Cyber Incident Response Analyst Location: Austin, TX / San Antonio, TX (Onsite) Duration: 12 Months Contract Interview: Onsite Cyber Incident Response, Digital Forensics, Windows & Linux Security, SIEM, EDR, IDS/IPS, Threat Hunting, Malware Analysis, Memory & Disk Forensics, MITRE ATT&CK, CrowdStrike, SentinelOne, Microsoft Sentinel, NetWitness, Corelight, Gravwell, Google SecOps, Incident Command, Threat Intelligence, Security Operations (SOC). Job Description We are seeking an experienced Cyber Incident Response Analyst to join our cybersecurity team. The ideal candidate will be responsible for investigating and responding to cybersecurity incidents, conducting forensic analysis, and collaborating with internal teams to protect critical systems and infrastructure. This role requires strong analytical skills, hands-on experience with incident response tools, and the ability to communicate technical findings to both technical and non-technical stakeholders. Responsibilities
- Perform incident response activities, including triage, investigation, containment, eradication, and recovery.
- Conduct host-based forensic investigations across Windows and Linux environments.
- Analyze logs, memory, file systems, and malware to determine the scope and impact of security incidents.
- Monitor and investigate alerts from SIEM, EDR, IDS/IPS, and network monitoring tools.
- Correlate endpoint, network, and threat intelligence data to identify attack patterns and build incident timelines.
- Serve as the Incident Commander during major cybersecurity events when required.
- Analyze attacker tactics, techniques, and procedures (TTPs) and map findings to the MITRE ATT&CK framework.
- Prepare detailed incident reports, executive summaries, and technical documentation.
- Collaborate with cross-functional teams to improve detection capabilities and strengthen security controls.
- Participate in post-incident reviews and contribute to updating incident response playbooks.
- Provide on-call support for critical security incidents as needed.
Required Qualifications
- 5+ years of experience in Cybersecurity Incident Response, Security Operations, or Digital Forensics.
- Strong experience with Windows and Linux incident response and forensic investigations.
- Hands-on experience with SIEM, EDR, IDS/IPS, and security monitoring platforms.
- Experience using tools such as CrowdStrike, SentinelOne, Microsoft Sentinel, NetWitness, Corelight, Gravwell, or Google SecOps.
- Knowledge of malware analysis, memory analysis, and digital forensic techniques.
- Strong understanding of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies.
- Experience producing incident reports and documenting technical findings.
- Excellent analytical, troubleshooting, and communication skills.
- Ability to work effectively in a fast-paced, collaborative environment.
Preferred Qualifications
- Experience with threat intelligence platforms such as Recorded Future, GreyNoise, VirusTotal, Mandiant, or Google Threat Intelligence.
- Experience with security orchestration and automation tools such as Cyware CSAP.
- Previous experience supporting government, public sector, or critical infrastructure environments.
- Industry certifications such as CISSP, GCIH, Security+, GCFA, or GCFE.