Incident Response Analyst
$127k - $140kdeepwatch
Overview Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry. If you're ready to challenge yourself with work that matters, then this is the place for you. We're redefining cybersecurity as one of the fastest growing companies in the U.S. – and we have a blast doing it! Who We Are Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business. Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit. Deepwatch recognition includes: 2025, 2024, 2023, 2022 and 2021 Great Place to Work® Certified 2024 Military Times Best for Vets Employers 2024 US Department of Labor Hire Vets Gold Award 2024 Forbes' America's Best Startup Employers 2024 Cyber Defense Magazine, Global Infosec Awards 2023 and 2022 Fortress Cybersecurity Award 2023 $180M Series C investment from Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners of Vista Equity Partners 2022 Cybersecurity Excellence Award for MDR Location Hybrid, Tampa, FL / Remote Note on location While proximity to Tampa is preferred to support a hybrid schedule in our Tampa Center of Excellence, we’re open to remote candidates who can support the Eastern Time Zone. Responsibilities Reporting to the Manager of Adversary Response, the Incident Response Analyst operates on the front lines of active cyber conflict—defending organizations against sophisticated, real-world adversaries. This is a mission-critical role for practitioners who thrive in high-pressure environments and are driven to outpace, outthink, and disrupt advanced threat actors. As a primary responder during live incident engagements, you will lead hands-on investigations into complex intrusions, leveraging advanced EDR and detection platforms to trace attacker behavior, contain threats in real time, and eradicate adversary presence at its source. In this role, you’ll get to: Lead end-to-end incident response engagements within customer environments, driving rapid investigation, containment, and remediation of active threats Conduct deep-dive forensic and malware analysis to uncover adversary tactics, techniques, and procedures (TTPs), translating findings into actionable intelligence Proactively hunt for advanced threats through hypothesis-driven threat hunting across diverse data sources and telemetry Triage and validate suspicious activity using a combination of OSINT, proprietary intelligence, and behavioral analysis Own the documentation of incidents, ensuring clear, defensible reporting and timeline reconstruction within case management systems Identify and operationalize new adversary techniques, tools, and tradecraft—scaling knowledge across the team to strengthen collective defense Maintain a constant pulse on the evolving threat landscape, applying emerging intelligence to real-world investigations Surface visibility gaps in logging, telemetry, and detection coverage, and partner with stakeholders to enhance overall security posture Collaborate cross-functionally to develop and refine detection content, response playbooks, and threat intelligence outputs Serve as a trusted advisor to customers, confidently guiding them through the full incident response lifecycle—from initial compromise to full remediation and recovery Qualifications To be successful in this role, you will bring: Proven, hands-on experience leading incident response investigations, with the ability to independently scope, analyze, and drive complex engagements to resolution A track record of operating in high-volume, high-complexity environments (e.g., MDR, MSSP, consulting, or enterprise IR teams), with exposure to a wide range of real-world incidents and adversary scenarios Deep expertise with Endpoint Detection & Response (EDR) platforms such as SentinelOne, Microsoft Defender, and CrowdStrike, including advanced querying, triage, and response actions Strong command of incident response methodologies and frameworks (e.g., NIST, PICERL), with the ability to apply them dynamically in fast-moving, ambiguous situations Experience leveraging SIEM, SOAR, case management, and threat intelligence platforms to investigate, correlate, and respond to threats at scale A solid understanding of attacker methodologies, including common and emerging tactics, techniques, and procedures (TTPs), with the ability to map activity to frameworks such as MITRE ATT&CK Exceptional communication skills, with experience presenting technical findings and strategic recommendations to both technical teams and executive stakeholders The ability to operate as a trusted advisor during high-pressure incidents—bringing clarity, structure, and confidence to customer engagements Note This role is best suited for practitioners who have been deeply immersed in live incident response environments and have built pattern recognition across numerous engagements. Candidates with limited exposure to real-world incidents may find the pace, ambiguity, and complexity of this role challenging. Additional Compliance & Benefits Statutory Pay Disclosure The anticipated salary range for this role is $127,00 - $140,000 + stock options + benefits. Actual compensation may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level. ITAR Compliance This position will have access to customer data and as such is subject to International Traffic in Arms Regulations (ITAR). Upon application, candidates will be asked to confirm that they are a U.S. Person as defined by the following: A citizen of the U.S.; A lawful permanent resident of the United States; A person admitted to the United States as a refugee; or A person that has been granted asylum by the United States government. The intent of this requirement is not to verify employment eligibility overall, but to ensure compliance with import/export regulations. If you do not meet these requirements, we encourage you to apply for other open roles at Deepwatch. This information will be verified upon offer of employment. What We Offer Deepwatch is excited to provide benefits designed to support team members and their families. Including: Medical, dental, vision, and disability insurance Flexible Time Off (FTO), 12 company holidays, sick leave and 8-Weeks Paid Parental Leave Unique professional development benefits with Annual “development dollars” to support our people growth and development Wellness contests and monthly educational programs 401(K) retirement program Learn more here: Deepwatch Benefits EEO & Privacy We know theconfidence gapandimposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you. Please review our DEI Statement here. Deepwatch welcomes and encourages applications from people with disabilities and accommodations are available on request for candidates taking part in all aspects of the selection process. Please inform your recruiter or View email address on click.appcast.io for further information. All Deepwatch employees are expected to: Be interested in and able to work remotely from a home office when not at a corporate office Pass a pre-employment background check in accordance with applicable laws Deepwatch is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, marital status, sexual orientation, gender identity, genetic information, protected veteran status, or any other characteristic protected by law. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire. By submitting your application, you agree that Deepwatch may collect your personal data for recruiting, global organization planning, and related purposes. The Deepwatch Privacy Policy explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over Deepwatch’s use of your personal information. #J-18808-Ljbffr
$120k - $145k
...Corporation is looking for an experienced Information Security Analyst (SME) to join their team in Washington, DC. The ideal... ...Degree and over 4 years of experience in security analysis and incident response. Responsibilities include maintaining threat awareness, developing...Suggested- ...A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience...SuggestedRemote work
- ...Global Solutions in Washington, DC is seeking a Senior Security Operations Analyst to monitor and respond to cybersecurity threats. The candidate will analyze security events, manage incident response, and support the National Indian Gaming Commission's cybersecurity...Suggested
$131.3k - $237.35k
...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support...SuggestedFlexible hours$100k - $125k
...A cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA. This role involves serving as a subject matter expert in incident response, requiring strong analytical skills and an active TS/SCI clearance. Candidates should have over 8...Suggested- ...Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations and helps deliver mission-focused outcomes...Contract workShift workNight shift
- ...rotational weekend and holiday workdays. Responsibilities Provide on-site CSSP/IR support to a... .... Providing detailed triage of CSSP/IR incidents including implementing intrusion detection... ...resume). CYBERSECURITY SERVICE PROVIDER/INCIDENT RESPONSE ANALYST #J-18808-Ljbffr...Work at officeMonday to FridayWeekend work
- ...Nightwing Group is seeking a Business Analyst to support onsite incident response for U.S. Government agencies experiencing cyber-attacks. The role involves gathering requirements, stakeholder coordination, and ensuring technology integration aligns with operational priorities...
- ...Cayuse Holdings is seeking an ITSM Incident Response Analyst to support and respond to incidents while collaborating with the Service Desk and Desktop support teams. This remote position emphasizes adherence to ITIL-aligned processes, ensuring effective incident management...Contract workRemote work
- ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public Trust (or eligibility to obtain) We are seeking an experienced Incident Response Analyst...Full timeContract workRemote workMonday to Friday
- ...Tyto Athene is searching for a Tier 2 Incident Response Analyst (IR) to support a law enforcement customer in Washington, DC. Our IR analysts form the backbone of our cybersecurity services. You will play a critical role in securing our customers by monitoring our tools...Part timeShift workNight shiftWeekend workDay shift2 days per week
- ...A cybersecurity firm is looking for a Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor security tools, triage alerts, and investigate cyber threats. Ideal candidates have six years in cybersecurity, preferably three in SOC...
$30 - $48 per hour
...Overview Job Title: ITSM Incident Response Analyst Location: Remote Type: Independent Contract - Corp to Corp/1099 Start Date: ASAP Pay Rate: $30-48/hr (Independent Contract) Contract Length: through August 31 Responsibilities Serve as...Contract workFor contractorsWork experience placementLocal areaImmediate startRemote work- ...A cybersecurity firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site support for DoD customers, possessing technical skills in intrusion detection and prevention, and will have a...
- ...Ernst & Young Oman is looking for a Cyber Triage and Forensics (CTF) Incident Analyst to be a senior member of the technical team handling security incidents. Responsibilities include performing digital forensic analysis, responding to security incidents, and developing...Flexible hours
- ...Qualifications At least 2 years of incident response experience Experience with Crowdstrike and Web Application Firewall (WAF) Proficient with at least one scripting language (Python, Java, PowerShell, Bash) Cloud experience is a plus Responsibilities Address cybersecurity...Remote workVisa sponsorship
- ...Rividium Inc is looking for an Incident Response Analyst to join the MODES III team in Alexandria, Virginia. The role involves supporting IT, Cybersecurity, and Data Operations to achieve mission-focused outcomes for military personnel and their families. Key responsibilities...Shift work
- ...Full-Time/Part-Time Full-Time Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations...Full timeContract workPart timeShift workNight shift
- Leidos is seeking a Mid‑Level Cyber Security Analyst to provide comprehensive cyber security services. This full-time position in Baltimore, MD, includes responsibilities such as incident response, malicious activity hunting, and threat analysis. Candidates should have...Full time
$131.3k - $237.35k
...better-informed decisions using trusted data at scale. Leidos Digital Modernization sector is seeking an experienced SME Incident Response Analyst to support the delivery, enhancement, and adoption of enterprise data and analytics products used across multiple DoD organizations...- ...Business Computers Management Consulting Group Llc is looking for Cyber Eviction Analysts to support critical customer missions in incident response and proactive cyber security measures. Ideal candidates will have extensive experience in threat analysis, incident response...
- ...Eliassen Group is seeking a SOC Analyst to join their team in Washington, DC. This role... ...continuous monitoring, detection, analysis, and response to cybersecurity events across hybrid... ...experience with security monitoring and incident response, proficiency with SIEM tools...Remote work
$131.3k - $237.35k
Leidos is seeking a Senior Incident Response Analyst in Bethesda, Maryland to support the DHS CISA Program. The role involves coordinating incident investigations, analyzing cyber incidents, and developing response procedures. A bachelor's degree in Computer Science or...- ...firm in Virginia is seeking a Host Forensics Analyst to support critical missions related to cybersecurity incidents. The position requires at least 8 years of relevant... ...and an active TS/SCI clearance. Responsibilities include leading forensic teams, providing technical...
$80.2k - $111.3k
...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts for enterprise networks... ...technical and procedural coaching to incident handlers and SOC analysts, elevating investigative techniques, documentation quality,...Contract workWork experience placementWork at office- ...supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners... ...Indicators of Compromise (IOCs), escalating to specialized analysts Required Skills: - Must have an active TS/SCI clearance -...Contract workImmediate startShift work
- ...is supporting a U.S. Government customer to provide onsite incident response to civilian Government agencies and critical asset owners who... ...Indicators of Compromise (IOCs), escalating to specialized analysts Required Skills U.S. Citizenship Must have an active TS/SCI...Contract workImmediate startShift workNight shiftWeekend work
- ...A leading cybersecurity firm is seeking a Network Forensics Analyst to support critical incident response missions. Candidates must have 8+ years of experience in network investigations, preferably with an active TS/SCI clearance. The role involves coordinating teams,...
$83.5k - $87.5k
...Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client’s cybersecurity framework by serving as the primary entry point for all external communications regarding cybersecurity incidents and related information requests. Operating within the...Temporary workWork at officeLocal areaFlexible hoursShift work- ...Njvc LLC is looking for a Security Operations Center Analyst in Arlington, Virginia. The role involves monitoring devices, performing incident management, and using various security tools to analyze network events. Candidates must have a Bachelor's degree or equivalent...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Analyst. Be the first to apply!
- entry level analyst Washington DC
- cash analyst Washington DC
- workforce analyst Washington DC
- sales and trading analyst Washington DC
- remote epic analyst Washington DC
- packaging analyst Washington DC
- intellectual property analyst Washington DC
- senior foia analyst Washington DC
- senior database analyst Washington DC
- strategic sourcing analyst Washington DC

