Incident Responder I

SchoolsFirst Federal Credit Union

United States

Hybrid

USD 58,424 - 87,642

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SchoolsFirst Federal Credit Union is seeking an Incident Responder I to monitor, triage, and resolve IT incidents. You will work with monitoring tools, participate in on-call rotations, and document incident timelines to keep services available.

You’ll analyze alerts from Splunk, ServiceNow, AppDynamics, and SIEM platforms, escalate as needed, and follow playbooks to reduce outage duration while maintaining data quality for KPI reporting.

Qualifications

  • Requires a Bachelor’s Degree or equivalent experience, plus 1–3 years of related work.
  • CompTIA Security+ and ITIL Foundation are preferred.
  • Experience with SIEM and alerting frameworks is expected.

Responsibilities

  • Respond to major incidents during business hours and extended hours.
  • Create and maintain unified monitoring of infrastructure, applications, and services.
  • Monitor 24x7 security and network operations and escalate as needed.
  • Participate in on-call rotation supporting production systems.
  • Perform initial triage, correlation, and documentation of incidents.
  • Investigate alerts using standard tools and predefined queries.

Skills

Incident management
Security monitoring
SLA tracking
Splunk
Kusto SPL
PowerShell / Python

Education

Bachelor’s Degree or equivalent experience
High School Diploma or GED

Tools

Splunk
ServiceNow
AppDynamics
Tenable
Sentinel
Kusto

Job description

Incident Responder I

Pay Range: $42.41 – $63.62

Scheduled Weekly Hours: 40

Responsibilities
  • Respond to all major systems and service incidents during business hours and extended business hours in support of the IT Incident Management program.
  • Create and maintain unified monitoring of infrastructure, applications, and business & IT services to proactively detect, predict, and prevent service, application, and security problems.
  • Monitor security and network operations in a 24x7 environment and escalates exceptions based on established procedures.
  • Participate in on-call rotation supporting production systems.
  • Perform initial triage, correlation, and documentation of security, availability, and service incidents.
  • Investigate alerts using standard tools and predefined queries; escalates incidents requiring advanced analysis or coordination.
  • Execute established incident response and availability playbooks for repeatable events.
  • Maintain accurate incident records and provide status updates to stakeholders during the incident lifecycle.
  • Utilize and maintain monitoring dashboards and alert views (ServiceNow, Splunk, Orion, Tenable, AppDynamics, Sentinel).
  • Use prebuilt dashboards and analytics to identify potential issues such as service degradation, security events, and insider risk indicators.
  • Follow established monitoring rules and procedures to support proactive fault detection and reduce alert noise.
  • Coordinate with internal teams and vendors for resolution of assigned incidents.
  • Track SLA adherence and ensure data quality for reporting and KPI tracking.
  • Maintain working knowledge of tools, processes, and incident response best practices.
Additional Job Functions

Perform other duties as assigned.

Comply with regulatory compliance and assigned training requirements, including but not limited to BSA regulations corresponding to specific job duties.

Qualifications
  • High School Diploma or GED required.
  • Bachelor’s Degree in a related field or equivalent years of experience required.
  • 1-3 years of prior relevant experience required.
  • CompTIA Security+ required.
  • ITIL Foundation required.
  • CompTIA CySA+ preferred.
  • Splunk Power User preferred.
  • Certified CyberDefender preferred.
Knowledge, Skills, and Abilities
  • Demonstrated ability to solve structured problems with guidance; developing capability for unstructured scenarios.
  • Excellent written and verbal communication with ability to document incidents clearly.
  • Basic knowledge of TCP/IP and operating systems.
  • Foundational understanding of enterprise security and monitoring concepts.
  • Familiarity with reading basic Kusto Query Language (KQL) and Search Processing Language (SPL).
  • Foundational understanding of industry security frameworks (ISO27001, NIST800‑53).
  • Working knowledge of Microsoft Active Directory, Exchange, SQL, enterprise network operations, SIEM platforms and alerting frameworks.
  • Scripting basics (PowerShell / Python).
  • Change Management and system hardening practices.
  • SOC operations processes and tooling.
Additional Knowledge, Skills, and Abilities
  • Understands basic alert types and indicators across endpoint, network, and cloud sources.
  • Participates in tabletop exercises as a responder executing predefined playbooks, validating alert triage and escalation processes, and documenting actions to support testing of detection and response procedures.
  • Follows predefined detection logic and recognizes common false positives.
  • Understands the incident response lifecycle and follows defined playbooks.
  • Escalates incidents based on predefined severity and impact criteria.
  • Reviews logs and alerts to support basic investigations and documentation.
  • Identifies obvious indicators of compromise using available tools.
  • Understands basic integration between tools (SIEM, EDR, ticketing).
  • Understands basic business impact of incidents (service disruption, user impact).
  • Escalates issues affecting critical systems or users.
  • Provides clear and accurate incident updates to internal teams.
  • Documents incidents in a structured and understandable format.
  • Identifies basic issues in alerts, processes, or documentation.
  • Provides feedback to improve playbooks and monitoring.
  • Understands basic concepts of security controls and alert generation.
  • Recognizes how alerts are triggered within tools.
Equal Employment Opportunity Statement

SchoolsFirst FCU is an equal opportunity employer and prohibits discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibits discrimination against all individuals based on race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, political affiliation, or genetic information. This organization participates in E‑Verify.

Work Location

100% on-site, 0% remote. Includes those serving Members in‑person at our branches. Three days a week in the office and up to two days remote. Hybrid teams coordinate on‑site days to collaborate in‑person. Up to 100% remote. Select individual contributor roles may be given the option to work fully remote.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

Financial-Plus-Credit-Union • Flint (MI)

On-site
USD 90,000 - 120,000
Senior Endpoint Services Administrator
Senior Endpoint Services Administrator

SchoolsFirst Federal Credit Union • United States

Hybrid
USD 88,000 - 132,000
Cybersecurity Analyst
Cybersecurity Analyst

Myfpcu • Flint (MI)

On-site
USD 85,000 - 115,000
Senior Endpoint Services Administrator
Senior Endpoint Services Administrator

Schoolsfirst-Federal-Credit-Union • Tustin (CA)

On-site
USD 88,000 - 132,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000
Cyber Defense Incident Response Lead
Cyber Defense Incident Response Lead

KeyBank • United States

On-site
USD 96,000 - 181,000
Incident Response Lead Specialist, Vice President
Incident Response Lead Specialist, Vice President

MUFG Bank, Ltd. • Tempe (AZ)

Hybrid
USD 126,000 - 180,000
Health benefits
Retirement plans
Educational assistance
+2
Security Operations Center Engineer
Security Operations Center Engineer

Jobgether • United States

On-site
USD 68,000 - 162,000
Remote work flexibility (US)
Health insurance
401(k) retirement plan
+2
Cyber Defense Incident Response Lead
Cyber Defense Incident Response Lead

KeyBank • New York (NY)

Hybrid
USD 96,000 - 181,000
Benefits overview
Endpoint Services Engineer
Endpoint Services Engineer

Schoolsfirst-Federal-Credit-Union • Tustin (CA)

On-site
USD 98,000 - 156,000