Cyber Defense & Incident Response Analyst

Jobtailor

Cincinnati (OH)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks an experienced security operations professional to monitor SIEM/EDR and respond to alerts on a 24/7 basis across hybrid environments. You will lead investigations, coordinate with MDR/MSSP partners, and drive audit readiness for SOC 2 Type 2 and related programs.

Responsibilities include PAM policy design, privileged-access reviews, mailbox security investigations, and phishing defense, with collaboration across IT Ops and Compliance.

Qualifications

  • BS/BA in Computer Science, Electrical Engineering, Information Security, or related field; equivalent experience considered.
  • Progressive experience in software, automation, or logistics environments with accountability.
  • Hands-on SIEM/EDR and security tool experience (Rapid7, Defender, Abnormal, KnowBe4, Intune, Securden PAM).
  • Working knowledge of SOC 2 Type 2 evidence collection and audit support.
  • Strong organizational, PM, and communication skills; ability to build trust at all levels.
  • High ethical standards; self-starter, decisive, energetic.
  • Skills and platform experience considered a plus: Microsoft Purview, Intune, Rapid7, MS 365/Azure, SharePoint, Vanta, MITRE ATT&CK, security certifications.

Responsibilities

  • Monitor SIEM/alerts 24/7 across networks, servers, cloud, and endpoints.
  • Perform triage, containment, and restore of affected systems.
  • Lead investigations of phishing and token-theft events; review mailboxes.
  • Coordinate incident follow-up with MDR/MSSP partners and run playbooks.
  • Provide audit evidence and logs for auditors on request.
  • Serve as primary contact for SOC 2 Type 2 audit and quarterly reviews.
  • Maintain logs/reports for audit readiness and remediation tracking.
  • Define PAM policies and conduct privileged-access reviews.
  • Review privileged access requests and enforce policy.
  • Define endpoint security baselines and policy compliance.
  • Monitor EDR/NGAV coverage and disk encryption; maintain audit trails.
  • Coordinate patch validation and vendor vulnerability remediation.
  • Design and tune mail security (SPF/DKIM/DMARC; phishing filters).
  • Investigate mail threats and manage quarantine decisions.
  • Review backup security configurations and participate in DR testing.
  • Track threat intelligence and map to MITRE ATT&CK.
  • Maintain enterprise security documents and incident response plans.
  • Lead security vendor evaluations and test deliverables.

Skills

Organizational skills
Project management
Communication
Self-starter
Energetic

Education

BS/BA in Computer Science or related field

Tools

Rapid7
Microsoft Defender
Abnormal Security
KnowBe4
Intune
Securden PAM
Microsoft Purview
Data Protection
MS 365/Azure
SharePoint
Vanta
MITRE ATT&CK
Security certifications

Job description

Jobtailor seeks an experienced security operations professional to monitor SIEM/EDR and respond to alerts on a 24/7 basis across hybrid environments. You will lead investigations, coordinate with MDR/MSSP partners, and drive audit readiness for SOC 2 Type 2 and related programs.

Responsibilities include PAM policy design, privileged-access reviews, mailbox security investigations, and phishing defense, with collaboration across IT Ops and Compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst – SOC Lead & IR Orchestrator
Senior Security Analyst – SOC Lead & IR Orchestrator

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Senior Security Analyst: Threat Detection & IR Lead
Senior Security Analyst: Threat Detection & IR Lead

Jobtailor • Minneapolis (MN)

On-site
USD 110,000 - 140,000
Security Operations & Incident Response Lead
Security Operations & Incident Response Lead

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 120,000 - 180,000
Cybersecurity Analyst II - Threat Detection & Incident Response
Cybersecurity Analyst II - Threat Detection & Incident Response

Jobtailor • Reading

On-site
USD 90,000 - 120,000
Cybersecurity Operations & Threat Response Specialist
Cybersecurity Operations & Threat Response Specialist

Jobtailor • Los Angeles (CA)

On-site
USD 90,000 - 140,000
Cybersecurity Incident Response Engineer II
Cybersecurity Incident Response Engineer II

Jobtailor • Pennsylvania

On-site
USD 70,000 - 100,000
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000
Security Operations Engineer — Threat Hunting & SIEM Expert
Security Operations Engineer — Threat Hunting & SIEM Expert

Jobtailor • North Carolina

On-site
USD 70,000 - 110,000
Cyber Defense Analyst — Incident Response & SIEM Specialist
Cyber Defense Analyst — Incident Response & SIEM Specialist

Omniscius Consulting • Washington

On-site
USD 120,000 - 150,000
Cybersecurity Governance & Incident Response Manager
Cybersecurity Governance & Incident Response Manager

Jobtailor • City of Tonawanda (NY)

On-site
USD 120,000 - 150,000