Cyber Incident Response Analyst II

AmTrust Financial Services Inc.

Cleveland (OH)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical & Dental Plans
Life Insurance
Flexible Spending
Dependent Care
401k Savings Plans
Paid Time Off

Job summary

AmTrust Financial Services Inc. is seeking an experienced Cyber Security Incident Response II to detect, analyze, investigate, and respond to cybersecurity threats across the enterprise.

The role requires managing complex incidents, coordinating with IT, Legal, Risk, and Compliance, and continuously improving detection and response capabilities. Responsibilities include leading investigation efforts, performing digital forensics and log analysis, and developing response playbooks.

Qualifications

  • Bachelor's degree in cyber security, information technology, computer science, information systems, or related field, or equivalent practical experience.
  • 3-5+ years of experience in cyber security incident response, digital forensics, security operations, or related disciplines.
  • Experience investigating and responding to security incidents in enterprise environments.
  • Strong understanding of threat actor TTPs, attack methodologies, and incident response frameworks.
  • Experience with SIEM, EDR/XDR, email security, identity security, and cloud security platforms.
  • Ability to manage multiple investigations with attention to detail and documentation quality.
  • Strong analytical and communication skills, with the ability to explain technical findings to non-technical audiences.

Responsibilities

  • Investigate security alerts and incidents to determine scope, impact, root cause, and remediation actions.
  • Lead analysis and response for medium- to high-complexity incidents with containment and recovery.
  • Perform digital forensics, log analysis, artifact collection, and host/network investigations.
  • Analyze indicators of compromise (IOCs), TTPs, and threat intelligence to support investigations.
  • Utilize SIEM, EDR, threat intel, cloud security, and case management platforms for response.
  • Develop and maintain detection logic, rules, analytics, and response playbooks.
  • Document findings, timelines, root cause analyses, and lessons learned per procedures.
  • Collaborate with IT, Security, Legal, Risk, HR, and Compliance during investigations.
  • Participate in tabletop exercises, incident simulations, and post-incident reviews.
  • Propose improvements to security controls and detection content based on findings.
  • Participate in on-call and after-hours incident response as required.

Skills

Incident response
Forensics
Threat hunting
Documentation
Communications
Independent work

Education

Bachelor's degree
Equivalent experience

Tools

SIEM
EDR/XDR
Cloud security
Threat intel
Case management

Job description

Overview

The Cyber Security Incident Response II is responsible for detecting, analyzing, investigating, and responding to cybersecurity threats and incidents across the enterprise. This role performs advanced threat detection, incident triage, forensic analysis, containment, and recovery activities coordinated across internal and external stakeholders.

The ideal candidate possesses a strong foundation in cyber security incident response, digital forensics, detection capabilities, and stakeholder engagement. This position requires the ability to independently manage complex cybersecurity incidents, collaborate effectively with business and technical teams, influence decision-making through risk-based recommendations, and perform successfully in time-sensitive and high-pressure environments.

This role partners with third-party service providers, vendors, infrastructure teams, and security engineering and architecture teams to strengthen the organization's security posture and improve incident response capabilities. The candidate will maintain a strong understanding of AmTrust's mission, vision, and values while upholding the highest standards of professionalism and service.

Responsibilities
  • Investigate security alerts, suspicious activity, and cybersecurity incidents to determine scope, impact, root cause, and remediation actions.
  • Lead the analysis and response efforts for medium- to high-complexity security incidents, ensuring timely containment, eradication, recovery, and documentation.
  • Perform digital forensics, log analysis, artifact collection and preservation, and host and network investigations using enterprise security monitoring and endpoint detection tools.
  • Analyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and threat intelligence to support investigations.
  • Utilize SIEM, EDR, threat intelligence, cloud security, and case management platforms to investigate and respond to security incidents.
  • Develop and maintain detection logic, correlation rules, analytics, and response playbooks to improve detection and response capabilities.
  • Document investigation findings, incident timelines, root cause analysis, and lessons learned in accordance with established procedures.
  • Collaborate with IT, Security, Legal, Risk, HR, and Compliance teams as required during incident investigations.
  • Participate in tabletop exercises, incident response simulations, and post-incident reviews to validate and improve response readiness.
  • Recommend improvements to security controls, detection content, monitoring coverage, and response processes based on investigative findings.
  • Participate in on-call and after-hours incident response support as required.
Qualifications
  • Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field. Equivalent practical experience may be considered in lieu of a degree.
  • 3-5+ years of experience in cyber security incident response, digital forensics, security operations, threat hunting, or related cyber security disciplines.
  • Experience investigating and responding to security incidents in enterprise environments.
  • Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks.
  • Experience working with security monitoring technologies, including SIEM, EDR/XDR, email security, identity security, and cloud security platforms.
  • Ability to manage multiple investigations while maintaining attention to detail and documentation quality.
  • Strong analytical, problem solving, written, and verbal communication skills.
  • Ability to effectively communicate technical findings and risk-based recommendations to both technical and non-technical audiences.
  • Proven ability to work independently, manage competing priorities, and perform effectively in fast-paced, high-pressure environments.

Preferred:

  • Industry certifications such as Security+, CySA+, SecurityX (formerly CASP+) GCIH, GCFA, GCIA, GNFA, CISSP, or other relevant cybersecurity certifications.
  • Experience investigating incidents across hybrid environments.
  • Experience conducting malware analysis, memory analysis, and digital forensic investigations.
  • Knowledge of scripting, automation, and query languages such as PowerShell, Python, KQL, SPL, or similar languages.
  • Experience operating in highly regulated industries and familiarity with applicable cybersecurity regulatory requirements.
What We Offer

AmTrust Financial Services offers a competitive compensation package and excellent career advancement opportunities.

Our benefits include:

  • Medical & Dental Plans
  • Life Insurance, including eligible spouses & children
  • Health Care Flexible Spending
  • Dependent Care
  • 401k Savings Plans
  • Paid Time Off

AmTrust strives to create a diverse and inclusive culture where thoughts and ideas of all employees are appreciated and respected. This concept encompasses but is not limited to human differences with regard to race, ethnicity, gender, sexual orientation, culture, religion or disabilities.

AmTrust values excellence and recognizes that by embracing the diverse backgrounds, skills, and perspectives of its workforce, it will sustain a competitive advantage and remain an employer of choice. Diversity is a business imperative, enabling us to attract, retain and develop the best talent available. We see diversity as more than just policies and practices. It is an integral part of who we are as a company, how we operate and how we see our future.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Response Analyst II
Cyber Incident Response Analyst II

AmTrust Financial Services, Inc. • Cleveland (OH)

On-site
USD 85,000 - 125,000
Medical & Dental Plans
Life Insurance
401k Savings Plans
+1
Security Engineer II
Security Engineer II

AmTrust Financial Services Inc. • Cleveland (OH)

On-site
USD 90,000 - 120,000
Medical & Dental Plans
Life Insurance
401k Savings Plans
+1
Security Engineer I
Security Engineer I

AmTrust Financial Services, Inc. • Cleveland (OH)

On-site
USD 70,000 - 100,000
Medical & Dental Plans
Life Insurance, including eligible/sp​
Health Care Flexible Spending
+3
Cyber Incident Response Analyst II — Rapid, Impactful Investigations
Cyber Incident Response Analyst II — Rapid, Impactful Investigations

AmTrust Financial Services Inc. • Cleveland (OH)

On-site
USD 90,000 - 130,000
Medical & Dental Plans
Life Insurance
Flexible Spending
+3
Chief Information Security Officer
Chief Information Security Officer

AmTrust Financial Services Inc. • Cleveland (OH)

On-site
USD 170,000 - 230,000
Medical & Dental Plans
Life Insurance
401k Savings Plans
+1
Senior Security Engineer
Senior Security Engineer

AmTrust Financial Services, Inc. • Cleveland (OH)

On-site
USD 120,000 - 180,000
Medical & Dental Plans
Life Insurance
Health Care Flexible Spending
+3
Security Engineer I
Security Engineer I

AmTrust Financial Services Inc. • Cleveland (OH)

On-site
USD 65,000 - 90,000
Medical & Dental Plans
Life Insurance
401k Savings Plans
+1
Chief Information Security Officer
Chief Information Security Officer

Socket.dev • Cleveland (OH)

On-site
USD 170,000 - 250,000
Medical & Dental Plans
Life Insurance for you and family
401k Savings Plans
+1
Cyber Threat Analyst
Cyber Threat Analyst

Donnelley Financial, LLC • Rockville (MD)

On-site
USD 90,000 - 120,000
Competitive compensation
Flexible workplace
Professional growth opportunities
Senior Security Engineer
Senior Security Engineer

AmTrust Financial Services Inc. • Cleveland (OH)

On-site
USD 130,000 - 180,000
Medical insurance
Dental plan
Life insurance
+4