Incident Responder I
Pay Range: $42.41 – $63.62
Scheduled Weekly Hours: 40
Responsibilities
- Respond to all major systems and service incidents during business hours and extended business hours in support of the IT Incident Management program.
- Create and maintain unified monitoring of infrastructure, applications, and business & IT services to proactively detect, predict, and prevent service, application, and security problems.
- Monitor security and network operations in a 24x7 environment and escalates exceptions based on established procedures.
- Participate in on-call rotation supporting production systems.
- Perform initial triage, correlation, and documentation of security, availability, and service incidents.
- Investigate alerts using standard tools and predefined queries; escalates incidents requiring advanced analysis or coordination.
- Execute established incident response and availability playbooks for repeatable events.
- Maintain accurate incident records and provide status updates to stakeholders during the incident lifecycle.
- Utilize and maintain monitoring dashboards and alert views (ServiceNow, Splunk, Orion, Tenable, AppDynamics, Sentinel).
- Use prebuilt dashboards and analytics to identify potential issues such as service degradation, security events, and insider risk indicators.
- Follow established monitoring rules and procedures to support proactive fault detection and reduce alert noise.
- Coordinate with internal teams and vendors for resolution of assigned incidents.
- Track SLA adherence and ensure data quality for reporting and KPI tracking.
- Maintain working knowledge of tools, processes, and incident response best practices.
Additional Job Functions
Perform other duties as assigned.
Comply with regulatory compliance and assigned training requirements, including but not limited to BSA regulations corresponding to specific job duties.
Qualifications
- High School Diploma or GED required.
- Bachelor’s Degree in a related field or equivalent years of experience required.
- 1-3 years of prior relevant experience required.
- CompTIA Security+ required.
- ITIL Foundation required.
- CompTIA CySA+ preferred.
- Splunk Power User preferred.
- Certified CyberDefender preferred.
Knowledge, Skills, and Abilities
- Demonstrated ability to solve structured problems with guidance; developing capability for unstructured scenarios.
- Excellent written and verbal communication with ability to document incidents clearly.
- Basic knowledge of TCP/IP and operating systems.
- Foundational understanding of enterprise security and monitoring concepts.
- Familiarity with reading basic Kusto Query Language (KQL) and Search Processing Language (SPL).
- Foundational understanding of industry security frameworks (ISO27001, NIST800‑53).
- Working knowledge of Microsoft Active Directory, Exchange, SQL, enterprise network operations, SIEM platforms and alerting frameworks.
- Scripting basics (PowerShell / Python).
- Change Management and system hardening practices.
- SOC operations processes and tooling.
Additional Knowledge, Skills, and Abilities
- Understands basic alert types and indicators across endpoint, network, and cloud sources.
- Participates in tabletop exercises as a responder executing predefined playbooks, validating alert triage and escalation processes, and documenting actions to support testing of detection and response procedures.
- Follows predefined detection logic and recognizes common false positives.
- Understands the incident response lifecycle and follows defined playbooks.
- Escalates incidents based on predefined severity and impact criteria.
- Reviews logs and alerts to support basic investigations and documentation.
- Identifies obvious indicators of compromise using available tools.
- Understands basic integration between tools (SIEM, EDR, ticketing).
- Understands basic business impact of incidents (service disruption, user impact).
- Escalates issues affecting critical systems or users.
- Provides clear and accurate incident updates to internal teams.
- Documents incidents in a structured and understandable format.
- Identifies basic issues in alerts, processes, or documentation.
- Provides feedback to improve playbooks and monitoring.
- Understands basic concepts of security controls and alert generation.
- Recognizes how alerts are triggered within tools.
Equal Employment Opportunity Statement
SchoolsFirst FCU is an equal opportunity employer and prohibits discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibits discrimination against all individuals based on race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, political affiliation, or genetic information. This organization participates in E‑Verify.
Work Location
100% on-site, 0% remote. Includes those serving Members in‑person at our branches. Three days a week in the office and up to two days remote. Hybrid teams coordinate on‑site days to collaborate in‑person. Up to 100% remote. Select individual contributor roles may be given the option to work fully remote.