Lead Incident Response Analyst - Remote & On-Call

Merck

Rahway (NJ)

On-site

USD 117,000 - 184,000

Full time

25 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) plan
Paid holidays
Vacation days

Job summary

Merck is seeking a Lead Incident Response Analyst in the US Tech Center to oversee day-to-day operations of the incident response team and coordinate 24x7x365 support. The role requires flexibility to respond to high-severity incidents and collaborate across global technology centers for long-term investigations.

You will lead initial responses, mentor teams, and ensure containment actions across cloud and endpoint environments, reporting findings clearly to stakeholders.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity or equivalent experience.
  • 7+ years of hands-on cybersecurity operations, incident response or threat detection.
  • Leading complex investigations in cloud environments, identity systems and modern endpoint tooling.
  • Experience building or shaping a detection and response program with leadership.
  • Strong familiarity with attacker TTPs (MITRE ATT&CK), log analysis and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry) and containment in cloud environments.
  • Excellent written and verbal communication to produce concise investigative findings.

Responsibilities

  • Lead incident response for escalated MSSP/MDR alerts, including scoping, investigation and containment across cloud and endpoints.
  • Perform forensic review of affected systems, including log correlation and attacker technique identification.
  • Provide clear incident findings, timelines and remediation steps to technical and non-technical stakeholders.
  • Coordinate response activities across teams or with partners.

Skills

Cloud investigations
MDR/IR leadership
Digital forensics
MITRE ATT&CK
Log analysis
Incident response
Containment actions
AWS/Azure logs
Clear findings

Education

Bachelor's degree in Computer Science or Cybersecurity

Job description

Merck is seeking a Lead Incident Response Analyst in the US Tech Center to oversee day-to-day operations of the incident response team and coordinate 24x7x365 support. The role requires flexibility to respond to high-severity incidents and collaborate across global technology centers for long-term investigations.

You will lead initial responses, mentor teams, and ensure containment actions across cloud and endpoint environments, reporting findings clearly to stakeholders.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Lead Incident Response & Forensics
Remote Lead Incident Response & Forensics

Merck & Co. • Rahway (NJ)

On-site
USD 117,000 - 184,000
Remote Incident Response Lead
Remote Incident Response Lead

MSD Malaysia • Rahway (NJ)

On-site
USD 117,000 - 184,000
Medical
Dental
Vision
+4
Senior Incident Response Engineer - Remote/Hybrid
Senior Incident Response Engineer - Remote/Hybrid

LinkedIn • United States

Hybrid
USD 129,000 - 212,000
Annual bonus
Stock plans
Benefits
Senior Incident Response Lead — Remote
Senior Incident Response Lead — Remote

Maestro Search • United States

On-site
USD 120,000 - 155,000
Senior Incident Response Leader | Cybersecurity Ops
Senior Incident Response Leader | Cybersecurity Ops

TeleTech Holdings, Inc. • Austin (TX)

On-site
USD 120,000 - 140,000
100% remote work
Bonus opportunities
Healthcare benefits
+1
Remote Cyber Defense Analyst: Incident Response Lead
Remote Cyber Defense Analyst: Incident Response Lead

UnitedHealth Group • Eden Prairie (MN)

On-site
Confidential
Senior Incident Response Leader (Remote)
Senior Incident Response Leader (Remote)

Centene Corp. • Illinois

On-site
USD 121,000 - 225,000
Health insurance
401K and stock purchase plans
Tuition reimbursement
+2
Senior Cyber Incident Responder & Technical Lead
Senior Cyber Incident Responder & Technical Lead

Meriplex-Communication • Town of Texas (WI)

On-site
USD 110,000 - 160,000
Senior Incident Response Leader (Remote)
Senior Incident Response Leader (Remote)

Cognizant • City of Albany (NY)

On-site
USD 135,000 - 145,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Senior Incident Response Engineer - Remote/Hybrid
Senior Incident Response Engineer - Remote/Hybrid

Linkedin3 • United States

Hybrid
USD 129,000 - 212,000