First Citizens Bank
First Citizens BankVerified Source

Senior Information Security Analyst (Incident Response)

140K–188K
Onsite · Raleigh, North Carolina
Posted August 12, 2026
payroll

Overview

Remote role supporting Cyber Incident Response team at First Citizens Bank. Experienced senior analyst needed to detect and respond to threats interact with stakeholders and restore operations. Technical role supporting Threat Hunting Intelligence and Monitoring with content creation threat analysis detection recommendations and colleague mentoring.

What You'll Do15

  • 1Investigate SIEM SOAR events as necessary
  • 2Apply malware analysis network endpoint security to respond contain incidents
  • 3Lead incidents coordinate investigation mitigation remediation technically
  • 4Coordinate with technical business stakeholders
  • 5Ensure incidents are detected documented investigated resolved
  • 6Develop countermeasures mitigations in response to incidents
  • 7Support creation of threat hunting operational driven inputs
  • 8Track evolving threat actor techniques
  • 9Provide post incident reviews recommendations improve communication processes procedures mitigation options
  • 10Define security requirements drive project deliverables
  • 11Maintain multiple incidents ensure timely responses
  • 12Respond to cloud related incidents in Azure AWS Google Cloud
  • 13Utilize cloud administrative experience preferred
  • 14Participate in afterhours on call rotation weekly cycles
  • 15Drive security requirements and incident response activities

Requirements12

  • 1Bachelor's Degree and 8 years experience in Information security
  • 2High School Diploma or GED and 12 years experience in Information security
  • 32+ years Threat Hunting experience
  • 4Familiarity with MITRE ATT&CK application to countermeasure creation
  • 5Experience analyzing disclosing escalating security events systems applications network authentication email events
  • 6Ability translate threat actor techniques to building mitigations via Yara Sigma or Regular Expressions
  • 7Define security requirements drive project deliverables
  • 8Track multiple incidents ensure timely responses
  • 9Respond to cloud incidents in Azure AWS Google Cloud
  • 10Cloud administrative experience preferred
  • 11Cyber Incident Response experience 3+ years primary job was Incident Response role
  • 12Participate in afterhours on call rotation weekly cycles

Salary Insight

$140 - $188k per year

Location

Typeonsite
LocationRaleigh, North Carolina

Required Skills

pythonawsreactkubernetescpc card
Share:

Similar open positions

Explore active roles that match your skills and interests.

System One

System One

9d agoWashington, District of Columbiapayroll

Mid-Level Cybersecurity Incident Response Analyst

Own security alert investigation and response at scale. Deliver actionable insights within 90 days. Differentiate through proactive threat hunting and cross-functional collaboration.

Competitive salary
pythonawsreact+2 more
BCforward

BCforward

12h agoPhoenix, Arizonapayroll

Cyber Security Engineer, SOC & Incident Response

Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.

135K–146K
splunkcrowdstrikeaws+2 more
MANTECH

MANTECH

13h agoWashington, District of Columbiapayroll

Cyber Security Analyst, Incident Response & SOC

You will own security event correlation and incident triage across enterprise networks, detecting and responding to threats in real time. You will work within a 24x7 SOC team, analyzing alerts from Windows and Linux systems and coordinating remediation. You hold IAT Level II certification (Security+ or equivalent) and thrive in high-stakes environments. This role offers direct exposure to COTS security tools and a clear path to advanced cyber roles.

Competitive salary
Security event and incident correlationCyber incident triageCyber engineering trend analysis+7 more
Robert Half

Robert Half

11h agoSan Francisco, Californiacontract

Security Analyst, Cloud Security Operations

You will own threat detection and incident response for cloud-based workloads at a growing fintech. You will triage alerts, hunt for malicious activity, and tune detections across AWS and Azure. You will partner with engineering and IT to reduce risk and improve response workflows. This role stands out for its emphasis on building detection content and automating response with Python and Splunk.

45K–50K
splunkcrowdstrikeaws+2 more
AaraTechnologies Inc

AaraTechnologies Inc

11h agoWashington, District of Columbiacontract

Cyber Security Analyst, Retail & E-Commerce

You will own security monitoring and incident response for retail and e-commerce platforms, protecting payment systems and customer data. As a Cyber Security Analyst with 2-3 years experience, you will report to the Security Operations Lead and collaborate with DevOps and Compliance teams. You will detect threats, remediate vulnerabilities, and support PCI-DSS compliance. This contract role stands out by offering direct impact on fraud prevention and real-time threat mitigation.

31K–36K
Threat MonitoringVulnerability AssessmentIncident Response+1 more

Phoenix Cyber

18d agoRemotepayroll

Cybersecurity Analyst Remote Phoenix Cyber

Lead ownership of network traffic analysis and IDS monitoring for a remote team at Phoenix Cyber. Analyze security events and logs to prioritize threats. Develop SOPs and provide actionable insights. Collaborate with cross-functional teams to improve security architecture. Stay current with emerging threats and mitigation strategies. This role offers unique exposure to diverse security challenges across multiple clients.

Competitive salary
Network Traffic MonitoringIntrusion Detection Systems (IDS)Security Event Log Analysis+9 more