Cyber Security Analyst

Insight Global

United States

On-site

USD 120,000 - 165,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Insight Global is seeking a Lead Cyber Incident Responder (T3) to provide expert leadership during security incidents, driving rapid detection, triage, containment, and eradication while maintaining readiness and mentoring responders. You will coordinate incident response end-to-end, manage stakeholder communications, and drive collaboration with CTI to enrich investigations.

Lead automation, runbooks, and tabletop exercises to strengthen resilience.

Job description

The Lead Cyber Incident Responder (T3) provides expert leadership during security incidents, driving rapid detection, triage, containment, and eradication activities. The role maintains operational readiness of response capabilities, mentors responders, and ensures clear, confident communication across technical and business stakeholders. This individual acts as the escalation point for complex incidents and sets the standard for investigative quality, rhythm, and discipline.

Responsibilities

1. Incident Detection, Triage, and Response

  • Lead and coordinate security incident response operations end-to-end, from initial alert triage through closure.
  • Maintain situational awareness for any potential or incoming incidents, including the report cyber incident distro, identifying and escalating any potential incident as swiftly as possible, inline with documented processes and procedures.
  • Validate and prioritize alerts generated by SIEM, EDR, NDR, SOAR, and threat-intel sources, including hunting activities.
  • Execute deep and meaningful incident investigations, including analysis across endpoints, servers, cloud services, and network telemetry.
  • Direct containment actions: host isolation, account disablement, network blocks, identity access revocations, emergency control changes.
  • Ensure eradication and recovery steps are executed cleanly, validated, and documented.
  • Decide if, when, and how to escalage incidents to senior management, Legal, HR, DPO, Fraud, BCM, or third parties.
  • Maintain accurate incident timelines, chain-of-evidence discipline, and investigation notes.

2. Incident Command & Stakeholder Management

  • Drive the battle rhythm: situation updates, decision points, stakeholder engagement, and evidence-based assessment of impact.
  • Define incident objectives, assign tasks, and ensure cross-team accountability.
  • Communicate status and risk clearly to technical teams, senior stakeholders, and executives when required. Technical and non- technical.
  • Ensure lessons-learned sessions are completed and improvement actions are logged, tracked, and closed.

3. Stakeholder Collaboration

  • Work with CTI to enrich investigations, validate IoCs, link activity to adversary behaviour, and drive hunting hypotheses.
  • Recommend detection improvements to TDO, signature updates, and tuning based on incident findings.
  • Support tactical hunts and pivoting based on novel attacker techniques observed in incidents.
  • Critical celebrity vulnerability and purple teaming involvement with the ASM team.

4. Tools, Technology, and Automation

  • Recommend and request optimization from ACE for IR tooling: EDR, forensic toolkits, log platforms, case management, SOAR playbooks.
  • Lead the development, maintenance, and continuous improvement of IR runbooks and playbooks.
  • Identify automation opportunities to reduce manual toil and increase response speed.
  • Lead IR tabletop exercises, live action drills, simulations and continuous improvement efforts (internal to IR).
  • Support wider tabletop exercises (Fusion Cell and ASM), simulations, and purple-team activities to validate readiness.

5. Governance, Reporting, and Assurance

  • Produce high-quality incident reports, impact analysis, and executive summaries.
  • Track IR metrics: MTTD, MTTA, MTTC, containment quality, repeat incident patterns, root-cause themes.
  • Ensure IR actions align with policy, regulatory requirements, and evidentiary standards.
  • Provide assurance that security controls performed as expected during incidents; identify deviations and drive remediation.
  • Ensure end of shift handover is completed and distribute in a timely fashion and to a high standard.

6. Additional Responsibilities

  • Adhoc fulfillment of Audit requests driven by control testing and analysis- Limited to SOC/monitoring and IR activities only.
  • Adhoc IR process improvement based on postmortem activities, either driven directly by IR or Fusion Cell.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Cyber Incident Responder Tier 3
Lead Cyber Incident Responder Tier 3

Compunnel, Inc. • Charlotte (NC), Northern (KY)

On-site
USD 120,000 - 170,000
Lead Cyber Incident Responder
Lead Cyber Incident Responder

Insight Global • United States

On-site
USD 120,000 - 165,000
Incident Response Coordinator, Senior
Incident Response Coordinator, Senior

asmexternalcareersite • United States

Remote
USD 120,000 - 170,000
Cybersecurity Incident Responder
Cybersecurity Incident Responder

DivIHN Integration Inc • Saint Paul (MN)

On-site
USD 70,000 - 100,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Senior Cyber Incident Response Lead
Senior Cyber Incident Response Lead

Compunnel, Inc. • Charlotte (NC), Northern (KY)

On-site
USD 120,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 170,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • Kansas City (MO)

On-site
USD 120,000 - 180,000