Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Incident Response Analyst

Jobgether

Senior Incident Response Analyst

Lead end-to-end security incident response activities within a fast-paced, technology-driven environment. You will take ownership of complex incidents from initial detection through containment, recovery, and post-incident review. The role combines digital forensics, threat investigation, security operations, automation, and clear incident communication. You will investigate host, memory, network, cloud, and identity environments while protecting sensitive systems and information. Working as a hands-on individual contributor, you will exercise defined containment authority and collaborate closely with senior security professionals. You will also strengthen incident response capabilities by improving playbooks, automating repetitive work, and applying AI responsibly to security workflows. Success will be measured through faster response, stronger forensic capabilities, effective documentation, and continuous improvement of the incident response program.

Accountabilities:

  • Own Tier 1 and Tier 2 security incidents from detection validation, triage, and scoping through containment, eradication, recovery, and post-incident review.
  • Conduct independent digital forensic investigations across host and disk, memory, network, cloud, and identity environments while maintaining rigorous evidence-handling practices.
  • Investigate security events using EDR and SIEM telemetry, developing queries, correlation logic, and incident timelines from available log data.
  • Participate in the incident response on-call rotation and exercise defined containment authority, including host isolation and session revocation when appropriate.
  • Develop, update, and improve incident response playbooks based on lessons learned from real incidents.
  • Lead post-incident reviews and ensure identified findings and corrective actions are tracked through completion.
  • Automate repetitive triage and evidence-collection activities and use AI-assisted workflows to improve investigation efficiency while applying sound judgment around sensitive information.
  • Produce clear and defensible incident documentation for both technical and executive audiences, translating detailed findings into concise business-level summaries.
  • Apply threat intelligence and MITRE ATT&CK techniques to active investigations and use investigative findings to strengthen detection and response capabilities.
  • Contribute to the ongoing maturity of the incident response program, including improvements to processes, tooling, automation, and operational readiness.

Requirements:

  • 6–8 years of hands-on cybersecurity experience, with the majority focused on incident response and/or digital forensics.
  • Demonstrated ownership of the complete incident response lifecycle, from detection validation through post-incident review.
  • Hands-on digital forensics experience spanning host and disk, memory, network, cloud, and identity investigations.
  • Strong experience with EDR/EPP platforms, including endpoint telemetry investigation, response actions, and tuning detection or response capabilities.
  • Strong SIEM experience, including query development, correlation logic, and reconstruction of incident timelines from log data.
  • Practical experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK, X-Ways, plaso, Zeek, or Wireshark.
  • Strong evidence-handling discipline, including chain of custody, sound acquisition practices, and documentation suitable for legal, regulatory, and client review.
  • Working knowledge of the MITRE ATT&CK framework applied to real-world investigations.
  • Scripting and automation experience using Python, PowerShell, or similar technologies.
  • Demonstrated hands-on experience using AI tools such as Claude, ChatGPT, Copilot, or equivalent solutions in security operations, with an understanding of how to use AI effectively while protecting sensitive data.
  • Excellent technical and executive communication skills, with the ability to produce both detailed incident timelines and concise executive summaries.
  • Willingness to participate in a shared incident response on-call rotation.
  • Experience with CrowdStrike Falcon EDR, Falcon Next-Gen SIEM, or similar platforms is preferred.
  • Experience with AWS incident response, including CloudTrail, GuardDuty, IAM abuse patterns, and related cloud security investigations is preferred.
  • Experience investigating identity-related threats, particularly within Okta environments, including session hijacking, MFA fatigue, token theft, and SSO abuse.
  • Healthcare, fintech, or other regulated-industry experience involving sensitive data is advantageous.
  • Familiarity with HIPAA, HITRUST, or SOC 2 from an operational perspective, including breach determination processes, is preferred.
  • Relevant certifications such as GCFA, GCFE, GCIH, GNFA, GCIA, GREM, or equivalent demonstrated expertise are valued.
  • Experience with malware triage, reverse engineering fundamentals, SOAR platforms, AI-assisted incident response workflows, threat intelligence, or IR program maturity is beneficial.
  • Ability to work effectively in a collaborative environment while maintaining strong independent judgment and accountability.

Benefits:

  • Medical, dental, and vision insurance plans.
  • Flexible Spending Accounts and Health Savings Accounts.
  • Flexible paid time off.
  • 401(k) retirement plan with company matching.
  • Life insurance.
  • Pet insurance and additional employee benefits.
  • Opportunity to work in a relatively flat organization that encourages employees to contribute ideas and take ownership.
  • Environment built around autonomy, competence, collaboration, and belonging.
  • Opportunity to strengthen incident response capabilities and work with modern security, forensic, automation, and AI technologies.
Vacancy posted 6 hours ago
Similar jobs that could be interesting for youBased on the Senior Incident Response Analyst in United States vacancy
  • $135k - $175k

     ...global technology environment. This position is responsible for leading security investigations, coordinating incident response activities, advancing detection capabilities...  ...and response capabilities.Serve as a senior escalation point for complex and high-priority security... 
    Senior
    Full time
    Monday to Friday
    Afternoon shift
    Early shift

    Hogan Lovells

    Denver, CO
    5 days ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services... 
    Senior
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    2 days ago
  • $99k - $225k

    Incident Response Analyst, SeniorThe Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the United States government. In all of this “cyber noise,” how can these organizations understand... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    2 days ago
  • $100k - $125k

     ...inspired, invested, cared for, valued, and have a strong sense of belonging. What You Can Expect We're seeking a Senior Incident Response Analyst to join our cybersecurity incident response team. This is a hands-on technical role responsible for investigating and... 
    Senior
    Remote work
    Flexible hours

    Zimmer Biomet

    United States
    5 days ago
  •  ...has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission‑critical government program. As part of the Security Operations Center, you will... 
    Senior
    Permanent employment

    Tetrad Digital Integrity

    Arlington, VA
    3 days ago
  •  ...Senior Incident Response Analyst Location: Remote (USA-based, on-call support required) Employment Type: Full-time The Senior Incident Response Analyst will manage and resolve cybersecurity incidents across on-premises and cloud (AWS/Azure) environments... 
    Senior
    Full time
    Remote work
    Shift work

    Veracity

    United States
    3 days ago
  •  ...collaboration, and bold ideas. Are you ready to make an impact and help shape what’s next? We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This... 
    Senior
    Worldwide

    Dun & Bradstreet

    Center Valley, PA
    1 day ago
  • $104k - $166k

     ...Senior Incident Response Analyst Job Locations: US Requisition ID: 2026-169782 Position Category: Cyber Security Clearance: No Clearance Required Responsibilities Position Is Contingent Upon Award Peraton Labs is hiring a Senior Incident Response Analyst to lead hands... 
    Senior
    Contract work
    Shift work

    Peraton

    Herndon, VA
    3 days ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services... 
    Senior
    Flexible hours

    Leidos

    Arlington, VA
    4 days ago
  •  ...accommodation for individuals with disabilities. Posting Summary Rutgers, The State University of New Jersey, is seeking a Senior Incident Response Analyst for the Office of Information Technology. This position will report to the Associate Director. Performs daily... 
    Senior
    Full time
    Temporary work
    Seasonal work
    Work at office
    Flexible hours
    Shift work

    Rutgers University

    Brooklyn, NY
    1 day ago
  •  ...experienced CSIRT Investigator to join our security team in the United States. You will identify and investigate security incidents, contribute to incident response enhancements, and participate in on-call rotations as part of an individual contributor role reporting to the Sr.... 
    Senior

    DocuSign

    San Francisco, CA
    6 days ago
  • Sysco is seeking a Security Operations Center Analyst III to join our Vulnerability and Threat Management program. You’ll analyze...  ...involves event correlation, escalation to the SOC, and developing incident response playbooks. Candidates should have extensive incident response... 
    Senior

    FHLB Des Moines

    Brooklyn, NY
    5 days ago
  • Lennar is seeking a Senior SOC Analyst in Miami, Florida, to lead incident response efforts, manage escalations, and work with security partners to detect and remediate threats effectively. The role requires 5-7 years of cybersecurity experience with expertise in incident... 
    Senior

    Lennar

    Miami, FL
    5 days ago
  • $132.48k - $336.96k

     ...Responsibilities About the Team The TikTok USDS JV Security Operations Center (SOC) is responsible...  ...response efforts to enterprise-wide incidents, including post-incident root-cause analysis...  ...critical security incidents. As an IR Analyst, you will belong to a team of strong... 
    Senior
    Temporary work
    Shift work

    TikTok USDS Joint Venture

    Washington DC
    1 day ago
  •  ...a leader in autonomous maritime security, seeks a Senior SecOps Analyst to drive detection and response across endpoint, cloud, and identity domains. You will...  ...join an on-call rotation and contribute to post-incident reviews, with room to grow across security domains... 
    Senior

    Saronic

    Austin, TX
    3 days ago
  • A leading logistics company in Austin is seeking a Senior Security Operations Center Analyst to enhance their security posture. Responsibilities include conducting threat hunting, responding to security incidents, and collaborating with IT teams to improve security strategies... 
    Senior

    Ryder

    Austin, TX
    4 days ago
  • Resource Management Concepts, Inc. (RMC) is seeking a Tier 3 Incident Response Senior Analyst to support an active government contract in Quantico, Virginia. You will conduct advanced cyber defense activities, DFIR, and incident management across the enterprise network... 
    Senior
    Contract work

    Resource Management Concepts

    Quantico, VA
    5 days ago
  • Rutgers University seeks a Senior Incident Response Analyst to join the Office of Information Technology. The role oversees daily detection and response operations, provides expert investigations, and supports remediation across Rutgers' networks and devices. You will... 
    Senior
    Work at office

    Rutgers University

    New Brunswick, NJ
    5 days ago
  •  ...Senior Incident Response Analyst Rutgers, The State University of New Jersey, is seeking a Senior Incident Response Analyst for the Office of Information Technology. This position will report to the Associate Director. Among the key duties of this position are the... 
    Senior
    Full time
    Temporary work
    Seasonal work
    Work at office
    Flexible hours
    Shift work

    Rutgers University-New Brunswick

    Piscataway, NJ
    3 days ago
  • $108.15k - $165.47k

    Rutgers University is hiring a Senior Incident Response Analyst. The analyst runs daily incident detection and response operations for Rutgers' Office of Information Technology, hunting for threats and escalating complex security incidents across the university's networks... 
    Senior
    Work at office

    Rutgers University

    Piscataway, NJ
    5 days ago
  • The Role This senior-level position supports a government CSSP contract...  ...conducting end-to-end cyber incident management from initial...  ...delivery of an internal Incident Response training course. Skills &...  ...investigations, guide junior analysts, and contribute to training development... 
    Senior
    Contract work

    Forensic Focus Limited

    Virginia, IL
    6 days ago
  • cFocus Software seeks an Incident Response Analyst (Tier 2) to join our program supporting the AOUSC. This role is Hybrid with onsite in Washington, DC, and requires a Public Trust clearance. You will perform in-depth IR activities, analyze security incidents, and coordinate... 
    Senior

    cFocus Software Incorporated

    Washington DC
    5 days ago
  •  ...Cortek, Inc. is seeking a Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency engagements...  ...enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret... 
    Senior
    Work at office

    CORTEK Inc

    Washington DC
    5 days ago
  • Lead incident response activities through triage, investigation, containment, remediation, recovery, and post-incident analysis Investigate...  ...logic, alerting, playbooks, workflows, and automation Serve as a senior escalation point for complex and high-priority security... 
    Senior
    Afternoon shift
    Early shift

    Jobtailor

    Denver, CO
    4 days ago
  • Senior J-9 Hac Incident Response Analyst Location: Fort Meade, MD 20755 Clearance Level: Active Secret Clearance Job Type: Full-Time Citizenship: Must be U.S. Citizen Job Overview PD Inc International is seeking an experienced and mission‑driven Senior J-9 Hac Incident... 
    Senior
    Full time
    Work experience placement
    Casual work
    Work at office

    PD Inc

    Annapolis, MD
    3 days ago
  • $135k - $150k

    RMC is hiring a Tier 3 Incident Response Senior Analyst to support an active government contract in Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government’s mission to... 
    Senior
    Full time
    Contract work
    Work experience placement
    Relocation package
    Monday to Friday
    Shift work
    Day shift

    Resource Management Concepts

    Quantico, VA
    5 days ago
  • Docusign is seeking a senior CSIRT Investigator to join our security team in the United States. You will identify and investigate security incidents, triage alerts, and contribute to incident response improvements across the organization. This individual contributor role... 
    Senior

    DocuSign

    San Francisco, CA
    5 days ago
  • $100k - $125k

    A cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA. This role involves serving as a subject matter expert in incident response, requiring strong analytical skills and an active TS/SCI clearance. Candidates should have over 8 years... 
    Senior

    Argo Cyber Systems

    Arlington, VA
    6 days ago
  • $131.3k - $237.35k

    Leidos Inc is seeking a Senior Incident Response Analyst to join their team in Arlington, Virginia. The role involves coordinating incident response efforts, analyzing cyber threats, and developing security protocols for the Department of Homeland Security's CISA Program... 
    Senior

    Leidos

    Arlington, VA
    5 days ago
  • First Citizens Bank is seeking a Senior Incident Response Analyst to join the Cyber Incident Response team on a remote basis. The role requires hands-on expertise in detecting and responding to threats, coordinating with stakeholders, and mentoring colleagues. Strong communication... 
    Senior
    Remote job

    First Citizens Bank

    Raleigh, NC
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Incident Response Analyst. Be the first to apply!