Incident Response Analyst (Mid-Senior Level)

Toyota Tsusho Systems Corporation

Plano (TX)

On-site

USD 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Toyota Tsusho Systems US, Inc. seeks an experienced Incident Response Analyst to join the TRRAC team. You will lead IR, perform digital forensics across Windows, Linux, macOS, and mobile platforms, and drive proactive threat hunting and intelligence activities.

You will craft reports, coordinate with the 24/7 SOC, and help improve playbooks and SOPs. Responsibilities include on-call incident handling, collaboration with multiple cybersecurity teams, and contributing to tabletop exercises while

Qualifications

  • Minimum 3–5 years hands-on incident response and digital forensics.
  • Experience acting as Incident Commander in high-pressure incidents.
  • Familiarity with security frameworks (NIST, HIPAA, ISO, OWASP).
  • Proficient with DFIR tooling and scripting for automation.

Responsibilities

  • Lead incident response activities following NIST Cybersecurity Framework across all phases.
  • Respond to cyber incidents impacting corporate and partner ecosystems.
  • Perform digital forensic investigations on diverse devices (Windows, Linux, macOS, mobile).
  • Prepare forensic reports and incident communications for executives.
  • Participate in 24/7 on-call rotation for incident coverage.
  • Develop and improve incident response playbooks and training materials.

Skills

Incident response
Digital forensics
Threat hunting
Scripting (Python)
Malware analysis

Education

Bachelor's degree in Cybersecurity or related field

Tools

Autopsy
The Sleuth Kit
Volatility
Magnet Axiom
FTK

Job description

Founded in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) is a Toyota group company, that develops IT solutions wherever global businesses operate. Transforming into a technology and mobility company, TTS-US with it's 8 TTS affiliates worldwide is establishing a secure and resilient Toyota global value chain. The creative capacity to forge such limitless business opportunities is one of the strengths of Toyota Tsusho Systems.
We are seeking a skilled and experienced Incident Response Analyst to join our collaborative cybersecurity incident response team within the Threat Research, Response & Analysis Center (TRRAC). In this role, you will combine technical expertise in digital forensics and incident response with proactive threat intelligence and hunting activities. You will respond to critical security incidents across the ecosystem, conduct comprehensive forensic investigations, and collaborate closely with the 24/7 SOC and other cybersecurity teams. When not actively responding to incidents, you will contribute to threat hunting, cyber threat intelligence, tooling improvements, and the development of SOPs and training materials—helping to elevate the entire team's capabilities.

What You’ll Be Doing
  • Conduct comprehensive incident response activities following the NIST Cybersecurity Framework across all phases: Initial Detection, Analysis & Validation, Containment, Eradication, Recovery, and Post-Incident Activity.
  • Respond to cyber incidents impacting TMNA Corporate, Manufacturing Plants, Third-Parties, Dealerships, and RSOC Customers.
  • Perform digital forensic investigations including collection, processing, and analysis of forensic evidence from diverse devices (Windows, Linux, macOS, mobile).
  • Maintain an "Always Be Timelining" (ABT) approach, continuously updating incident timelines as findings are discovered.
  • Support proactive, reactive, and exploratory threat hunting activities across the ecosystem.
  • Analyze emerging cyber threats, attacker TTPs, and track threat actors/groups to anticipate and mitigate potential attacks.
  • Collaborate closely with the 24/7 SOC, Threat Detection Engineering, Vulnerability Management, and Insider Risk Management teams.
  • Prepare and deliver forensic reports, incident communications, and executive updates during active incidents.
  • Participate in weekly on-call rotation schedule for 24/7 incident response coverage.
  • Conduct malware analysis (behavioral and static) using TRRAC Labs' dynamic analysis capabilities.
  • Help develop, refine, and maintain incident response playbooks, SOPs, and training materials to improve team effectiveness.
  • Participate in quarterly tabletop exercises to test incident response workflows and controls.
  • Stay current on emerging threats, attacker techniques, and industry best practices.

· Minimum of 3-5 years of hands‑on experience in incident response and digital forensics.

· Proven ability to act as Incident Commander within a team setting during high‑pressure incidents.

· Strong technical expertise in Windows, Linux, and macOS internals related to monitoring and threat detection.

· Experience with cloud security incident response and threat mitigation.

· Skilled in malware analysis (behavioral and static) and basic cryptanalysis.

· Familiarity with security frameworks and compliance standards (NIST, HIPAA, ISO, OWASP, etc.).

· Proficient with DFIR tools such as Autopsy, The Sleuth Kit, Volatility, Magnet Axiom, FTK, and others.

· Competent in scripting languages like Python, PowerShell, and Bash for automation and analysis.

· Excellent communication skills with the ability to collaborate effectively across technical teams and stakeholders.

Preferred / Bonus Skills

· Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred) Experience in enterprise, manufacturing, or software industries.

· Familiarity with SOAR platforms and security automation.

· Prior experience contributing to or improving incident response programs in a team environment.

Why Join Us?

· Be part of a skilled, collaborative incident response team where your expertise helps drive collective success.

· Lead and support incident response efforts alongside experienced peers.

· Continuously grow your skills through diverse investigations, threat hunting, and team knowledge sharing.

· Help shape and improve our incident response processes and training.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Analyst (Mid-Senior Level)
Incident Response Analyst (Mid-Senior Level)

Socket.dev • Plano (TX)

On-site
USD 90,000 - 130,000
Incident Response Lead & Threat Hunter
Incident Response Lead & Threat Hunter

Socket.dev • Plano (TX)

On-site
USD 90,000 - 130,000
Senior Incident Response & Digital Forensics Analyst
Senior Incident Response & Digital Forensics Analyst

Toyota Tsusho Systems Corporation • Plano (TX)

On-site
USD 90,000 - 130,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Toyota Tsusho Systems Corporation • Plano (TX)

On-site
USD 100,000 - 140,000
CTI Analyst
CTI Analyst

Toyota Tsusho Systems • Plano (TX)

On-site
USD 110,000 - 150,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems Corporation • Plano (TX)

On-site
USD 120,000 - 180,000
Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 120,000 - 180,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000