Incident Response Analyst
Apex Systems Inc
Incident Response Analyst
An Incident Response Analyst is sought to join a co-sourced cyber operations environment. In this setting, an external managed security service provider handles primary SOC monitoring, and the internal team manages escalated investigations through to remediation. This position will provide operational coverage, investigate security events, coordinate response activities across technical teams, and strengthen vulnerability management and data loss prevention capabilities.
Key Responsibilities
- Receive escalated alerts and tickets from the SOC, initiate investigations, determine scope and impact, and manage incidents through remediation and closure.
- Investigate malware, phishing, unexpected network connections, and other security events by reviewing SIEM logs, endpoint telemetry, affected assets, and impacted users.
- Coordinate with infrastructure, application, clinical technology, privacy, and other internal teams to contain threats and execute corrective actions.
- Participate in the rotating SOC alert and on-call coverage model.
- Execute and improve established incident response runbooks and support the continued development of operational procedures.
- Use packet capture data at network egress points to trace threats and support response actions that require internal access or credentials.
- Create, tune, and maintain custom detections and response scripts within the co-sourced security model.
- Support vulnerability management operations by researching newly disclosed CVEs, identifying affected assets, validating exposure, and assisting in the prioritization of remediation.
- Account for systems that may not appear in standard vulnerability tools, such as medical and other specialized devices, when assessing exposure.
- Review DLP alerts and policies, investigate potential data exposure events, and coordinate escalation to the privacy team when events may involve PHI or patient impact.
- Document investigations, response actions, findings, and remediation activities in ServiceNow in alignment with ITIL-based processes.
Required Qualifications
- Approximately 5-10 years of relevant cybersecurity operations experience, with hands-on incident response and SOC escalation responsibility.
- Demonstrated ability to independently investigate alerts, build a complete picture from multiple data sources, and coordinate an incident through remediation.
- Experience reading and interpreting SIEM logs; Sumo Logic experience is preferred.
- Hands-on experience with CrowdStrike for endpoint investigation, threat response, exposure research, and detection or response scripting.
- A solid foundation in vulnerability management, including practical experience assessing CVEs, identifying affected assets, interpreting scanner findings, and prioritizing remediation.
- Experience with vulnerability management platforms such as Tenable Nessus and Qualys; direct Tenable experience is preferred.
- Experience investigating DLP events and understanding how DLP policies trigger; Microsoft Purview experience is preferred.
- Working knowledge of ITIL practices and experience using ServiceNow for security operations workflows and ticket management.
- Clear communication, sound judgment, and the ability to work effectively across technical and business teams during active investigations.
Preferred Qualifications
- Experience in a healthcare environment or with security events involving PHI, medical devices, or patient-impacting systems.
- Deep vulnerability management expertise and the ability to improve prioritization practices, recommend better operating approaches, and share knowledge with other team members.
- Experience working in an operational security function where workload shifts based on active incidents and emerging threats.
- Experience authoring custom detections and developing scripts that automate or accelerate threat response.
$99k - $225k
Incident Response Analyst, SeniorThe Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the United States government. In all of this “cyber noise,” how can these organizations understand...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$135k - $175k
...team and play a key role in protecting the firm's global technology environment. This position is responsible for leading security investigations, coordinating incident response activities, advancing detection capabilities, and helping strengthen the processes, technologies...SuggestedFull timeMonday to FridayAfternoon shiftEarly shift- ...security solutions provider in Texas is seeking a Cyber Security Analyst to implement security measures protecting client information... ...policy development, conduct risk assessments, and support incident responses. A Bachelor's degree or equivalent experience in Information...Suggested
- Ford Motor Company is seeking a cybersecurity specialist to support monitoring operations and incident response for connected vehicles and cloud services. You will collaborate with PSOC teams globally to ensure timely investigations and effective mitigations. The role requires...Suggested
- ...in the United States. You will be at the forefront of identifying and investigating security incidents, and contributing to the continuous improvement of our incident response capabilities. This role requires a strong technical background, participation in on-call rotations...SuggestedPermanent employmentFull timeContract workWork at officeLocal areaRemote work2 days per week
$131.3k - $237.35k
...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The Department of Homeland Security (DHS), Security Operations Center (SOC) Support...Full timeFlexible hours- ...a vital role in shaping a safer, more trustworthy AI-powered future.AI Fearlessly.Job DescriptionPosition Summary:The Sr.Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role...Full timeH1b
$132.48k - $336.96k
...Responsibilities About the Team The TikTok USDS JV Security Operations Center (SOC) is responsible... ...response efforts to enterprise-wide incidents, including post-incident root-cause analysis... ...critical security incidents. As an IR Analyst, you will belong to a team of strong...Temporary workShift work- ...been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission‑critical government program. As part of the Security Operations Center, you will...Permanent employment
$104k - $166k
...Senior Incident Response Analyst Job Locations: US Requisition ID: 2026-169782 Position Category: Cyber Security Clearance: No Clearance Required Responsibilities Position Is Contingent Upon Award Peraton Labs is hiring a Senior Incident Response Analyst to lead hands-...Contract workShift work- ...accommodation for individuals with disabilities. Posting Summary Rutgers, The State University of New Jersey, is seeking a Senior Incident Response Analyst for the Office of Information Technology. This position will report to the Associate Director. Performs daily operations...Full timeTemporary workSeasonal workWork at officeFlexible hoursShift work
- ...collaboration, and bold ideas. Are you ready to make an impact and help shape what’s next? We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This...Worldwide
$131.3k - $237.35k
...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support...Flexible hours- ...Senior Incident Response Analyst Location: Remote (USA-based, on-call support required) Employment Type: Full-time The Senior Incident Response Analyst will manage and resolve cybersecurity incidents across on-premises and cloud (AWS/Azure) environments,...Full timeRemote workShift work
- ...'ll join our Global Managed Detection & Response (MDR) team at exactly the right moment:... ...triage and anomaly detection are enabling analysts to identify genuine threats faster,... ...minutes and deliver insights that turn incidents into lasting security improvements. Every...Full timeH1bWork at officeNight shiftRotating shift3 days per week
- ...Owning the end-to-end incident response process, the full-time Senior Incident Response Analyst will manage tier-1 and tier-2 incidents, conduct forensic investigations, and automate evidence collection while working remotely. Key responsibilities Lead detection validation...Full timeRemote work
$100k - $125k
...Senior Incident Response Analyst At Zimmer Biomet, we believe in pushing the boundaries of innovation and driving our mission forward. As a global medical technology leader for nearly 100 years, a patient's mobility is enhanced by a Zimmer Biomet product or technology...Remote workFlexible hours$95.7k - $144.9k
...through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities... ...are looking for mid-level candidates with malware analysis and incident response experience. • Specific experience with triaging detections...Full timeWork at officeFlexible hoursDay shift$95.17k - $156.36k
This role sits at the intersection of hands-on incident response, cyber defense and threat mitigation. You will be part of a highly collaborative cyber defense and incident response organization, responding to and investigating high-impact security incidents.The ideal candidate...Full timeWork at officeVisa sponsorshipWork visaFlexible hours- ...Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to... ...as a variable cost.Job Description· 5 + years Cybersecurity incident response and technical forensics investigation with 3 or more years in...H1bImmediate start
- Purpose and Impact: Amentum is seeking SOC / Incident Response Analyst to support our U.S. Department of Energy contract. Positions will be based in the Washington, D.C area.Work Schedule: 5 days, 8hrsEssential Responsibilities: Provide a wide range of Cyber Intelligence...Contract workFor contractors
$95k - $115k
...developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SECURITY ANALYST (DETECTION AND INCIDENT RESPONSE)As a Security Analyst at SpaceX, you are on the frontline of our information security operations. You will be responsible...Permanent employmentTemporary workRemote workWeekend work- ...Qualifications At least 2 years of incident response experience Experience with Crowdstrike and Web Application Firewall (WAF) Proficient with at least one scripting language (Python, Java, PowerShell, Bash) Cloud experience is a plus Responsibilities Address cybersecurity...Remote workVisa sponsorship
$87.1k - $157.45k
...Description Leidos is seeking an experienced Incident Response Analyst to support the Defense Manpower Data Center (DMDC) CyberPRIMES program . Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting...Contract workWork at officeLocal areaImmediate startRemote work- ...cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance...Work at office
- ...iT1, a leading technology solution provider in Tempe, AZ, is seeking a skilled Security Analyst. This role involves monitoring security tools, coordinating incident responses, and developing documentation to protect internal and customer environments. Applicants should...
- Ops Tech Alliance seeks a Cybersecurity Risk Analyst to support enterprise cyber defense in the Washington, D.C. metro area. You will... ..., identify operational risks and process gaps, support incident-response, and translate complex cyber information into actionable recommendations...
- Lennar is seeking a Senior SOC Analyst in Miami, Florida, to lead incident response efforts, manage escalations, and work with security partners to detect and remediate threats effectively. The role requires 5-7 years of cybersecurity experience with expertise in incident...
- Rutgers University seeks a Senior Incident Response Analyst to join the Office of Information Technology. The role oversees daily detection and response operations, provides expert investigations, and supports remediation across Rutgers' networks and devices. You will act...Work at office
- ...Position Purpose: Resolve security incidents and recommend improvements to strengthen... ...security. Execute incident response plans and contribute to scalable preventative... ...(GSEC), GIAC Certified Intrusion Analyst (GCIA), or GIAC Certified Incident Handler...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Analyst. Be the first to apply!
- entry level program analyst United States
- merchandising analyst United States
- accessibility analyst United States
- hybrid analyst United States
- video analyst United States
- back office analyst United States
- operational due diligence analyst United States
- integration analyst United States
- ar analyst United States
- summer analyst internship United States

