Incident Response Analyst - Americas

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC

Washington (District of Columbia)

On-site

USD 140,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Retirement benefits
Health insurance
Life insurance and disability
Paid time off

Job summary

The Carlyle Group is seeking an experienced Incident Response Analyst to join our SOC and protect financial data across on-prem and cloud environments. You will investigate, contain, and remediate security incidents, leveraging SIEM, XSIAM, EDR, and threat intelligence, while driving automation and playbook improvements.

You will own incidents end-to-end, communicate findings to stakeholders, and contribute to ongoing threat hunting and detection engineering in a fast-paced, security-driven

Qualifications

  • Four-year college degree or equivalent years’ of relevant experience.
  • 5+ years of IT-related experience; 3+ years in IT security operations and incident response.
  • Experience with digital forensics and evidence collection techniques in various environments.
  • Strong communication and collaboration skills with technical and business stakeholders.
  • Ability to prioritize tasks, manage multiple incidents concurrently, and work under pressure.

Responsibilities

  • Security Incident Response: analyze, investigate, document, contain, remediate, and coordinate response across endpoints, identity, network, cloud, SaaS, and data environments.
  • Maintain ownership of incidents through resolution and documentation.
  • Serve as escalation point for security events referred by MSSP requiring deeper analysis or response.
  • Correlate telemetry across multiple platforms to determine scope, root cause, and impact.
  • Develop, test, tune, and improve detection logic and analytics for threats.
  • Identify opportunities to automate investigations and response using scripting, APIs, SOAR, and automation platforms.
  • Develop, maintain incident response playbooks and procedures.
  • Develop operational metrics and reporting related to incident response and SOC performance.

Skills

SOAR platforms
SIEM
Cloud security
IaC
Python
Threat hunting
Incident response

Education

Four-year college degree or equivalent experience

Tools

Palo Alto XSIAM
AWS/Azure
Terraform
CloudFormation

Job description

Company Profile

The Carlyle Group (NASDAQ: CG) is a global investment firm with $485 billion of assets under management, across 678 investment vehicles as of June 30, 2026. Founded in 1987 in Washington, DC, Carlyle has grown into one of the world's largest and most successful investment firms, with more than 2,500 professionals operating in 28 offices in North America, Europe, the Middle East, Asia and Australia. Carlyle’s purpose is to connect people, ideas, and capital to fuel growth for companies and performance for investors, which range from public and private pension funds to wealthy individuals and families to sovereign wealth funds, unions and corporations. Carlyle invests across three segments – Global Private Equity, Global Credit and Carlyle AlpInvest – and has deep expertise across industries, markets, and geographies. At Carlyle, we believe that a wide spectrum of experiences and viewpoints drives performance and success. Our CEO, Harvey Schwartz, has stated that, "To build better businesses and create value for all of our stakeholders, we are focused on assembling leadership teams with the strongest insights from a range of perspectives." Reflecting this view, emphasis is placed on development, retention and inclusion through our internal processes and seven Employee Resource Groups (ERGs). We cultivate a culture where ideas are openly shared and challenged, connecting diverse expertise and perspectives to drive enduring value.

Position Summary

The Incident Response Analyst plays a critical role in protecting the organization’s information, technology platforms, and sensitive financial data from increasingly sophisticated cyber threats. This is a hands-on technical position within the Security Operations Center (SOC), responsible for investigating, containing, and resolving security incidents across endpoint, identity, network, cloud, SaaS, and enterprise environments. The successful candidate will combine strong cybersecurity fundamentals with modern detection, investigation, automation, and threat analysis capabilities to rapidly identify malicious activity and reduce organizational risk. The ideal candidate will possess a strong understanding of incident response, security operations, threat detection, threat hunting, and digital investigation methodologies. They will take ownership of security incidents throughout the response lifecycle, including triage, investigation, containment, eradication, recovery, and post-incident analysis. The analyst will correlate and analyze telemetry from multiple security technologies—including SIEM, XDR, EDR, identity, network, cloud, email, and data protection platforms to reconstruct attack activity, determine scope and impact, identify root cause, and recommend appropriate remediation actions. Familiarity with contemporary attack techniques and frameworks such as MITRE ATT&CK is essential for understanding adversary behavior and improving detection and response capabilities. This role will be an advocate for an automation-first SOC. The Incident Response Analyst will leverage security orchestration, scripting, APIs, automation platforms, and increasingly AI-assisted security capabilities to accelerate investigations and reduce repetitive manual activities. The analyst should be comfortable identifying opportunities to automate enrichment, evidence collection, alert triage, containment actions, case management, and other repeatable incident response processes while maintaining appropriate human oversight for high-impact decisions. As enterprise environments increasingly span traditional infrastructure and cloud services, the analyst must understand modern attack surfaces across endpoints, identities, networks, cloud infrastructure, SaaS platforms, applications, and data environments. Knowledge of cloud security concepts, identity-based attacks, credential compromise, privilege escalation, lateral movement, data exfiltration, ransomware, phishing, malware, and emerging AI-enabled threats will be important to effectively investigate and respond to modern cyberattacks. The Incident Response Analyst will also contribute to the continuous improvement of the SOC by performing threat hunting, detection engineering, incident retrospectives, playbook development, and security control optimization. Lessons learned from investigations should be translated into improved detections, automated workflows, response procedures, and preventative controls. The analyst will work closely with security engineering, threat intelligence, vulnerability management, identity, cloud, infrastructure, application security, and other technology teams to strengthen the organization's overall detection and response capabilities. Strong communication and sound judgment are equally important. During significant security incidents, the analyst must clearly communicate technical findings, business impact, response actions, and recommendations to both technical and non-technical stakeholders. They must be capable of managing multiple investigations, making risk-based decisions with incomplete information, maintaining accurate incident documentation and evidence, and remaining effective during high-pressure situations. This position provides an opportunity to work with modern security technologies and help shape the evolution of a data-driven, intelligence-led, and highly automated Security Operations Center. The successful candidate will demonstrate technical curiosity, analytical thinking, ownership, collaboration, and a continuous-improvement mindset while helping the organization detect threats earlier, investigate incidents faster, and respond to cyber threats more effectively.

In-Office Requirement

4 days per week

Primary Responsibilities
  • Security Incident Response Analyze, investigate, document, contain, remediate, and coordinate response to cybersecurity incidents across endpoint, identity, network, cloud, SaaS, email, application, and data environments.
  • Maintain ownership of incidents through resolution and ensure appropriate escalation, communication, evidence preservation, and documentation throughout the incident lifecycle.
SOC Escalation and Advanced Investigation
  • Serve as an escalation point for security events referred by the Tier 1 Managed Security Service Provider (MSSP) that require deeper technical analysis, validation, or response.
  • Correlate telemetry across multiple security platforms to determine attack scope, root cause, affected identities and assets, potential business impact, and required containment or remediation actions.
Detection Engineering
  • Develop, test, tune, and continuously improve detection logic, correlation rules, analytics, queries, and behavioral detections designed to identify advanced and emerging threats.
  • Translate lessons learned from incidents and threat hunting activities into improved detection and prevention capabilities.
Security Automation and AI-Assisted Operations
  • Identify opportunities to automate repetitive investigation and response activities using scripting, APIs, security orchestration, workflow automation, and AI-assisted security technologies.
  • Develop and improve automated workflows for alert enrichment, evidence collection, investigation, case management, containment, and remediation while maintaining appropriate human oversight.
Incident Response Playbooks
  • Develop, maintain, test, and continuously improve incident response playbooks and operational procedures for common and high-impact security scenarios, including compromised accounts, phishing, malware, ransomware, data exfiltration, insider threats, cloud compromise, and other emerging attack techniques.
Metrics and Reporting
  • Develop and maintain meaningful operational metrics and reporting related to incident response, detection effectiveness, threat hunting, automation, project deliverables, and SOC performance.
  • Use operational data to identify trends and opportunities to improve detection coverage, response time, and overall security effectiveness.
Continuous Learning and Technical Leadership
  • Maintain and expand technical expertise through research, hands-on lab work, threat research, training, industry engagement, and professional development.
  • Share knowledge with other analysts, mentor team members, document technical findings, and contribute to improving the overall capabilities and maturity of the Security Operations Center.
Requirements
  • Education & Certificates: Four-year college degree, or equivalent years’ of relevant experience, required. Certifications in incident response (GCIH, SANS) or security (CISSP, CCSP) preferred.
  • Professional Experience: 5+ years of overall IT-related experience, required. 3+ years of IT security operations and incident response experience, required. Knowledge of financial services industry and alternative asset management, strongly preferred. In-depth knowledge of incident response methodologies (identify, contain, eradicate, recover, learn). Proven ability to conduct investigations, analyze evidence, and identify root causes of security incidents. Experience with digital forensics and evidence collection techniques in various environments (cloud, network, endpoint). Experience with leveraging APIs to automate integrations between security tools. Knowledge of cloud security best practices (IAM, encryption, logging). Ability to prioritize tasks, manage multiple incidents concurrently, and work effectively under pressure. Strong analytical and problem-solving skills to diagnose complex security incidents. Excellent communication and collaboration skills to work effectively with security teams, IT teams, and business stakeholders.
Position-specific Technical Requirements
  • Proficiency with security orchestration, automation and response (SOAR) platforms (Palo Alto XSIAM).
  • Proficiency with security information and event management (SIEM) tools.
  • Proficiency with at least one major cloud platform (AWS, Azure).
  • Familiarity with Infrastructure as Code (IaC) tools (Terraform, CloudFormation).
  • Experience with scripting languages (Python, Bash, PowerShell) for automating incident response tasks.
  • Strong understanding of network security concepts (firewalls, intrusion detection/prevention systems).
  • Proficiency with endpoint security tools (antivirus, endpoint detection and response (EDR), Application Control).
  • Working knowledge of various operating systems (Windows, Linux, macOS).
Benefits/Compensation
  • The compensation range for this role is specific to Washington, DC and takes into account a wide range of factors including but not limited to the skill sets required/preferred; prior experience and training; licenses and/or certifications.
  • The anticipated base salary range for this role is $140,000-$160,000.
  • Retirement benefits
  • Health insurance
  • Life insurance and disability
  • Paid time off
  • Paid holidays
  • Family planning benefits
  • Various wellness programs
  • Annual discretionary incentive program

Due to the high volume of candidates, please be advised that only candidates selected to interview will be contacted by Carlyle.

Who We Are

When people, ideas, and capital come together, opportunity expands across private markets. At Carlyle, this belief has shaped how we invest for decades, fueling growth for companies and delivering performance for investors.

About Us

The Carlyle Group (NASDAQ: CG) is a global investment firm with $485 billion of assets under management, across 678 investment vehicles as of June 30, 2026. Founded in 1987 in Washington, DC, Carlyle has grown into one of the world's largest and most successful investment firms, with more than 2,500 professionals operating in 28 offices in North America, Europe, the Middle East, Asia and Australia. Carlyle’s purpose is to connect people, ideas, and capital to fuel growth for companies and performance for investors, which range from public and private pension funds to wealthy individuals and families to sovereign wealth funds, unions and corporations. Carlyle invests across three segments – Global Private Equity, Global Credit and Carlyle AlpInvest – and has deep expertise across industries, markets, and geographies. At Carlyle, we believe that a wide spectrum of experiences and viewpoints drives performance and success. Our CEO, Harvey Schwartz, has stated that, "To build better businesses and create value for all of our stakeholders, we are focused on assembling leadership teams with the strongest insights from a range of perspectives." Reflecting this view, emphasis is placed on development, retention and inclusion through our internal processes and seven Employee Resource Groups (ERGs). We cultivate a culture where ideas are openly shared and challenged, connecting diverse expertise and perspectives to drive enduring value.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

On-site
USD 160,000 - 180,000
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
SOC Analyst
SOC Analyst

Clear Capital • Reno (NV)

On-site
USD 114,000 - 139,000
Profit-sharing bonus
401(k) plan with employer match
Comprehensive health/dental/vision
+2
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Carlyle Group • Washington

Hybrid
USD 160,000 - 180,000
Incident Response Analyst — On-Site 4 Days/Week
Incident Response Analyst — On-Site 4 Days/Week

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

On-site
USD 140,000 - 160,000
Retirement benefits
Health insurance
Life insurance and disability
+1
Forward Deployed Engineer, Client Solutions Group
Forward Deployed Engineer, Client Solutions Group

Carlyle Group • New York (NY), Northern (KY)

Hybrid
USD 160,000 - 190,000
Competitive compensation package
Senior Security Operation Center (SOC) Analyst – L2
Senior Security Operation Center (SOC) Analyst – L2

Richemont • New York (NY)

On-site
USD 135,000 - 140,000
Medical, dental, and vision programs
401(k) with employer match
Paid time off
Security Operations Manager
Security Operations Manager

McKinsey & Company, Inc. • Boston (MA)

On-site
USD 174,000 - 178,000
Healthcare benefits
Retirement plan
Paid time off
+1