Lead Incident Response Analyst - Detection and Response

MSDRahway, NJ
$117,000 - $184,200Remote

About The Position

The Lead Incident Response Analyst is responsible for the day-to-day operations of the team that enables the CFC to respond to an emerging security incident with a coordinated response in the first 0-24hours. The team consist of Incident Response Analysts in the US Tech Center. This position directly supports a 24x7x365 support staff and candidates should be opened to supporting incident response functions outside of core hours. This position will require flexibility to work Incidents to containment and collaborate across global technology centers for long-term investigations.

Requirements

  • Bachelors in Computer Science, Cybersecurity or equivalent work experience
  • 7+ years of hands‑on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload‑level events) and taking containment measures in cloud environments.
  • Excellent written and verbal communication skills, including the ability to produce concise, high‑clarity investigative findings.

Nice To Haves

  • Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.
  • Prior experience conducting in depth log analysis and correlating events across an enterprise.
  • Exposure to SIEM/SOAR platforms from an investigative perspective.
  • Incident response or forensics‑related certifications (e.g., GCIH, GCFA, GNFA, GCFE).

Responsibilities

  • Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments.
  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non‑technical stakeholders.
  • Coordinate appropriate response activities across teams or directly with partners.
  • Lead the initial response for the Cyber Fusion Center for high impact cybersecurity events.
  • Develop, mentor, and lead the teams and individual members.
  • Oversee the day-to-day operations of the team.
  • Coordinate incident transfer between geographical locations and shifts.
  • Provide data analysis of incidents base on prevalent correlations and data.
  • Evaluate events, escalations, and incidents to determine remediation and resolution actions.
  • Update playbooks to improve processes and information sharing across teams.

Benefits

  • medical
  • dental
  • vision healthcare
  • other insurance benefits (for employee and family)
  • retirement benefits
  • 401(k)
  • paid holidays
  • vacation
  • compassionate and sick days
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service