Incident Response Analyst II

WGU

Salt Lake City (UT)

On-site

USD 108,000 - 162,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Bonuses
Medical, dental, vision
Wellbeing programs
Tuition assistance

Job summary

WGU is seeking an experienced Security Analyst to lead incident response and security operations. You will investigate security events, analyze logs, and refine detection rules while collaborating with infrastructure and risk teams. The position emphasizes cloud security awareness and automation.

The role is in-office with a swing shift at Salt Lake City, UT or Raleigh, NC, offering a comprehensive benefits package and career growth opportunities within a mission-driven university.

Qualifications

  • Bachelor's degree in IT security, CS, engineering, or related field.
  • 3+ years of information security experience.
  • Experience analyzing SIEM, network, event, and IDS alert logs.
  • Experience working with MITRE ATT&CK Framework.
  • Experience designing and deploying security solutions.
  • Scripting experience (Bash, Python) with automation knowledge.
  • Experience with compliance and regulatory program requirements.
  • Knowledge of AWS, cloud security, CI/CD security, and IaC.

Responsibilities

  • Lead incident response and related security efforts, including forensics, continuous monitoring, intrusion detection, and automation.
  • Investigate security events and unusual activity using SIEM, IDS/IPS, endpoint security, DLP, and other tools.
  • Analyze logs and network traffic to identify malicious or anomalous behavior.
  • Lead or participate in tactical response to address security risks across environments.
  • Develop and refine SIEM rules and MITRE ATT&CK-aligned use cases.
  • Collaborate with architects and security teams to implement detective and preventive controls.
  • Document and improve incident response processes and security operations practices.

Skills

Information security experience
MITRE ATT&CK knowledge
Automation scripting (Bash, Python)
Compliance & regulatory programs
Security incident handling & forensics
Communication skills
AWS cloud security & IaC

Education

Bachelor's Degree in IT Security/related field

Tools

SIEM
IDS/IPS
Endpoint security
Firewalls
DLP
Syslog
AWS

Job description

If you’re passionate about building a better future for individuals, communities, and our country—and you’re committed to working hard to play your part in building that future—consider WGU as the next step in your career.

Driven by a mission to expand access to higher education through online, competency-based degree programs, WGU is also committed to being a great place to work for a diverse workforce of student-focused professionals. The university has pioneered a new way to learn in the 21st century, one that has received praise from academic, industry, government, and media leaders. Whatever your role, working for WGU gives you a part to play in helping students graduate, creating a better tomorrow for themselves and their families.

Pay Range: $108,200.00 - $162,400.00

This role has a strong incident response and security operations focus, with opportunities to apply expertise across digital forensics, intrusion detection, continuous monitoring, cloud security, and security automation. You’ll collaborate with infrastructure teams, architects, risk professionals, and other security specialists to strengthen defensive capabilities and continuously improve how security threats are detected and addressed.

What You’ll Do
  • Serve as a lead analyst for incident response and related security efforts, including digital forensics, continuous monitoring, intrusion detection and prevention, penetration testing, integration, and automation.
  • Investigate security events and unusual activity using SIEM, IDS/IPS, endpoint security, DLP, HIPS, EPP, client proxy, firewalls, and other security technologies.
  • Analyze phishing emails, logs, network traffic, alerts, and other security telemetry using industry-standard tools to identify malicious, suspicious, or anomalous behavior.
  • Lead or participate in tactical response efforts to investigate and address identified security risks across technical environments.
  • Develop and refine SIEM security rules and security use cases aligned with the MITRE ATT&CK Framework.
  • Collaborate with architects, risk professionals, infrastructure teams, and security specialists to build and integrate detective, preventive, and corrective security controls.
  • Improve incident response and security operations through documentation, automation, lessons learned, Correction of Errors (CoE), and the development of more effective security practices.
What You’ll Bring
  • Bachelor's Degree in IT Security, Computer Science, Engineering, or related field.
  • 3 years of Information Security experience.
  • Experience analyzing SIEM, network, event, security, and IDS alert logs.
  • Experience working with MITRE ATT&CK Framework.
  • Experience with security industry standards and best practices, specifically with interpreting and implementing those standards in a corporate environment.
  • Scripting language experience (Bash, Python, etc.) with strong working knowledge of automation.
  • Experience working with compliance and regulatory program requirements.
  • Experience designing and deploying security solutions.Knowledge and experience in incident handling, computer forensics, intrusion detection systems, firewalls, antivirus, syslog, and related security technologies.
  • Strong understanding of SIEM content security rules to detect malicious, suspicious, and/or abnormal events.
  • Working knowledge of intrusion detection methodologies, network traffic analysis, sensor tuning, and interpreting signatures.
  • Understanding of AWS services, cloud security principles, CI/CD security, infrastructure-as-code, and data encryption strategies.
  • Excellent analytical, problem-solving, decision-making, written, and verbal communication skills.

Equivalent relevant experience performing the essential functions of this job may substitute for education degree requirements. Generally, equivalent relevant experience is defined as 1 year of experience for 1 year of education and is the discretion of the hiring manager.

Bonus Points
  • 8 years of Information Security experience.
  • Experience recommending additional security requirements and safeguards.
  • Experience in the development of end-user operating manuals and documentation.
  • Familiarity with Cloud infrastructure.
  • Relevant security certifications (CISSP, GIAC, ISACA, CCSP, CCSK, AWS, etc.).
What to Expect

At WGU, our mission drives everything we do, including how we hire. Our interview experience is designed to give qualified candidates the opportunity to show their best work through meaningful conversations and collaboration.

We thoughtfully review every application and invite forward the candidates whose experience and potential best align with the role and our mission.

  • Introductory call
  • Hiring leader interview
  • Senior Executive Interview
Work Location

This is a full-time, in-office position requiring five days per week in our Salt Lake City, Utah or Raleigh, North Carolina office, designed to foster the collaboration and connection that fuel our best work.

This role works a swing shift of 3:00 p.m. to 12:00 a.m., aligned to either Eastern or Mountain Time.

#LI-AW2

Additional Information

Full-Time Regular Positions (classified as regular and working 40 standard weekly hours): This is a full-time, regular position (classified for 40 standard weekly hours) that is eligible for bonuses; medical, dental, vision, telehealth and mental healthcare; health savings account and flexible spending account; basic and voluntary life insurance; disability coverage; accident, critical illness and hospital indemnity supplemental coverages; legal and identity theft coverage; retirement savings plan; wellbeing program; discounted WGU tuition; and flexible paid time off for rest and relaxation with no need for accrual, flexible paid sick time with no need for accrual, 11 paid holidays, and other paid leaves, including up to 12 weeks of parental leave.

  • Disclaimer: The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive.
  • Accommodations: Applicants with disabilities who require assistance or accommodation during the application or interview process should contact our Talent Acquisition team at recruiting@wgu.edu.
  • Equal Employment Opportunity: All qualified applicants will receive consideration for employment without regard to any protected characteristic as required by law.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Analyst
Senior Incident Response Analyst

WGU • Raleigh (NC)

On-site
USD 140,000 - 190,000
Health benefits
HSA & FSA
Life insurance
+6
Incident Response Analyst II Western Governors University · Salt Lake City, UT + 1 more Full-time · On-site $108,200–162,400 4 hours ago
Incident Response Analyst II Western Governors University · Salt Lake City, UT + 1 more Full-time · On-site $108,200–162,400 4 hours ago

Emploive • Salt Lake City (UT)

Hybrid
USD 108,000 - 162,000
Bonuses
Medical benefits
Tuition benefits
+7
Senior Incident Response Analyst
Senior Incident Response Analyst

Western Governors University • Salt Lake City (UT)

On-site
USD 131,000 - 196,000
Bonuses
Health benefits
Tuition discount
+2
Incident Response Analyst II
Incident Response Analyst II

Western Governors University • Salt Lake City (UT)

On-site
USD 108,000 - 162,000
Medical insurance
Dental insurance
Vision insurance
+11
Senior Manager, Security Engineering and Architecture
Senior Manager, Security Engineering and Architecture

WGU • Raleigh (NC)

On-site
USD 152,000 - 251,000
Bonuses eligible
Medical, dental, vision
Wellbeing program
+2
Senior IT Fraud Analyst
Senior IT Fraud Analyst

Western Governors University • Raleigh (NC)

On-site
USD 131,000 - 196,000
Senior IT Fraud Analyst
Senior IT Fraud Analyst

Western Governors University • Salt Lake City (UT)

On-site
USD 131,000 - 196,000
Bonuses
Health benefits
Tuition discount
+4
Lead IAR Data Analyst
Lead IAR Data Analyst

WGU • Salt Lake City (UT)

On-site
USD 110,000 - 170,000
Bonuses
Medical benefits
Tuition benefits
+3
Software Engineer II - Academy
Software Engineer II - Academy

WGU • Salt Lake City (UT)

Hybrid
USD 119,000 - 179,000
Bonuses
Medical, dental, vision, telehealth &
Wellbeing program
+3
Software Engineer II Academy
Software Engineer II Academy

WGU • Salt Lake City (UT)

Hybrid
USD 119,000 - 179,000
Bonuses
Medical, dental, vision
Tuition discount
+2