Senior Information Security Analyst (Incident Response)
Overview
Remote role supporting Cyber Incident Response team at First Citizens Bank. Experienced senior analyst needed to detect and respond to threats interact with stakeholders and restore operations. Technical role supporting Threat Hunting Intelligence and Monitoring with content creation threat analysis detection recommendations and colleague mentoring.
What You'll Do15
- 1Investigate SIEM SOAR events as necessary
- 2Apply malware analysis network endpoint security to respond contain incidents
- 3Lead incidents coordinate investigation mitigation remediation technically
- 4Coordinate with technical business stakeholders
- 5Ensure incidents are detected documented investigated resolved
- 6Develop countermeasures mitigations in response to incidents
- 7Support creation of threat hunting operational driven inputs
- 8Track evolving threat actor techniques
- 9Provide post incident reviews recommendations improve communication processes procedures mitigation options
- 10Define security requirements drive project deliverables
- 11Maintain multiple incidents ensure timely responses
- 12Respond to cloud related incidents in Azure AWS Google Cloud
- 13Utilize cloud administrative experience preferred
- 14Participate in afterhours on call rotation weekly cycles
- 15Drive security requirements and incident response activities
Requirements12
- 1Bachelor's Degree and 8 years experience in Information security
- 2High School Diploma or GED and 12 years experience in Information security
- 32+ years Threat Hunting experience
- 4Familiarity with MITRE ATT&CK application to countermeasure creation
- 5Experience analyzing disclosing escalating security events systems applications network authentication email events
- 6Ability translate threat actor techniques to building mitigations via Yara Sigma or Regular Expressions
- 7Define security requirements drive project deliverables
- 8Track multiple incidents ensure timely responses
- 9Respond to cloud incidents in Azure AWS Google Cloud
- 10Cloud administrative experience preferred
- 11Cyber Incident Response experience 3+ years primary job was Incident Response role
- 12Participate in afterhours on call rotation weekly cycles
Salary Insight
$140 - $188k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

System One
VerifiedMid-Level Cybersecurity Incident Response Analyst
Own security alert investigation and response at scale. Deliver actionable insights within 90 days. Differentiate through proactive threat hunting and cross-functional collaboration.

BCforward
VerifiedCyber Security Engineer, SOC & Incident Response
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.
MANTECH
VerifiedCyber Security Analyst, Incident Response & SOC
You will own security event correlation and incident triage across enterprise networks, detecting and responding to threats in real time. You will work within a 24x7 SOC team, analyzing alerts from Windows and Linux systems and coordinating remediation. You hold IAT Level II certification (Security+ or equivalent) and thrive in high-stakes environments. This role offers direct exposure to COTS security tools and a clear path to advanced cyber roles.
Robert Half
VerifiedSecurity Analyst, Cloud Security Operations
You will own threat detection and incident response for cloud-based workloads at a growing fintech. You will triage alerts, hunt for malicious activity, and tune detections across AWS and Azure. You will partner with engineering and IT to reduce risk and improve response workflows. This role stands out for its emphasis on building detection content and automating response with Python and Splunk.

AaraTechnologies Inc
VerifiedCyber Security Analyst, Retail & E-Commerce
You will own security monitoring and incident response for retail and e-commerce platforms, protecting payment systems and customer data. As a Cyber Security Analyst with 2-3 years experience, you will report to the Security Operations Lead and collaborate with DevOps and Compliance teams. You will detect threats, remediate vulnerabilities, and support PCI-DSS compliance. This contract role stands out by offering direct impact on fraud prevention and real-time threat mitigation.
Phoenix Cyber
VerifiedCybersecurity Analyst Remote Phoenix Cyber
Lead ownership of network traffic analysis and IDS monitoring for a remote team at Phoenix Cyber. Analyze security events and logs to prioritize threats. Develop SOPs and provide actionable insights. Collaborate with cross-functional teams to improve security architecture. Stay current with emerging threats and mitigation strategies. This role offers unique exposure to diverse security challenges across multiple clients.