Incident Response Analyst
$127k - $140kDeepwatch
Overview Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry. If you're ready to challenge yourself with work that matters, then this is the place for you. We're redefining cybersecurity as one of the fastest growing companies in the U.S. – and we have a blast doing it! Who We Are Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business. Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit. Deepwatch recognition includes: 2025, 2024, 2023, 2022 and 2021 Great Place to Work® Certified 2024 Military Times Best for Vets Employers 2024 US Department of Labor Hire Vets Gold Award 2024 Forbes' America's Best Startup Employers 2024 Cyber Defense Magazine, Global Infosec Awards 2023 and 2022 Fortress Cybersecurity Award 2023 $180M Series C investment from Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners of Vista Equity Partners 2022 Cybersecurity Excellence Award for MDR Location Hybrid, Tampa, FL / Remote Note on location While proximity to Tampa is preferred to support a hybrid schedule in our Tampa Center of Excellence, we’re open to remote candidates who can support the Eastern Time Zone. Responsibilities Reporting to the Manager of Adversary Response, the Incident Response Analyst operates on the front lines of active cyber conflict—defending organizations against sophisticated, real-world adversaries. This is a mission-critical role for practitioners who thrive in high-pressure environments and are driven to outpace, outthink, and disrupt advanced threat actors. As a primary responder during live incident engagements, you will lead hands-on investigations into complex intrusions, leveraging advanced EDR and detection platforms to trace attacker behavior, contain threats in real time, and eradicate adversary presence at its source. In this role, you’ll get to: Lead end-to-end incident response engagements within customer environments, driving rapid investigation, containment, and remediation of active threats Conduct deep-dive forensic and malware analysis to uncover adversary tactics, techniques, and procedures (TTPs), translating findings into actionable intelligence Proactively hunt for advanced threats through hypothesis-driven threat hunting across diverse data sources and telemetry Triage and validate suspicious activity using a combination of OSINT, proprietary intelligence, and behavioral analysis Own the documentation of incidents, ensuring clear, defensible reporting and timeline reconstruction within case management systems Identify and operationalize new adversary techniques, tools, and tradecraft—scaling knowledge across the team to strengthen collective defense Maintain a constant pulse on the evolving threat landscape, applying emerging intelligence to real-world investigations Surface visibility gaps in logging, telemetry, and detection coverage, and partner with stakeholders to enhance overall security posture Collaborate cross-functionally to develop and refine detection content, response playbooks, and threat intelligence outputs Serve as a trusted advisor to customers, confidently guiding them through the full incident response lifecycle—from initial compromise to full remediation and recovery Qualifications To be successful in this role, you will bring: Proven, hands-on experience leading incident response investigations, with the ability to independently scope, analyze, and drive complex engagements to resolution A track record of operating in high-volume, high-complexity environments (e.g., MDR, MSSP, consulting, or enterprise IR teams), with exposure to a wide range of real-world incidents and adversary scenarios Deep expertise with Endpoint Detection & Response (EDR) platforms such as SentinelOne, Microsoft Defender, and CrowdStrike, including advanced querying, triage, and response actions Strong command of incident response methodologies and frameworks (e.g., NIST, PICERL), with the ability to apply them dynamically in fast-moving, ambiguous situations Experience leveraging SIEM, SOAR, case management, and threat intelligence platforms to investigate, correlate, and respond to threats at scale A solid understanding of attacker methodologies, including common and emerging tactics, techniques, and procedures (TTPs), with the ability to map activity to frameworks such as MITRE ATT&CK Exceptional communication skills, with experience presenting technical findings and strategic recommendations to both technical teams and executive stakeholders The ability to operate as a trusted advisor during high-pressure incidents—bringing clarity, structure, and confidence to customer engagements Note This role is best suited for practitioners who have been deeply immersed in live incident response environments and have built pattern recognition across numerous engagements. Candidates with limited exposure to real-world incidents may find the pace, ambiguity, and complexity of this role challenging. Additional Compliance & Benefits Statutory Pay Disclosure The anticipated salary range for this role is $127,00 - $140,000 + stock options + benefits. Actual compensation may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level. ITAR Compliance This position will have access to customer data and as such is subject to International Traffic in Arms Regulations (ITAR). Upon application, candidates will be asked to confirm that they are a U.S. Person as defined by the following: A citizen of the U.S.; A lawful permanent resident of the United States; A person admitted to the United States as a refugee; or A person that has been granted asylum by the United States government. The intent of this requirement is not to verify employment eligibility overall, but to ensure compliance with import/export regulations. If you do not meet these requirements, we encourage you to apply for other open roles at Deepwatch. This information will be verified upon offer of employment. What We Offer Deepwatch is excited to provide benefits designed to support team members and their families. Including: Medical, dental, vision, and disability insurance Flexible Time Off (FTO), 12 company holidays, sick leave and 8-Weeks Paid Parental Leave Unique professional development benefits with Annual “development dollars” to support our people growth and development Wellness contests and monthly educational programs 401(K) retirement program Learn more here: Deepwatch Benefits EEO & Privacy We know theconfidence gapandimposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you. Please review our DEI Statement here. Deepwatch welcomes and encourages applications from people with disabilities and accommodations are available on request for candidates taking part in all aspects of the selection process. Please inform your recruiter or View email address on click.appcast.io for further information. All Deepwatch employees are expected to: Be interested in and able to work remotely from a home office when not at a corporate office Pass a pre-employment background check in accordance with applicable laws Deepwatch is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, marital status, sexual orientation, gender identity, genetic information, protected veteran status, or any other characteristic protected by law. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire. By submitting your application, you agree that Deepwatch may collect your personal data for recruiting, global organization planning, and related purposes. The Deepwatch Privacy Policy explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over Deepwatch’s use of your personal information. #J-18808-Ljbffr Deepwatch
- Cayuse Holdings is looking for an ITSM Incident Response Analyst to support and manage incident responses effectively within their IT teams. You will oversee incident documentation and ensure alignment with ITIL processes for consistent service management. The ideal candidate...SuggestedRemote jobContract work
- Alignerr is looking for an Incident Response Analyst to work on AI-driven security analysis within a remote and flexible environment. You will have the opportunity to shape how AI systems understand and respond to modern security threats based on your hands-on experience...SuggestedRemote jobContract workFlexible hours
- Incident Response Analyst (AI Training) About The Role We’re partnering with leading AI research labs to build the next generation of security-focused AI systems — and we need real incident responders to make it happen. Your hands‑on experience in SOC environments, alert...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
$24 - $27 per hour
Job Description Responsible for the initial analysis, and classification of customer cases, as well as following troubleshooting documentation... ...through tactical troubleshooting, monitoring, and proactive incident resolution for Flexential's customer environments. A strong...SuggestedHourly payTemporary workRemote workMonday to FridayFlexible hoursShift workDay shift$127k - $140k
Deepwatch is looking for an Incident Response Analyst located in the United States, Colorado. This mission-critical role requires a candidate proficient in leading incident response investigations and operating in high-pressure environments to defend organizations against...SuggestedRemote job- ManpowerGroup is seeking an Information Security Analyst in Denver, Colorado. This vital role in the Security Operations Center (SOC... ..., along with at least 2 years of experience in cybersecurity incident response. This position offers a competitive pay rate and...
$85k - $95k
Leprino Foods in Denver is seeking an IT Security Analyst to enhance security for their global dairy operations. This role... ...core security platforms while investigating security incidents and coordinating responses. Qualifications include a bachelor's degree in a relevant...$80 - $90 per hour
Apex Systems is seeking a SOC Analyst in Denver, Colorado. The candidate will be responsible for monitoring, analyzing, and responding to security events, requiring a solid understanding of security tools and experience with SEIM platforms. The ideal applicant should have...Remote jobHourly payContract work$90k - $105k
...SupportFinity™ in Colorado is seeking an experienced Security Analyst to enhance its information security program. You will collaborate with the IT team to detect and respond to security incidents and play a crucial role in implementing security operations. The ideal...$24 - $27 per hour
...to ensure superior customer experience through effective troubleshooting and documentation. You will handle customer requests and incidents, working closely with the Level 2 support team to stay updated on technology trends. The ideal candidate will have at least 1-3 years...Hourly pay$60 - $65 per hour
ManpowerGroup Global, Inc. is looking for an Information Security Analyst in Denver, Colorado. As part of the Security Operations Center, you will monitor security events, perform incident triage, and ensure the security of digital assets. The ideal candidate should possess...Hourly pay$84.63k - $112.84k
...ready connectivity, join us today. The Role Cybersecurity Incident Response Team (CIRT) Engineers at Lumen are on the front lines of... ...Responsibilities Shift hours are from 10:00am to 7:00pm Pacific Time. Analyst can be located in any US state. Respond to, remediate, and...Full timeTemporary workRemote workShift work- Vertilocity, located in Englewood, CO, is looking for a Security Analyst to help protect our client's systems and data from cyber... ...candidate will have a strong background in IT consulting and will be responsible for monitoring systems, investigating violations, and...Flexible hours
$66.9k - $82.1k
...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across enterprise networks and mission-critical systems in a highly regulated government environment. This role contributes...Contract workWork experience placementWork at office$55.7k - $82.1k
...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity... ...incidents, and escalates significant events to senior analysts or incident responders as appropriate. The analyst supports...Contract workWork at officeShift work$28 - $30 per hour
Flexential is seeking an IT Specialist located in Aurora, Colorado. This position involves troubleshooting and providing support for customer issues across various platforms. The ideal candidate will possess strong communication and customer service skills, with a keen ...Hourly payFlexible hours$100k - $115k
...member of the Information Services Department, the Senior Analyst, Cybersecurity Operations & Response supports the execution and continuous improvement of... ...responsible for assisting with security operations, incident response activities, and threat and vulnerability management...Full timeContract workWork at office- Cytel is looking for a Cyber Security Analyst in Denver, Colorado, to enhance its information security operations. This role encompasses... ...position requires strong analytical skills for investigating incidents, vulnerability management, and working with various security tools...
- ...Operations Center (SOC) Information Security Analyst to join our team. This position will... ...audiences. Roles and Responsibilities The SOC Analyst will respond to security... ...through SIEM platforms, as well as incidents reported through the organization's ticketing...
$60 - $65 per hour
...and detail-oriented Information Security Analyst to join their dynamic team. As an... ...within the SOC using Security Event and Incident Management (SEIM) platforms. Perform cyber... ...identify threats on the network. Document response procedures and contribute to the development...Hourly payWeekly payTemporary workFlexible hours$37.44 - $46.8 per hour
...innovation workspaces**PRIMARY DUTIES & RESPONSIBILITIES****Salary to be commensurate with... ...of Position/Department:**The Security Analyst will work within the ISO Engagement team... ...compliance.* Assist in emergency response and incident investigations.* Support development of...Hourly payWork at officeLocal areaHome office$37.44 - $46.8 per hour
...of Position / Department The Security Analyst will work within the ISO Engagement team... ...data governance program. Primary Duties & Responsibilities Evaluate and consult on security and... ...compliance. Assist in emergency response and incident investigations. Support development of...Hourly payWork at officeHome office$57.78k
...of America Colorado employs an ANS QA Analyst to safeguard grant compliance, elevate... ...Intervention, and Motivational Interviewing. Responsibilities Plan, organize, and conduct Strategic... ...monitoring. Review complaints and incident reports and implement corrective actions...Full timeContract workPart timeWork at officeLocal areaFlexible hours$60 - $65 per hour
...and detail-oriented Information Security Analyst to join their dynamic team. As an... ...within the SOC using Security Event and Incident Management (SEIM) platforms. Perform cyber... ...identify threats on the network. Document response procedures and contribute to the development...Hourly payWeekly payTemporary workFlexible hours$90k
...Role Title: Business Analyst – Network Operations & Intake Management Work Setup: Hybrid... ...efficiency and service delivery. Responsibilities Review, analyze, and evaluate information... ...prioritize, and assign incoming requests and incidents to appropriate network engineering...Contract workWork at officeFlexible hours- ...ensure the continuous execution of our organizational missions and to adequately protect our systems and data. A key responsibility is leading incident response and related initiatives with a focus on preparation and prevention. This individual is not only expected to...Full timeRemote workMonday to FridayWeekend workAfternoon shift
$90k - $100k
...Overview GovCIO is currently hiring for an Operations Research Analyst / Data Scientist to support database development, data... ...Immigration and Customs Enforcement (ICE). This role will be responsible for working within an interconnected reporting and analytics team...Full timeWork experience placementCurrently hiringRemote workFlexible hours$90k - $105k
...SAP Business Analyst - MM/PP/WM Make an Impact with Healthcare Technology Jobs That Matter... ...experience with SAP MM/PP/WM modules. Responsibilities Responsibility for the design,... ...PP/WM/QM and Ariba solutions, including incident and change management Support Logistics...$73.78k
...The Identify Access Management (IAM) Analyst supports the day-to-day operations and process... ...Management (IAM) functions, including Incident, Requests, and Change Management... ...internal end users. Essential Duties and Responsibilities Perform operational activities for Incident...Work at office$66.6k - $103.3k
...Description Join a team dedicated to minimizing the impact of major incidents across the organization. The MIM team leads efforts to... ...groups, and drive continuous improvement in our processes. Responsibilities Develop, edit, and distribute effective internal and...Work experience placementWork at officeLocal areaFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Analyst. Be the first to apply!
- construction analyst Denver, CO
- paid search analyst Denver, CO
- remediation analyst Denver, CO
- entry level program analyst Denver, CO
- noc analyst Denver, CO
- accessibility analyst Denver, CO
- health analyst Denver, CO
- law enforcement response team analyst Denver, CO
- utilities analyst Denver, CO
- internal audit analyst Denver, CO


