Lead Incident Response Analyst - Detection and Response

Merck

Rahway (NJ)

On-site

USD 117,000 - 184,000

Full time

32 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) plan
Paid holidays
Vacation days

Job summary

Merck is seeking a Lead Incident Response Analyst in the US Tech Center to oversee day-to-day operations of the incident response team and coordinate 24x7x365 support. The role requires flexibility to respond to high-severity incidents and collaborate across global technology centers for long-term investigations.

You will lead initial responses, mentor teams, and ensure containment actions across cloud and endpoint environments, reporting findings clearly to stakeholders.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity or equivalent experience.
  • 7+ years of hands-on cybersecurity operations, incident response or threat detection.
  • Leading complex investigations in cloud environments, identity systems and modern endpoint tooling.
  • Experience building or shaping a detection and response program with leadership.
  • Strong familiarity with attacker TTPs (MITRE ATT&CK), log analysis and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry) and containment in cloud environments.
  • Excellent written and verbal communication to produce concise investigative findings.

Responsibilities

  • Lead incident response for escalated MSSP/MDR alerts, including scoping, investigation and containment across cloud and endpoints.
  • Perform forensic review of affected systems, including log correlation and attacker technique identification.
  • Provide clear incident findings, timelines and remediation steps to technical and non-technical stakeholders.
  • Coordinate response activities across teams or with partners.

Skills

Cloud investigations
MDR/IR leadership
Digital forensics
MITRE ATT&CK
Log analysis
Incident response
Containment actions
AWS/Azure logs
Clear findings

Education

Bachelor's degree in Computer Science or Cybersecurity

Job description

Job Description

The Lead Incident Response Analyst is responsible for the day-to-day operations of the team that enables the CFC to respond to an emerging security incident with a coordinated response in the first 0-24hours. The team consist of Incident Response Analysts in the US Tech Center. This position directly supports a 24x7x365 support staff and candidates should be opened to supporting incident response functions outside of core hours. This position will require flexibility to work Incidents to containment and collaborate across global technology centers for long-term investigations.

Summary
Job Description

The Lead Incident Response Analyst is responsible for the day-to-day operations of the team that enables the CFC to respond to an emerging security incident with a coordinated response in the first 0-24hours. The team consist of Incident Response Analysts in the US Tech Center. This position directly supports a 24x7x365 support staff and candidates should be opened to supporting incident response functions outside of core hours. This position will require flexibility to work Incidents to containment and collaborate across global technology centers for long-term investigations.

Key Responsibilities
Position Responsibilities
  • Incident Response & InvestigationConduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency-only on-call availability is required for high-severity incidents.
  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and Various security tooling.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non‑technical stakeholders.
  • Coordinate appropriate response activities across teams or directly with partners.
Managerial Responsibilities
  • Lead the initial response for the Cyber Fusion Center for high impact cybersecurity events.
  • Develop, mentor, and lead the teams and individual members.
  • Oversee the day-to-day operations of the team.
  • Coordinate incident transfer between geographical locations and shifts.
  • Provide data analysis of incidents base on prevalent correlations and data.
  • Evaluate events, escalations, and incidents to determine remediation and resolution actions.
  • Update playbooks to improve processes and information sharing across teams.
Minimum Qualifications
  • Bachelors in Computer Science, Cybersecurity or equivalent work experience
  • 7+ years of hands‑on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload‑level events) and taking containment measures in cloud environments.
  • Excellent written and verbal communication skills, including the ability to produce concise, high‑clarity investigative findings.
Preferred Qualifications
  • Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.
  • Prior experience conducting in depth log analysis and correlating events across an enterprise.
  • Exposure to SIEM/SOAR platforms from an investigative perspective.
  • Incident response or forensics‑related certifications (e.g., GCIH, GCFA, GNFA, GCFE).
Required Skills

Adaptability, Adaptability, Analytical Thinking, Cybersecurity, Cyber Threat Analysis, Cyber Threat Hunting, Cyber Threat Intelligence, Data Loss Prevention (DLP), Detail-Oriented, Digital Forensics, Endpoint Management, Event Monitoring, Event Support, Forensic Analysis, Governance Management, Incident/Breach Triage and Containment, Incident Analysis, Incident Management, Incident Response, Incident Response Management, Insider Threat Mitigation, Log Analysis, Malware Analysis, Network Forensics, Offensive Cyber Operations {+ 17 more}

US And Puerto Rico Residents Only

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

Requirements

As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics. As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:
EEOC Know Your Rights
EEOC GINA Supplement
We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.
Learn more about your rights, including under California, Colorado and other US State Acts

Salary Range

The salary range for this role is
$117,000.00 - $184,200.00

The successful candidate will be eligible for annual bonus and long-term incentive, if applicable.

We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits.

The application deadline for this position is stated on this posting.

San Francisco Residents Only

We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance

Los Angeles Residents Only

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance

Search Firm Representatives Please Read Carefully

Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.

Employee Status

Regular

Relocation

No

VISA Sponsorship

No

Travel Requirements

10%

Flexible Work Arrangements

Remote

Shift

1st - Day

Valid Driving License

No

Hazardous Material(s)

N/A

Job Posting End Date

09/17/2026

  • A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Incident Response Analyst - Detection and Response
Lead Incident Response Analyst - Detection and Response

MSD Malaysia • Rahway (NJ)

On-site
USD 117,000 - 184,000
Medical
Dental
Vision
+4
Specialist , Infrastructure Engineering
Specialist , Infrastructure Engineering

Merck • Rahway (NJ)

Hybrid
USD 87,000 - 137,000
Hybrid work arrangement
Medical, dental, vision coverage
401(k) retirement plan
+2
Associate Director, AI/ML Engineering
Associate Director, AI/ML Engineering

Merck • Cambridge (MA)

Hybrid
USD 160,000 - 251,000
Medical, dental, vision benefits
401(k) and retirement benefits
Hybrid work arrangement
Specialist , Infrastructure Engineering
Specialist , Infrastructure Engineering

Merck & Co. • Rahway (NJ)

Hybrid
USD 112,000 - 137,000
Specialty, Pharma, & Infectious Diseases Competitive Intelligence Team Lead
Specialty, Pharma, & Infectious Diseases Competitive Intelligence Team Lead

Merck & Co. • Upper Gwynedd Township

Hybrid
USD 256,000 - 403,000
Hybrid work model
Annual bonus
Long-term incentive
Specialty, Pharma, & Infectious Diseases Competitive Intelligence Team Lead
Specialty, Pharma, & Infectious Diseases Competitive Intelligence Team Lead

Merck & Co. • Rahway (NJ)

Hybrid
USD 256,000 - 403,000
Comprehensive benefits
Specialty, Pharma, & Infectious Diseases Competitive Intelligence Team Lead
Specialty, Pharma, & Infectious Diseases Competitive Intelligence Team Lead

Merck & Co. • West Point (PA)

Hybrid
USD 256,000 - 403,000
Sr. Specialist, Financial Audit (Hybrid - Rahway, NJ)
Sr. Specialist, Financial Audit (Hybrid - Rahway, NJ)

Merck & Co. • Rahway (NJ)

Hybrid
USD 106,000 - 167,000
Annual bonus
Long-term incentive
Comprehensive benefits
+1
Senior Data Scientist, Predictive Immune Biomarker Foundation Models
Senior Data Scientist, Predictive Immune Biomarker Foundation Models

Merck • Cambridge (MA)

On-site
USD 145,000 - 228,000
Specialist, Business Consulting (Onsite)
Specialist, Business Consulting (Onsite)

Merck • Cambridge (MA)

On-site
USD 98,000 - 154,000