Senior Incident Response Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Washington, D.C.; salary ranges are also provided for Baltimore and Denver. Core hours are Monday through Friday, 9:00 a.m. to 6:00 p.m., with occasional evening, early morning, or after-hours incident support.
Salary: $135,000–$175,000 per year in Washington, D.C.; $125,000–$163,500 per year in Baltimore; $123,000–$161,500 per year in Denver. Additional discretionary bonuses may apply.
Company
operates a global technology environment supported by a mature and evolving security program.
What you will do
- Lead incident response from triage and investigation through containment, remediation, recovery, and post-incident analysis.
- Investigate security events across endpoint, identity, network, cloud, email, and SaaS environments.
- Conduct threat hunting and forensic investigations to identify malicious, suspicious, or unauthorized activity.
- Develop detection logic, alerting, playbooks, workflows, and automation to improve response capabilities.
- Serve as a senior escalation point for complex incidents and assess emerging threats, including AI-enabled technology risks.
- Prepare investigation reports, communicate findings to technical and non-technical stakeholders, and mentor team members.
Requirements
- Six or more years of experience in incident response, digital forensics, security operations, or a related cybersecurity discipline.
- Experience investigating threats across enterprise endpoint, cloud, identity, network, email, and SaaS environments.
- Strong expertise in SIEM technologies, log analysis, event correlation, threat hunting, and incident investigation.
- Experience with EDR/XDR platforms and host-based investigation techniques.
- Ability to improve detections, streamline response processes, and drive operational improvements.
- Bachelor’s degree in information technology, computer science, cybersecurity, or equivalent experience.
Nice to have
- Experience with security automation, SOAR platforms, PowerShell, Python, KQL, or similar scripting and query languages.
- Certifications such as GCIH, GCIA, GCFA, GCFE, GNFA, or CISSP.
Culture & Benefits
- Full-time exempt employment with flexibility to support operational and business needs.
- Medical, dental, and vision insurance.
- 401(k) retirement plan and paid time off.
- Potential annual discretionary bonuses.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →