
Mid-Level Cybersecurity Incident Response Analyst
Overview
Own security alert investigation and response at scale. Deliver actionable insights within 90 days. Differentiate through proactive threat hunting and cross-functional collaboration.
What You'll Do9
- 1Monitor and analyze security alerts from SIEM EDR IDS/IPS cloud platforms and other enterprise tools
- 2Perform incident detection triage analysis and containment recovery escalation
- 3Analyze logs endpoints network traffic and system data to identify malicious activity
- 4Support continuous monitoring of networks endpoints cloud environments and security infrastructure
- 5Conduct proactive threat hunting and document indicators of compromise
- 6Assist senior staff with digital forensics malware analysis and forensic investigations
- 7Maintain incident documentation and contribute to operational metrics reporting
- 8Participate in tabletop exercises and process improvement initiatives
- 9Provide technical guidance and day-to-day support to junior analysts
Requirements6
- 1Bachelor's degree in Cybersecurity Information Technology Computer Science or related field
- 2Three additional years of relevant experience may substitute for bachelor's degree
- 3Experience with SIEM EDR IDS/IPS SOAR and cloud security technologies
- 4Knowledge of digital forensics malware analysis cyber threat intelligence and threat hunting
- 5Familiarity with MITRE ATT&CK and NIST SP 800-61 SP 800-86 frameworks
- 6Experience supporting federal cybersecurity programs
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
AGR LLC
VerifiedMid-Level Cyber Defense Analyst
Lead a comprehensive cyber defense effort supporting government agencies in Washington DC. Own incident response and threat mitigation initiatives at a high level. Drive continuous improvement of security posture across cloud and on-premises environments.
First Citizens Bank
VerifiedSenior Information Security Analyst (Incident Response)
Remote role supporting Cyber Incident Response team at First Citizens Bank. Experienced senior analyst needed to detect and respond to threats interact with stakeholders and restore operations. Technical role supporting Threat Hunting Intelligence and Monitoring with content creation threat analysis detection recommendations and colleague mentoring.
MANTECH
VerifiedCyber Security Analyst, Incident Response & SOC
You will own security event correlation and incident triage across enterprise networks, detecting and responding to threats in real time. You will work within a 24x7 SOC team, analyzing alerts from Windows and Linux systems and coordinating remediation. You hold IAT Level II certification (Security+ or equivalent) and thrive in high-stakes environments. This role offers direct exposure to COTS security tools and a clear path to advanced cyber roles.
SPAHR SOLUTIONS GROUP LLC
VerifiedCybersecurity Protect Analyst
Lead technical cybersecurity liaison for subscriber organizations delivering advanced guidance on resolving complex security posture issues and patching delays. Serve as primary auditor for Data Element Dictionary governance overseeing validation rules for identity-attributed network and object-access events. Manage vulnerability tracking and KEV mitigation leveraging CVE NVD CVSS and CWE classifications. Conduct vulnerability assessments using ACAS and other enterprise scanning tools to provide prioritized remediation steps.
Phoenix Cyber
VerifiedCybersecurity Analyst Remote Phoenix Cyber
Lead ownership of network traffic analysis and IDS monitoring for a remote team at Phoenix Cyber. Analyze security events and logs to prioritize threats. Develop SOPs and provide actionable insights. Collaborate with cross-functional teams to improve security architecture. Stay current with emerging threats and mitigation strategies. This role offers unique exposure to diverse security challenges across multiple clients.

BCforward
VerifiedCyber Security Engineer, SOC & Incident Response
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.