Senior Incident Response Analyst

Jobtailor

Colorado

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a senior Incident Response professional to lead triage, investigation, containment, remediation, and post-incident analysis across diverse environments. You will investigate endpoints, cloud, identity, network, and SaaS threats while developing enhanced detection logic and automation.

You will mentor staff and communicate findings to stakeholders. Occasional after-hours support may be required.

Qualifications

  • Minimum 6+ years of incident response, digital forensics, security operations, or related cybersecurity discipline.
  • Experience investigating threats across enterprise endpoint, cloud, identity, network, email, and SaaS environments.
  • Strong expertise in SIEM technologies, log analysis, event correlation, threat hunting, and incident investigation.

Responsibilities

  • Lead incident response activities through triage, investigation, containment, remediation, recovery, and post-incident analysis.
  • Investigate security events across endpoint, identity, network, cloud, email, and SaaS environments.
  • Conduct threat hunting and forensic investigations to identify malicious, suspicious, or unauthorized activity.
  • Develop and enhance detection logic, alerting, playbooks, workflows, and automation.
  • Serve as a senior escalation point for complex and high-priority security incidents.
  • Assess emerging threats, including risks associated with AI-enabled technologies.
  • Prepare clear and actionable investigation reports and communicate findings to technical and non-technical stakeholders.
  • Mentor team members and contribute to the growth and maturity of the incident response and security operations program.
  • Provide occasional evening, early morning, or after-hours support for security incidents, investigations, and other time-sensitive matters.

Skills

Incident Response
Digital Forensics
SIEM Technologies
EDR/XDR Platforms
Security Automation
PowerShell
Python
KQL
Forensic Investigations
Risk Assessment
Analytical Skills
Problem-Solving Skills
Communication Skills
Mentoring

Education

Bachelor’s degree in information technology, computer science, cybersecurity, or equivalent experience
GCIH
GCIA
GCFA
GCFE
GNFA
CISSP

Tools

SOAR Platforms
Automation Tools
Cloud Environments
SaaS Environments
Endpoint Security

Job description


  • Lead incident response activities through triage, investigation, containment, remediation, recovery, and post-incident analysis

  • Investigate security events across endpoint, identity, network, cloud, email, and SaaS environments

  • Conduct threat hunting and forensic investigations to identify malicious, suspicious, or unauthorized activity

  • Develop and enhance detection logic, alerting, playbooks, workflows, and automation

  • Serve as a senior escalation point for complex and high-priority security incidents

  • Assess emerging threats, including risks associated with AI-enabled technologies

  • Prepare clear and actionable investigation reports and communicate findings to technical and non-technical stakeholders

  • Mentor team members and contribute to the growth and maturity of the incident response and security operations program

  • Provide occasional evening, early morning, or after-hours support for security incidents, investigations, and other time-sensitive matters


Requirements


  • Six (6)+ years of experience in incident response, digital forensics, security operations, or a related cybersecurity discipline

  • Experience investigating threats across enterprise endpoint, cloud, identity, network, email, and SaaS environments

  • Strong expertise in SIEM technologies, log analysis, event correlation, threat hunting, and incident investigation

  • Experience with EDR/XDR platforms and host-based investigation techniques across enterprise environments

  • Demonstrated ability to improve detections, streamline response processes, and drive operational improvements

  • Experience with security automation, SOAR platforms, PowerShell, Python, KQL, or similar scripting and query languages is preferred

  • Strong communication, analytical, and problem-solving skills, with the ability to perform effectively during complex investigations and active incidents

  • Bachelor’s degree in information technology, computer science, cybersecurity, or equivalent experience

  • Industry certifications such as GCIH, GCIA, GCFA, GCFE, GNFA, or CISSP are preferred

  • Flexibility to meet operational and business needs

  • Occasional evening, early morning, or after-hours support may be required

  • Exempt position


Core Competencies

Demonstrates extensive experience in incident response, digital forensics, and security operations, with a strong focus on threat hunting, investigation, and automation. Capable of mentoring team members and effectively communicating findings to diverse stakeholders.


Highest-signal resume keywords


  • Incident Response

  • Digital Forensics

  • SIEM Technologies

  • EDR/XDR Platforms

  • Security Automation


Hard Skills


  • Threat Hunting

  • Log Analysis

  • Event Correlation

  • Incident Investigation

  • Detection Logic Development

  • PowerShell

  • Python

  • KQL

  • Forensic Investigations

  • Risk Assessment


Soft Skills


  • Analytical Skills

  • Problem-Solving Skills

  • Communication Skills

  • Mentoring


Certifications & Qualifications


  • GCIH

  • GCIA

  • GCFA

  • GCFE

  • GNFA

  • CISSP


Industry Keywords


  • Cybersecurity

  • Incident Response Program

  • Security Operations

  • Emerging Threats

  • AI-Enabled Technologies


Tools & Technologies


  • SOAR Platforms

  • Automation Tools

  • Cloud Environments

  • SaaS Environments

  • Endpoint Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Sr Information Security Analyst
Sr Information Security Analyst

Scorpion Therapeutics • Michigan

Hybrid
USD 120,000 - 180,000
Hybrid work two days from home
Career development opportunities
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Senior Information Security Analyst – CSIRT
Senior Information Security Analyst – CSIRT

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 110,000 - 170,000
Incident Response Analyst
Incident Response Analyst

Jobtailor • California (MO)

On-site
USD 110,000 - 150,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Director of Cyber Security
Director of Cyber Security

Jobtailor • Concord (MA)

Hybrid
USD 180,000 - 260,000
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Jobtailor • Lehi (UT)

On-site
USD 120,000 - 180,000