Senior Incident Response Analyst

Jobgether

United States

On-site

USD 120,000 - 180,000

Full time

13 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
Pet insurance

Job summary

Jobgether, on behalf of a partner company, seeks a Senior Incident Response Analyst based in the United States. You will lead end-to-end security incident response from detection through containment, recovery, and post-incident review.

This hands-on role covers digital forensics, threat investigation, and security operations, with automation and AI-assisted workflows to improve investigation efficiency. You will work with EDR/SIEM, threat intel, and cloud identity environments.

Qualifications

  • 6–8 years of hands-on cybersecurity experience with emphasis on incident response and/or digital forensics.
  • Ownership of the complete incident response lifecycle from detection validation to post-incident review.
  • Forensic investigations across host, memory, network, cloud, and identity environments.
  • Strong experience with EDR/EPP platforms and SIEM query development and timelines.
  • Proficiency with Python or PowerShell for automation.
  • Experience using AI tools in security operations while protecting sensitive data.

Responsibilities

  • Own Tier 1 and Tier 2 security incidents from detection to containment and recovery.
  • Conduct digital forensics across host, memory, network, cloud, and identity environments.
  • Investigate events using EDR/SIEM telemetry and develop incident timelines.
  • Participate in on-call rotations and apply containment authority as needed.
  • Improve playbooks, automation, and AI-assisted workflows based on lessons learned.
  • Lead post-incident reviews and track corrective actions through completion.

Skills

Incident response
Digital forensics
EDR
SIEM
Python
PowerShell
AI in security operations
Executive communication
CrowdStrike
AWS security
Okta

Education

GCFA

Tools

Velociraptor
KAPE
Volatility
Autopsy
EnCase
FTK
X-Ways
Zeek
Wireshark

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Incident Response Analyst based in United States.

Lead end-to-end security incident response activities within a fast-paced, technology-driven environment.

You will take ownership of complex incidents from initial detection through containment, recovery, and post-incident review.

The role combines digital forensics, threat investigation, security operations, automation, and clear incident communication.

You will investigate host, memory, network, cloud, and identity environments while protecting sensitive systems and information.

Working as a hands-on individual contributor, you will exercise defined containment authority and collaborate closely with senior security professionals.

You will also strengthen incident response capabilities by improving playbooks, automating repetitive work, and applying AI responsibly to security workflows.

Success will be measured through faster response, stronger forensic capabilities, effective documentation, and continuous improvement of the incident response program.

Accountabilities
  • Own Tier 1 and Tier 2 security incidents from detection validation, triage, and scoping through containment, eradication, recovery, and post-incident review.
  • Conduct independent digital forensic investigations across host and disk, memory, network, cloud, and identity environments while maintaining rigorous evidence-handling practices.
  • Investigate security events using EDR and SIEM telemetry, developing queries, correlation logic, and incident timelines from available log data.
  • Participate in the incident response on-call rotation and exercise defined containment authority, including host isolation and session revocation when appropriate.
  • Develop, update, and improve incident response playbooks based on lessons learned from real incidents.
  • Lead post-incident reviews and ensure identified findings and corrective actions are tracked through completion.
  • Automate repetitive triage and evidence-collection activities and use AI-assisted workflows to improve investigation efficiency while applying sound judgement around sensitive information.
  • Produce clear and defensible incident documentation for both technical and executive audiences, translating detailed findings into concise business-level summaries.
  • Apply threat intelligence and MITRE ATT&CK techniques to active investigations and use investigative findings to strengthen detection and response capabilities.
  • Contribute to the ongoing maturity of the incident response program, including improvements to processes, tooling, automation, and operational readiness.
Requirements
  • 6-8 years of hands-on cybersecurity experience, with the majority focused on incident response and/or digital forensics.
  • Demonstrated ownership of the complete incident response lifecycle, from detection validation through post-incident review.
  • Hands-on digital forensics experience spanning host and disk, memory, network, cloud, and identity investigations.
  • Strong experience with EDR/EPP platforms, including endpoint telemetry investigation, response actions, and tuning detection or response capabilities.
  • Strong SIEM experience, including query development, correlation logic, and reconstruction of incident timelines from log data.
  • Practical experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK, X-Ways, plaso, Zeek, or Wireshark.
  • Strong evidence-handling discipline, including chain of custody, sound acquisition practices, and documentation suitable for legal, regulatory, and client review.
  • Working knowledge of the MITRE ATT&CK framework applied to real-world investigations.
  • Scripting and automation experience using Python, PowerShell, or similar technologies.
  • Demonstrated hands-on experience using AI tools such as Claude, ChatGPT, Copilot, or equivalent solutions in security operations, with an understanding of how to use AI effectively while protecting sensitive data.
  • Excellent technical and executive communication skills, with the ability to produce both detailed incident timelines and concise executive summaries.
  • Willingness to participate in a shared incident response on-call rotation.
  • Experience with CrowdStrike Falcon EDR, Falcon Next-Gen SIEM, or similar platforms is preferred.
  • Experience with AWS incident response, including CloudTrail, GuardDuty, IAM abuse patterns, and related cloud security investigations is preferred.
  • Experience investigating identity-related threats, particularly within Okta environments, including session hijacking, MFA fatigue, token theft, and SSO abuse.
  • Healthcare, fintech, or other regulated-industry experience involving sensitive data is advantageous.
  • Familiarity with HIPAA, HITRUST, or SOC 2 from an operational perspective, including breach determination processes, is preferred.
  • Relevant certifications such as GCFA, GCFE, GCIH, GNFA, GCIA, GREM, or equivalent demonstrated expertise are valued.
  • Experience with malware triage, reverse engineering fundamentals, SOAR platforms, AI-assisted incident response workflows, threat intelligence, or IR program maturity is beneficial.
  • Ability to work effectively in a collaborative environment while maintaining strong independent judgment and accountability.
Benefits
  • Medical, dental, and vision insurance plans.
  • Flexible Spending Accounts and Health Savings Accounts.
  • Flexible paid time off.
  • 401(k) retirement plan with company matching.
  • Life insurance.
  • Pet insurance and additional employee benefits.
  • Opportunity to work in a relatively flat organization that encourages employees to contribute ideas and take ownership.
  • Environment built around autonomy, competence, collaboration, and belonging.
  • Opportunity to strengthen incident response capabilities and work with modern security, forensic, automation, and AI technologies.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Senior Incident Responder
Senior Incident Responder

TENEX.AI • United States

On-site
USD 120,000 - 180,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance