The Incident Response Analyst plays a critical role in protecting the organization’s information, technology platforms, and sensitive financial data from increasingly sophisticated cyber threats. This is a hands-on technical position within the Security Operations Center (SOC), responsible for investigating, containing, and resolving security incidents across endpoint, identity, network, cloud, SaaS, and enterprise environments. The successful candidate will combine strong cybersecurity fundamentals with modern detection, investigation, automation, and threat analysis capabilities to rapidly identify malicious activity and reduce organizational risk. The ideal candidate will possess a strong understanding of incident response, security operations, threat detection, threat hunting, and digital investigation methodologies. They will take ownership of security incidents throughout the response lifecycle, including triage, investigation, containment, eradication, recovery, and post-incident analysis. The analyst will correlate and analyze telemetry from multiple security technologies—including SIEM, XDR, EDR, identity, network, cloud, email, and data protection platforms—to reconstruct attack activity, determine scope and impact, identify root cause, and recommend appropriate remediation actions. Familiarity with contemporary attack techniques and frameworks such as MITRE ATT&CK is essential for understanding adversary behavior and improving detection and response capabilities. This role will be an advocate for an automation-first SOC. The Incident Response Analyst will leverage security orchestration, scripting, APIs, automation platforms, and increasingly AI-assisted security capabilities to accelerate investigations and reduce repetitive manual activities. The analyst should be comfortable identifying opportunities to automate enrichment, evidence collection, alert triage, containment actions, case management, and other repeatable incident response processes while maintaining appropriate human oversight for high-impact decisions. As enterprise environments increasingly span traditional infrastructure and cloud services, the analyst must understand modern attack surfaces across endpoints, identities, networks, cloud infrastructure, SaaS platforms, applications, and data environments. Knowledge of cloud security concepts, identity-based attacks, credential compromise, privilege escalation, lateral movement, data exfiltration, ransomware, phishing, malware, and emerging AI-enabled threats will be important to effectively investigate and respond to modern cyberattacks. The Incident Response Analyst will also contribute to the continuous improvement of the SOC by performing threat hunting, detection engineering, incident retrospectives, playbook development, and security control optimization. Lessons learned from investigations should be translated into improved detections, automated workflows, response procedures, and preventative controls. The analyst will work closely with security engineering, threat intelligence, vulnerability management, identity, cloud, infrastructure, application security, and other technology teams to strengthen the organization's overall detection and response capabilities. Strong communication and sound judgment are equally important. During significant security incidents, the analyst must clearly communicate technical findings, business impact, response actions, and recommendations to both technical and non-technical stakeholders. They must be capable of managing multiple investigations, making risk-based decisions with incomplete information, maintaining accurate incident documentation and evidence, and remaining effective during high-pressure situations. This position provides an opportunity to work with modern security technologies and help shape the evolution of a data-driven, intelligence-led, and highly automated Security Operations Center. The successful candidate will demonstrate technical curiosity, analytical thinking, ownership, collaboration, and a continuous-improvement mindset while helping the organization detect threats earlier, investigate incidents faster, and respond to cyber threats more effectively. In-Office Requirement: 4 days per week
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
Associate degree