proven experience and capability leading teams in performing deep and complex global investigations involving a multitude of disparate data sources from teams and regions spanning the globe Deep hands‑on Linux/Unix command line experience for low‑level system interrogation, log analysis, and artifact collection Hands‑on experience with cloud forensics and incident response across multi‑cloud infrastructure, including container and container‑level forensics (e.g., Docker, Kubernetes, container runtime logs) during active security investigations Must possess the ability to navigate the chaos of an active breach, make progress without prescriptive direction, proactively drive remediation solutions a high degree of integrity, and have the ability to lead and inspire change through post‑incident lessons learned Preferred Qualifications: Demonstrated teamwork and collaboration skills in leading or contributing to global, multi‑functional incident response teams Demonstrated time management, problem‑solving, and strict effort prioritization and within multiple constraints Strong cross‑functional expertise across multiple IT operational, network, cloud, and security disciplines Excellent communication skills (verbal and written) with the ability to act as a technical leader or incident commander and influence without authority during crises Ability to effectively translate complex technical compromise details into clear executive summaries for a broad range of technical and non‑technical staff Strong understanding and aptitude toward leveraging AI tools to accelerate investigation speeds and response efficacy Excellent fundamental knowledge of industry‑standard incident handling frameworks (e.g., NIST SP 800‑61, ISO/IEC 27035, MITRE ATT&CK) Proven capability and experience in performing deep and complex network analysis using PCAP captures and Zeek logs to reconstruct threat activity and adversary C2 communications Proven experience with live incident identification, investigation, containment, eradication, and recovery from advanced persistent threats (APTs) and threat actor TTPs Tenured experience and efficiency in querying, parsing, and analyzing large‑scale datasets across large data warehouses and distributed data architectures About USDS TikTok USDS Joint Venture LLC is dedicated to the safety and security of millions of Americans who create, discover, and connect with what they love on the apps we operate. The Joint Venture has been established in compliance with the Executive Order signed by President Trump on September 25, 2025. Our foundation is a comprehensive data privacy and cybersecurity program we operate under defined safeguards to protect national security and secure U.S. user data, apps and the algorithm. We safeguard the U.S. content ecosystem, holding decision‑making authority for trust and safety policies and moderation. USDS Joint Venture helps ensure Americans can continue to express their creativity, discover new hobbies and interests, and build thriving communities and businesses on a global scale. On‑site presence across teams allows the company to operate with greater speed, alignment, and agility — especially in areas like real‑time decision‑making, team development, and integrated execution. As such, the company is shifting from a hybrid work model to a fully in‑person schedule up to 5 days a week. Why Join Us Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day. We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us. Diversity & Inclusion TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too. USDS Reasonable Accommodation USDS is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at Job Information 【For Pay Transparency】 Compensation Description (Annually) - Washington, DC The base salary range for this position in the selected city is $ 132480 - $ 336960 annually. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units. Benefits may vary depending on the nature of employment and the country work location. Employees have day one access to medical, dental, and vision insurance, a 401(k) savings plan with company match, paid parental leave, short-term and long-term disability coverage, life insurance, wellbeing benefits, among others. Employees also receive 10 paid holidays per year, 10 paid sick days per year and 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure). The Company reserves the right to modify or change these benefits programs at any time, with or without notice. #J-18808-Ljbffr TikTok USDS Joint Venture
$131.3k - $237.35k
...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services...SeniorFull timeFlexible hours$120k - $135k
...Senior Incident Response Analyst Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business...SeniorPermanent employmentContract workRemote work2 days per week$131.3k - $237.35k
...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support...SeniorFlexible hours$131.3k - $237.35k
Leidos Inc is seeking a Senior Incident Response Analyst to join their team in Arlington, Virginia. The role involves coordinating incident response efforts, analyzing cyber threats, and developing security protocols for the Department of Homeland Security's CISA Program...Senior- Cortek, Inc. is seeking a Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency engagements... ...enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret...SeniorWork at office
$100k - $125k
A cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA. This role involves serving as a subject matter expert in incident response, requiring strong analytical skills and an active TS/SCI clearance. Candidates should have over 8 years...Senior- Edgewater Federal Solutions is seeking a Tier II Incident Response Analyst to support a federal government contract. The role requires US Citizenship and offers opportunities to work on enterprise security incidents within a government program. The ideal candidate will...SeniorContract work
- bcmcllc is seeking Host Forensics Analysts to support the DHS’s Hunt and Incident Response Team (HIRT). This role focuses on forensic investigations and incident response, requiring an active TS/SCI clearance. Candidates should possess at least 8 years of experience in...Senior
$90k - $120k
...firsthand. Potomac Haven is looking for a Senior Analyst with real, hands‑on experience in the... ...assault and harassment prevention and response field to support the National Science Foundation... ..., sexual harassment and stalking incidents and is responsible for overseeing...SeniorTemporary workWork at officeRemote work- ...Incident Response Analyst (Task 4 - Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public Trust (or eligibility to obtain) We are seeking an experienced Incident...Full timeContract workRemote workMonday to Friday
$94k - $127k
...Description Incident Response Analyst Xcelerate Solutions is seeking an Incident Response Analyst to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join...- cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance...Work at office
- SkyePoint Decisions is seeking an Incident Response Analyst to support cybersecurity operations by monitoring, analyzing, investigating, and responding to security incidents across enterprise, cloud, network, and endpoint environments. The analyst will work with security...Remote job
- Xcelerate Solutions is seeking an Incident Response Analyst to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Location: Alexandria, VA and Seaside, CA. Responsibilities...
$60k - $85k
Overview Edgewater is seeking an Incident Response Analystto provide support to an Edgewater Federal government contract. ** Due to the nature... ...is required ** Responsibilities As an Incident Response Analyst, you and team will be responsible for: Manning a 24x7x365 cybersecurity...Contract workFlexible hours$53.9k - $120.1k
Cybersecurity Incident Response Triage IR Analyst Arlington, VA The Cybersecurity Incident Response Triage IR Analyst role will work in the CIRT team in the CISO organization. This role works under analysis and triage team lead to perform in-depth investigation and analysis...Work experience placementLive inWork at officeLocal area$85k - $110k
Overview Edgewater Federal Solutions is currently seeking a Tier II Incident Response Analyst to provide support to an Edgewater Federal government contract. **Due to the nature of the contract and work, US Citizenship is a requirement** Responsibilities Understand Enterprise...Contract work- SkyePoint Decisions seeks an Incident Response Analyst to monitor, analyze, and respond to security incidents across enterprise, cloud, network, and endpoint environments. The role collaborates with security engineers and government stakeholders to identify threats, contain...Remote job
- Qualifications At least 2 years of incident response experience Experience with Crowdstrike and Web Application Firewall (WAF) Proficient with at least one scripting language (Python, Java, PowerShell, Bash) Cloud experience is a plus Responsibilities Address cybersecurity...Remote workVisa sponsorship
- A cybersecurity firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site support for DoD customers, possessing technical skills in intrusion detection and prevention, and will have a...
- ...weekend and holiday workdays. Responsibilities Provide on-site CSSP/IR... ...detailed triage of CSSP/IR incidents including implementing intrusion... ...recommended mitigations suitable for senior leaders and technical... ...PROVIDER/INCIDENT RESPONSE ANALYST #J-18808-Ljbffr Bespoke...Work at officeMonday to FridayWeekend work
- Xcelerate Solutions seeks an Incident Response Analyst to support CyberPRIMES cybersecurity, privacy, records and information management for DHRA. The role requires an Active Secret clearance and collaboration with government stakeholders across multiple environments. Minimum...
- Nightwing Group is seeking a Business Analyst to support onsite incident response for U.S. Government agencies experiencing cyber-attacks. The role involves gathering requirements, stakeholder coordination, and ensuring technology integration aligns with operational priorities...
- ...EmergencyMD is seeking a Lead Incident Responder for a potential government client. This role will involve leading incident response operations, managing complex threats, and ensuring compliance with federal cybersecurity frameworks. The candidate must have a Bachelor...Senior
- ...VA seeks a Security Operations Center Analyst to monitor, detect, and respond to cyber... ...networks. The role includes SIEM monitoring, incident handling, log analysis, and... ...to contain and recover from incidents. Responsibilities include monitoring devices, performing...
- SkyePoint Decisions is seeking a Threat Detection & Response Analyst to monitor enterprise systems, investigate security events, and respond to cybersecurity incidents. The Analyst collaborates with Incident Response, Vulnerability Management, RMF teams, and system owners...Remote job
- SkyePoint Decisions seeks a Threat Detection & Response Analyst to monitor enterprise systems, investigate security events, and respond to cybersecurity incidents across cloud, on-premises, and networks. The role emphasizes MITRE ATT&CK alignment and continuous monitoring...Remote job
$150k - $180k
...expertise and support to maximize cyber fusion across the Client’s SOC. The role requires 8+ years in cybersecurity threat hunting or incident response, with strong SIEM, EDR, and malware analysis skills, and eligibility for US citizenship. On-site in Frederick, MD, with...Senior- Edgewater Federal Solutions is seeking an Incident Response (IR) Manager to lead a team of IR Tier-1, Tier-2, and Forensics specialists on a Federal government contract. The role also serves as the Right-of-Boom Deputy to the Cybersecurity Operations Task Lead. The candidate...SeniorContract work
- bcmcllc is looking for a Solutions Architect to support U.S. Government mission by providing incident response related to cyber-attacks. This position demands extensive experience in systems engineering, along with capabilities in cybersecurity and technical analytics....Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Incident Response Analyst. Be the first to apply!
- pay analyst Washington DC
- design analyst Washington DC
- internal audit analyst Washington DC
- open source analyst Washington DC
- production control analyst Washington DC
- legislative analyst Washington DC
- trade analyst Washington DC
- accessibility analyst Washington DC
- soc analyst Washington DC
- hybrid analyst Washington DC

