Incident Response Analyst
BetterCloud
About AlphaSense: The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision‑making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content. The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI‑driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us! About the Role: We are hiring a Staff Incident Response Analyst to serve as the technical escalation point for our L2 SOC analysts and 24/7 managed detection and response (MDR) partner. When a case exceeds what an L2 can handle — complex forensics, multi‑system intrusions, ambiguous attacker behavior, or high‑stakes containment decisions — it lands with you. You are the last line of technical defense before the Security Operations Manager is pulled in. This is a deeply hands‑on role. You will spend the majority of your time in tooling: hunting through the SIEM, pulling host artifacts via EDR remote access, tracing IAM chains in cloud audit logs, and reconstructing attacker timelines from raw evidence. You are expected to know what you are looking at without being told, and to be faster and more thorough than the analysts escalating to you. Core Responsibilities: Escalation Handling & Incident Leadership Receive and own L2 escalations across all severity levels; take over technical lead role on Sev2+ Scope incidents accurately and quickly: determine blast radius, affected assets, and attacker objectives from available telemetry Make and document containment decisions — endpoint isolation, account suspension, token revocation, network block — with clear rationale Maintain a forensically sound incident timeline: ordered evidence, source attribution, and chain‑of‑custody throughout Communicate incident status to the Security Operations Manager with enough fidelity to brief upward without needing to re‑investigate Drive incidents to documented closure: root cause, attacker path, affected assets, and defensive gaps identified Host & Endpoint Forensics Perform deep‑draw endpoint triage via EDR: process tree analysis, remote artifact collection, behavioral event review, and custom detection rule evaluation Reconstruct attacker activity from Windows forensic artifacts: Prefetch, Shimcache, Amcache, MFT, $USNJrnl, event logs (4624, 4688, 4698, 7045), and registry hives Analyze Linux host artifacts: bash history, cron jobs, /tmp and /var/log contents, SUID binaries, and persistence mechanisms Perform memory forensics when warranted: process injection, credential extraction artifacts, and in‑memory malware indicators Extract and analyze malware samples statically and dynamically: PE header review, strings, YARA matching, and sandbox detonation interpretation Cloud Incident Response — AWS & GCP Lead AWS‑based IR: CloudTrail forensics, IAM chain reconstruction, EC2 isolation, S3 access pattern analysis, Lambda execution review Identify and respond to IMDS credential abuse, assumed‑role lateral movement, and cross‑account privilege escalation Investigate container and serverless incidents: ECS task behavior, Lambda invocation logs, and abnormal API call sequences Correlate VPC Flow Logs, native threat detection findings, and S3 access logs against SIEM events to build a complete cloud‑side timeline Handle GCP incidents using Cloud Audit Logs, Cloud Logging, and IAM policy review in a multi‑cloud context Use cloud security posture management (CSPM) findings and runtime data as investigative context during active incidents Identity & SaaS Forensics Investigate identity provider incidents: admin audit log review, session anomaly analysis, suspicious app assignments, MFA bypass patterns, and provisioning events Perform customer identity and access management (CIAM) forensics: authentication log analysis, abnormal grant flows, token misuse, and tenant‑level anomaly investigation Reconstruct identity‑based attack chains across the IdP, cloud IAM, and application layers — from initial credential compromise through lateral movement Identify and respond to OAuth abuse, token theft, session hijacking, and federated identity attacks Threat Hunting & Detection Contribution Conduct structured threat hunts in the SIEM using detection rule logic, event correlation queries, and multi‑source pivoting Hunt for attacker behavior that existing detections miss: living‑off‑the‑land techniques, LOLBins, slow‑and‑low persistence, and C2 beaconing patterns Translate hunt findings and post‑incident learnings into specific detection recommendations or rule drafts for the Security Operations Manager Contribute to ATT&CK coverage visibility by flagging technique gaps surfaced during investigations or hunts L2 Escalation Support & Quality Take escalation handoffs from L2 analysts and the MDR partner; provide technical direction when an analyst is stuck, not just take the case Review escalation packages for completeness and accuracy — push back when context is insufficient and coach on what’s missing Identify recurring escalation patterns and flag them to the Security Operations Manager as potential L2 training gaps or detection tuning needs Document investigation methodology on closed cases in enough detail that an L2 analyst can learn from the approach Required Qualifications: 6+ years of hands‑on incident response experience, with at least 3 years performing technical IR at a senior or staff level Expert‑level EDR proficiency (e.g., CrowdStrike Falcon, SentinelOne, or equivalent): remote triage, process tree analysis, behavioral detections, and custom detection rule authorship Deep AWS IR capability: CloudTrail forensics, IAM chain analysis, EC2 and Lambda investigation, and IMDS/assumed‑role abuse patterns Strong Windows forensics: ability to reconstruct attacker activity from Prefetch, MFT, Shimcache, event logs, and registry artifacts without tooling assistance Solid Linux forensics: persistence mechanisms, cron, SUID analysis, process anomalies, and log artifact interpretation Hands‑on SIEM investigation and detection experience (e.g., Google SecOps/Chronicle, Splunk, Microsoft Sentinel): writing detection logic, pivoting on normalized events, and multi‑event correlation Identity incident response experience in an enterprise IdP (e.g., Okta, Entra ID): audit log forensics, session analysis, app‑layer anomalies, and admin abuse patterns Demonstrated ability to scope and lead Sev1 incidents autonomously, including containment decisions and cross‑functional coordination Strong technical writing: you produce investigation timelines, evidence summaries, and escalation handoffs that are accurate, concise, and unambiguous MITRE ATT&CK fluency: you use it to communicate attacker behavior, not just as a reference Preferred Qualifications: Memory forensics experience using Volatility or equivalent: process injection, credential material in memory, and rootkit indicators Malware analysis capability: static analysis (PE headers, strings, imports), dynamic sandbox review, and YARA rule authorship GCP IR experience using Cloud Audit Logs, VPC Flow Logs, and IAM policy analysis in a live incident context CIAM forensics experience (e.g., Auth0, Cognito): authentication logs, abnormal grant flows, and token misuse investigation Experience receiving and evaluating escalations from an MSSP/MDR, including identifying under‑triaged or misrouted tickets Familiarity with CSPM tooling (e.g., Wiz, Prisma Cloud, Orca) as an investigative data source during cloud incidents DFIR certifications: GCFE, GCFA, GCFR, GREM, GCIH, or equivalent practical forensics credentials Prior experience in a SaaS company, financial services, or other regulated environment handling sensitive customer data AlphaSense is an equal—opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non‑merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination. In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations, and ordinances where a particular employee works. Recruiting Scams and Fraud We at AlphaSense have been made aware of fraudulent job postings and individuals impersonating AlphaSense recruiters. These scams may involve fake job offers, requests for sensitive personal information, or demands for payment. Please note: AlphaSense never asks candidates to pay for job applications, equipment, or training. All official communications will come from an @alpha-sense.com email address. If you’re unsure about a job posting or recruiter, verify it on our Careers page. If you believe you’ve been targeted by a scam or have any doubts regarding the authenticity of any job listing purportedly from or on behalf of AlphaSense, please contact us. Your security and trust matter to us. #J-18808-Ljbffr
$80.2k - $111.3k
Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts for enterprise networks and... ...technical and procedural coaching to incident handlers and SOC analysts, elevating investigative techniques, documentation quality,...SuggestedContract workWork experience placementWork at office$73.6k - $92k
Anticipated End Date: 2026-08-07 Position Title: Business Analyst III Job Description: Business Analyst III Location: The ideal... ...1-2 hours on a Saturday. The Business Analyst III will be responsible for serving as the liaison between the business and IT in translating...SuggestedFull timeTemporary workWork experience placementWork at officeLocal areaMonday to Friday2 days per week1 day per week$89.42k - $106.65k
...outlets. We are currently seeking a Sr. Analyst, Process Development (Corporate Quality... ...) to join our team. The Sr. Analyst is responsible for providing executional excellence... ...assurance program elements including Quality Incidents, quality assurance surveillance and...SuggestedTemporary workLocal areaMonday to FridayFlexible hoursAfternoon shift2 days per week3 days per week$69.7k - $112.8k
...The Performance Analyst, Mid monitors and analyzes the performance of enterprise IT systems... ...reliability and efficiency. Key Responsibilities Design and maintain performance... ...cause analysis on recurring performance incidents, documenting findings and driving follow...SuggestedContract workWork at officeRemote work$50 - $55 per hour
...Senior EDI Business Analyst Retail Integrations & IBM webMethods Pay Rate: $50-$55... ...drive technical discussions. Key Responsibilities Business Analysis & Requirements... ...tools, or scorecard management. ITIL, incident management, problem management, or production...SuggestedRemote workWork from home- ...a means to apply for or inquire about a position and we are unable to respond to non-accommodation-related requests. Your Responsibilities Required Skills BEST Skills Process Excellence Collaboration Communication Emotional Intelligence...Ongoing contract
$101.4k - $152.1k
...highly skilled and motivated SAP Supply chain Analyst to support S/4 HANA solutions. Ideal candidate is responsible for supporting, maintaining, and enhancing Belden... ...Chain Planning processes i.e ePP/DS, & QM Lead incident resolution, problem management, and root cause...Temporary workWork at officeRemote work- ...Overview Job Title: Quality Assurance Analyst – Salesforce Location: Remote / Hybrid Type: Contract Start: ASAP Role Overview: Join... ...management, and traceability within an Agile environment. Responsibilities QA Execution & Support Perform hands-on testing across unit,...Contract workImmediate startRemote work
- ...requirements for quality control and quality assurance. The QA Analyst will work with program developers to ensure all chemical... ...formats, with a focus on traceability and system validation. Responsibilities include: In-depth review of chemistry data packages for various...Flexible hours
- ...ITI Solutions in Indianapolis, IN seeks a Junior CSSP Analyst to join our security operations team on site. The... ...CCE security dashboards, triage alerts, and document incidents under senior guidance. Responsibilities include on-going log review, investigation note maintenance...
- ...Candidate will be a detailed planner, expert communicator, top-notch analyst, and have a deep understanding of business operations and IT... ...enhance productivity, and improve operational effectiveness. Responsibilities Collaborate with stakeholders to understand their needs and...
- ...Actual Job Title IT Senior Business Analyst Job Type FT Contract Date Opened 07/27/2026 Target Date 07/31/2026 City Indianapolis... ...enhance productivity, and improve operational effectiveness. Responsibilities Collaborate with stakeholders to understand their needs and gather...Contract work
$65.23 - $70.23 per hour
...privacy, HIPAA, and covered-entity compliance training, and to handle protected health information (PHI) per established policies. Responsibilities: Support recreation, validation, and maintenance of operational metrics from platform usage and pharmacy fulfillment data to...Temporary workWork experience placementLocal area$23 - $25 per hour
...Experienced Global Operations Analyst Job Summary Responsible for the vetting of international agents and ensuring all required documentation, screening and financials are complete. Responsible to obtain updated information and documentation from international agents as...Monday to FridayFlexible hours- ...We are seeking an IT Business Analyst to support pharmacy dispensing and fulfillment operations through data analysis, reporting,... ...compliance with HIPAA and data governance requirements. Key Responsibilities Dispensing & Operational Data Management Support the recreation...
- ...Join to apply for the Business Systems Analyst role at Valeo Financial Advisors LLC Valeo Financial Advisors is one of the largest... ...office attendance in our Carmel, Indiana headquarters. Duties And Responsibilities Configure and maintain Salesforce CRM leveraging Financial...Full timeWork at office
- ...The Operations Data Analyst plays a critical role in driving operational efficiency and strategic decision‑making through data analysis. This role is responsible for collecting, analyzing, and interpreting data related to business operations, identifying trends, and providing...Work at office
- ...features. Squadware Inc is hiring a Software Quality Assurance Analyst for a consulting position with one of our clients on the north... ...join our team in Indianapolis, IN. In this role, you will be responsible for evaluating and testing the functionality of software applications...Full timeContract workRemote workRelocation
- ...and rollout of the Epic Electronic Health Record (EHR) system. Responsible for helping optimize workflow processes by configuring and... ...clinical/business systems. Provides second‑level support for incidents and requests related to the Epic application. Serves as project...
$78.9k - $123.3k
Responsibilities Position Overview: We are seeking a detail‑oriented cybersecurity compliance professional to support system authorization and continuous monitoring activities within a Federal environment. This role is responsible for managing the security authorization...Permanent employmentFull timeContract workPart timeWork at officeLocal areaRemote work$25 - $30 per hour
...Our client is seeking a detail-oriented Quality Assurance Analyst to support aerospace manufacturing quality and compliance in... ..., certifications, and quality systems administration. Key Responsibilities Review inspection reports, certifications, traceability records...Hourly payFull timeWork at office- ...Manufacturing teams to establish compliant processes, documentation, and oversight for regulated product distribution. Roles & Responsibilities Support the qualification, onboarding, and ongoing oversight of a new 3PL partner to ensure compliance with applicable GxP,...Remote work
$59.7 - $70.23 per hour
...excellence in the digital product space. Position Title – IT Business Analyst Hourly Pay Rate (w2 Role) - USD 59.70 /hr - USD 70.23 /hr... ...of HIPAA/PHI governance and data-separation requirements Responsibilities Execute and maintain operational metrics derived from...Hourly payContract workWork at office3 days per week- ...CLEAR GLOBAL SOLUTIONS, LLC in Indianapolis is looking for an Analyst II to provide mid-level analytical, data management, and operational support. The ideal candidate will be responsible for data collection, validation, and analysis, supporting program evaluations, and...
- ...Senior Business Analyst (Healthcare IT) Location: Indianapolis, IN (Hybrid Preferred) Position Type: Contract (1824 Months) We... ...familiarity with SaaS applications are highly valued. Key Responsibilities Lead requirements gathering sessions with business and technical...Contract work
- ...The opportunity As an Offensive Security Analyst on the Attack Surface Management team,... ...impact of security weaknesses. Your responsibilities will include supporting the validation... ...Ideally, you’ll also have OWASP training Incident response experience What we look for We...Summer holidayFlexible hours
- ...Candidate will be a detailed planner, expert communicator, top-notch analyst, and have a deep understanding of business operations and IT... ...enhance productivity, and improve operational effectiveness. Responsibilities Collaborate with stakeholders to understand their needs and...
- ...The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response to security... ...telemetry, and threat intelligence to determine incident scope, impact, and root cause. p]:pt-0 [& p]:mb...Contract workWork at office
- ...Healthcare Operations Data Analyst Client is seeking a Healthcare Operations Data Analyst to support the operational and analytical... ..., and covered-entity data-governance policies. Core Responsibilities Recreate, validate, maintain, and improve operational metrics...Work experience placement
- ...Security Analyst III - (Data at Rest Encryption) Location: This role requires associates... ...III - (Data at Rest Encryption) is responsible for supporting enterprise data protection... ...and problem requests; leads Level 1 and 2 incident recoveries and root cause analysis....Full timeTemporary workWork at officeLocal areaRelocation2 days per week1 day per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Analyst. Be the first to apply!
- proposal analyst Indianapolis, IN
- client delivery analyst Indianapolis, IN
- transportation analyst Indianapolis, IN
- growth analyst Indianapolis, IN
- development analyst Indianapolis, IN
- merchandising analyst Indianapolis, IN
- behavioral analyst Indianapolis, IN
- category analyst Indianapolis, IN
- analyst sales operations Indianapolis, IN
- consulting analyst Indianapolis, IN


