Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Response Analyst

Apex Systems Inc

Incident Response Analyst

An Incident Response Analyst is sought to join a co-sourced cyber operations environment. In this setting, an external managed security service provider handles primary SOC monitoring, and the internal team manages escalated investigations through to remediation. This position will provide operational coverage, investigate security events, coordinate response activities across technical teams, and strengthen vulnerability management and data loss prevention capabilities.

Key Responsibilities

  • Receive escalated alerts and tickets from the SOC, initiate investigations, determine scope and impact, and manage incidents through remediation and closure.
  • Investigate malware, phishing, unexpected network connections, and other security events by reviewing SIEM logs, endpoint telemetry, affected assets, and impacted users.
  • Coordinate with infrastructure, application, clinical technology, privacy, and other internal teams to contain threats and execute corrective actions.
  • Participate in the rotating SOC alert and on-call coverage model.
  • Execute and improve established incident response runbooks and support the continued development of operational procedures.
  • Use packet capture data at network egress points to trace threats and support response actions that require internal access or credentials.
  • Create, tune, and maintain custom detections and response scripts within the co-sourced security model.
  • Support vulnerability management operations by researching newly disclosed CVEs, identifying affected assets, validating exposure, and assisting in the prioritization of remediation.
  • Account for systems that may not appear in standard vulnerability tools, such as medical and other specialized devices, when assessing exposure.
  • Review DLP alerts and policies, investigate potential data exposure events, and coordinate escalation to the privacy team when events may involve PHI or patient impact.
  • Document investigations, response actions, findings, and remediation activities in ServiceNow in alignment with ITIL-based processes.

Required Qualifications

  • Approximately 5-10 years of relevant cybersecurity operations experience, with hands-on incident response and SOC escalation responsibility.
  • Demonstrated ability to independently investigate alerts, build a complete picture from multiple data sources, and coordinate an incident through remediation.
  • Experience reading and interpreting SIEM logs; Sumo Logic experience is preferred.
  • Hands-on experience with CrowdStrike for endpoint investigation, threat response, exposure research, and detection or response scripting.
  • A solid foundation in vulnerability management, including practical experience assessing CVEs, identifying affected assets, interpreting scanner findings, and prioritizing remediation.
  • Experience with vulnerability management platforms such as Tenable Nessus and Qualys; direct Tenable experience is preferred.
  • Experience investigating DLP events and understanding how DLP policies trigger; Microsoft Purview experience is preferred.
  • Working knowledge of ITIL practices and experience using ServiceNow for security operations workflows and ticket management.
  • Clear communication, sound judgment, and the ability to work effectively across technical and business teams during active investigations.

Preferred Qualifications

  • Experience in a healthcare environment or with security events involving PHI, medical devices, or patient-impacting systems.
  • Deep vulnerability management expertise and the ability to improve prioritization practices, recommend better operating approaches, and share knowledge with other team members.
  • Experience working in an operational security function where workload shifts based on active incidents and emerging threats.
  • Experience authoring custom detections and developing scripts that automate or accelerate threat response.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Incident Response Analyst in United States vacancy
  • $99k - $225k

    Incident Response Analyst, SeniorThe Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the United States government. In all of this “cyber noise,” how can these organizations understand... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    1 day ago
  • $135k - $175k

     ...team and play a key role in protecting the firm's global technology environment. This position is responsible for leading security investigations, coordinating incident response activities, advancing detection capabilities, and helping strengthen the processes, technologies... 
    Suggested
    Full time
    Monday to Friday
    Afternoon shift
    Early shift

    Hogan Lovells

    Baltimore, MD
    4 days ago
  •  ...security solutions provider in Texas is seeking a Cyber Security Analyst to implement security measures protecting client information...  ...policy development, conduct risk assessments, and support incident responses. A Bachelor's degree or equivalent experience in Information... 
    Suggested

    Compunnel

    San Antonio, TX
    5 days ago
  • Ford Motor Company is seeking a cybersecurity specialist to support monitoring operations and incident response for connected vehicles and cloud services. You will collaborate with PSOC teams globally to ensure timely investigations and effective mitigations. The role requires... 
    Suggested

    Ford Motor Company

    Dearborn, MI
    4 days ago
  •  ...in the United States. You will be at the forefront of identifying and investigating security incidents, and contributing to the continuous improvement of our incident response capabilities. This role requires a strong technical background, participation in on-call rotations... 
    Suggested
    Permanent employment
    Full time
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    Seattle, WA
    18 hours ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The Department of Homeland Security (DHS), Security Operations Center (SOC) Support... 
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    1 day ago
  •  ...a vital role in shaping a safer, more trustworthy AI-powered future.AI Fearlessly.Job DescriptionPosition Summary:The Sr.Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role... 
    Full time
    H1b

    Trend Micro

    Irving, TX
    2 days ago
  • $132.48k - $336.96k

     ...Responsibilities About the Team The TikTok USDS JV Security Operations Center (SOC) is responsible...  ...response efforts to enterprise-wide incidents, including post-incident root-cause analysis...  ...critical security incidents. As an IR Analyst, you will belong to a team of strong... 
    Temporary work
    Shift work

    TikTok USDS Joint Venture

    Washington DC
    1 day ago
  •  ...been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission‑critical government program. As part of the Security Operations Center, you will... 
    Permanent employment

    Tetrad Digital Integrity

    Arlington, VA
    2 days ago
  • $104k - $166k

     ...Senior Incident Response Analyst Job Locations: US Requisition ID: 2026-169782 Position Category: Cyber Security Clearance: No Clearance Required Responsibilities Position Is Contingent Upon Award Peraton Labs is hiring a Senior Incident Response Analyst to lead hands-... 
    Contract work
    Shift work

    Peraton

    Reston, VA
    2 days ago
  •  ...accommodation for individuals with disabilities. Posting Summary Rutgers, The State University of New Jersey, is seeking a Senior Incident Response Analyst for the Office of Information Technology. This position will report to the Associate Director. Performs daily operations... 
    Full time
    Temporary work
    Seasonal work
    Work at office
    Flexible hours
    Shift work

    Rutgers University

    Brooklyn, NY
    18 hours ago
  •  ...collaboration, and bold ideas. Are you ready to make an impact and help shape what’s next? We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This... 
    Worldwide

    Dun & Bradstreet

    Center Valley, PA
    18 hours ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support... 
    Flexible hours

    Leidos

    Arlington, VA
    3 days ago
  •  ...Senior Incident Response Analyst Location: Remote (USA-based, on-call support required) Employment Type: Full-time The Senior Incident Response Analyst will manage and resolve cybersecurity incidents across on-premises and cloud (AWS/Azure) environments,... 
    Full time
    Remote work
    Shift work

    Veracity

    United States
    2 days ago
  •  ...'ll join our Global Managed Detection & Response (MDR) team at exactly the right moment:...  ...triage and anomaly detection are enabling analysts to identify genuine threats faster,...  ...minutes and deliver insights that turn incidents into lasting security improvements. Every... 
    Full time
    H1b
    Work at office
    Night shift
    Rotating shift
    3 days per week

    Trend Micro

    Irving, TX
    18 hours ago
  •  ...Owning the end-to-end incident response process, the full-time Senior Incident Response Analyst will manage tier-1 and tier-2 incidents, conduct forensic investigations, and automate evidence collection while working remotely. Key responsibilities Lead detection validation... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  • $100k - $125k

     ...Senior Incident Response Analyst At Zimmer Biomet, we believe in pushing the boundaries of innovation and driving our mission forward. As a global medical technology leader for nearly 100 years, a patient's mobility is enhanced by a Zimmer Biomet product or technology... 
    Remote work
    Flexible hours

    Zimmer Biomet

    United States
    4 days ago
  • $95.7k - $144.9k

     ...through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities...  ...are looking for mid-level candidates with malware analysis and incident response experience. • Specific experience with triaging detections... 
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Denver, NC
    3 days ago
  • $95.17k - $156.36k

    This role sits at the intersection of hands-on incident response, cyber defense and threat mitigation. You will be part of a highly collaborative cyber defense and incident response organization, responding to and investigating high-impact security incidents.The ideal candidate... 
    Full time
    Work at office
    Visa sponsorship
    Work visa
    Flexible hours

    Guardian Life Insurance

    Holmdel, NJ
    18 hours ago
  •  ...Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to...  ...as a variable cost.Job Description· 5 + years Cybersecurity incident response and technical forensics investigation with 3 or more years in... 
    H1b
    Immediate start

    Artech

    Plano, TX
    3 days ago
  • Purpose and Impact: Amentum is seeking SOC / Incident Response Analyst to support our U.S. Department of Energy contract. Positions will be based in the Washington, D.C area.Work Schedule: 5 days, 8hrsEssential Responsibilities: Provide a wide range of Cyber Intelligence... 
    Contract work
    For contractors

    Amentum Services

    Washington DC
    4 days ago
  • $95k - $115k

     ...developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SECURITY ANALYST (DETECTION AND INCIDENT RESPONSE)As a Security Analyst at SpaceX, you are on the frontline of our information security operations. You will be responsible... 
    Permanent employment
    Temporary work
    Remote work
    Weekend work

    SpaceX

    Hawthorne, CA
    18 hours ago
  •  ...Qualifications At least 2 years of incident response experience Experience with Crowdstrike and Web Application Firewall (WAF) Proficient with at least one scripting language (Python, Java, PowerShell, Bash) Cloud experience is a plus Responsibilities Address cybersecurity... 
    Remote work
    Visa sponsorship

    Breeze End Technology, LLC

    Alexandria, VA
    4 days ago
  • $87.1k - $157.45k

     ...Description Leidos is seeking an experienced Incident Response Analyst to support the Defense Manpower Data Center (DMDC)  CyberPRIMES  program . Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting... 
    Contract work
    Work at office
    Local area
    Immediate start
    Remote work

    Leidos

    Seaside, CA
    1 day ago
  •  ...cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance... 
    Work at office

    cFocus Software Incorporated

    Washington DC
    4 days ago
  •  ...iT1, a leading technology solution provider in Tempe, AZ, is seeking a skilled Security Analyst. This role involves monitoring security tools, coordinating incident responses, and developing documentation to protect internal and customer environments. Applicants should... 

    iT1

    Tempe, AZ
    4 days ago
  • Ops Tech Alliance seeks a Cybersecurity Risk Analyst to support enterprise cyber defense in the Washington, D.C. metro area. You will...  ..., identify operational risks and process gaps, support incident-response, and translate complex cyber information into actionable recommendations... 

    OPS TECH ALLIANCE LLC

    Mc Lean, VA
    3 days ago
  • Lennar is seeking a Senior SOC Analyst in Miami, Florida, to lead incident response efforts, manage escalations, and work with security partners to detect and remediate threats effectively. The role requires 5-7 years of cybersecurity experience with expertise in incident... 

    Lennar

    Miami, FL
    4 days ago
  • Rutgers University seeks a Senior Incident Response Analyst to join the Office of Information Technology. The role oversees daily detection and response operations, provides expert investigations, and supports remediation across Rutgers' networks and devices. You will act... 
    Work at office

    Rutgers University

    New Brunswick, NJ
    4 days ago
  •  ...Position Purpose: Resolve security incidents and recommend improvements to strengthen...  ...security. Execute incident response plans and contribute to scalable preventative...  ...(GSEC), GIAC Certified Intrusion Analyst (GCIA), or GIAC Certified Incident Handler... 
    Remote work

    Macpower Digital Assets Edge

    United States
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Response Analyst. Be the first to apply!