1

Cyber Incident Handler Jobs (NOW HIRING)

The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be ... Relevant certifications including GIAC Certified Incident Handler (GCIH), Certified Incident ...

The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be ... Relevant certifications including GIAC Certified Incident Handler (GCIH), Certified Incident ...

Senior Incident Handler

Chicago, IL ยท On-site

$18.25 - $22.25/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security ... Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive ...

Senior Incident Handler

$18.25 - $22/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security ... Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive ...

Senior Incident Handler

$18.25 - $22/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security ... Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive ...

Incident Handler Tier 2

Monterey, CA ยท On-site

$98K - $109K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 2 to work with ... cyber tools such as SIEM, Endpoint Protection, Network Access Controller, Cloud security ...

Incident Handler Tier 2

Monterey, CA ยท On-site

$98K - $109K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 2 to work with ... cyber tools such as SIEM, Endpoint Protection, Network Access Controller, Cloud security ...

Incident Handler Tier 2

Monterey, CA ยท On-site

$98K - $109K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 2 to work with ... cyber tools such as SIEM, Endpoint Protection, Network Access Controller, Cloud security ...

Showing results 21-40

Cyber Incident Handler information

See salary details

$9

$17

$24

How much do cyber incident handler jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for cyber incident handler in the United States is $17.97, according to ZipRecruiter salary data. Most workers in this role earn between $15.87 and $18.75 per hour, depending on experience, location, and employer.

What does a cyber incident handler do?

A Cyber Incident Handler is responsible for identifying, managing, and responding to cybersecurity incidents within an organization. Their primary duties include investigating security breaches, analyzing digital evidence, containing threats, and coordinating with other IT and security teams to minimize damage. They also develop and refine incident response plans, conduct post-incident analysis, and provide recommendations to improve the organization's cybersecurity posture. Cyber Incident Handlers play a critical role in keeping sensitive data and systems secure from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a cyber incident handler, and why are they important?

To thrive as a Cyber Incident Handler, you need strong analytical skills, in-depth knowledge of cybersecurity principles, and experience with incident response frameworks, often supported by a degree in information security or related field. Familiarity with tools such as SIEM platforms, intrusion detection systems, forensic software, and certifications like GCIH or CEH is typically required. Effective communication, attention to detail, and the ability to remain calm under pressure are crucial soft skills. These competencies are vital for quickly identifying, analyzing, and mitigating cyber threats to protect organizational assets and minimize damage.

What are some common challenges faced by cyber incident handlers during an active incident response?

Cyber Incident Handlers often encounter challenges such as incomplete or inconsistent data, time pressure to contain threats, and the need to coordinate with multiple teams under stressful conditions. Balancing thorough investigation with the urgency to restore normal operations can be difficult, especially when incidents are complex or rapidly evolving. Effective communication and decision-making are crucial, as handlers must relay technical findings to both technical and non-technical stakeholders while ensuring evidence is properly preserved for further analysis or legal proceedings.

What is the difference between Cyber Incident Handler vs Security Analyst?

AspectCyber Incident HandlerSecurity Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, CISSP, CEH (sometimes)
Work EnvironmentResponds to security incidents, investigates breaches, works in incident response teamsMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageCybersecurity firms, government agencies, large corporationsIT departments, cybersecurity teams, consulting firms

The Cyber Incident Handler focuses on responding to and managing security incidents, while the Security Analyst primarily monitors systems and analyzes threats. Both roles require similar certifications and often work within the same industry environments, but their core responsibilities differ in incident response versus proactive security monitoring.

More about Cyber Incident Handler jobs

What cities are hiring for Cyber Incident Handler jobs?

Cities with the most Cyber Incident Handler job openings:

What states have the most Cyber Incident Handler jobs?

States with the most job openings for Cyber Incident Handler jobs include:

What are popular job titles related to Cyber Incident Handler jobs?

For Cyber Incident Handler jobs, the most frequently searched job titles are:

Infographic showing various Cyber Incident Handler job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, 1% Temporary, and 2% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $37,374 per year, or $18 per hour.

Cyber Defense Analyst III

San Antonio, TX โ€ข On-site

Beyond SOF
Professional, Scientific, and Technical Servicesย โ€ขย 11 - 50 employees

Full-time

Re-posted 3 days ago


Job description

Essential Job Functions
  • Use information collected from a variety of sources to monitor network activity and analyze it for evidence of anomalous behavior.
  • Identify, triage and report events that occur in order to protect data and information systems.
  • Recommend proactive security measures.
  • Notify stakeholders of suspected incidents, articulating technical information surrounding the suspected incident.
  • Implement mitigations in accordance with cyber incident response plan.
  • Conduct PCAP analysis.
  • Perform advanced manual analysis to hunt previously unidentified threats.
  • Demonstrated ability to analyze and identify network and host-based security threats.
  • Understanding of snort filters and their use in IDS alerts.
  • Understanding of network hardening methodologies.
  • Working knowledge of enterprise-level IDS/IPS and firewall topologies.
  • Provide subject matter expert (SME)-level analysis of advanced adversarial Tactics, Techniques and Procedures (TTPs).
  • Develop and deploy effective threat identifying signatures and countermeasures to various sensors and intrusion prevention systems.
  • Lead and mentor team members as a technical expert.

Minimum Required Qualifications
  • Due to the nature of this position and the information that employees will be required to access, U.S. Citizenship is required.
  • Required Security Clearance: TS/SCI with FS Poly.
  • Required High School Diploma.
  • 8 years of demonstrated experience as a Cyber Defense Analyst. 2 years of experience can be substituted by a technical Bachelor's Degree.
  • Two years of experience with TCP/IP.
  • Two years of experience with tcpdump or Wireshark/tshark.
  • Requires GIAC Global Certified Incident Handler (GCIH) certification.