1

Cyber Incident Response Jobs (NOW HIRING)

ASMGi - Cyber Incident Response Analyst General Summary: As a key member of ASMGi's Information Security Incident Response Team this individual will be responsible for various parts of the incident ...

next page

Showing results 1-20

Cyber Incident Response information

See salary details

$41K

$127.2K

$199.5K

How much do cyber incident response jobs pay per year?

As of Jul 27, 2026, the average yearly pay for cyber incident response in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is a Cyber Incident Response job?

A Cyber Incident Response job involves identifying, analyzing, and mitigating security incidents to protect an organization's digital assets. Professionals in this role monitor systems for threats, investigate breaches, and coordinate responses to minimize damage. They also develop incident response plans, conduct forensic analysis, and work to improve security defenses. Strong analytical skills, knowledge of cybersecurity tools, and the ability to act quickly under pressure are essential for success in this field.

What are the key skills and qualifications needed to thrive in the Cyber Incident Response position, and why are they important?

To thrive in Cyber Incident Response, you need a strong understanding of network security, threat analysis, operating systems, and incident response procedures, typically backed by a degree in cybersecurity, information technology, or a related field. Familiarity with SIEM tools, forensic analysis platforms, and recognized certifications such as CISSP, CEH, or GIAC is often required. Excellent communication, problem-solving skills, and the ability to remain calm under pressure distinguish top performers in this area. These abilities are crucial to quickly detect, investigate, and mitigate security incidents while ensuring clear coordination with internal teams and stakeholders.

What are the typical daily responsibilities of someone working in Cyber Incident Response?

Professionals in Cyber Incident Response spend their days monitoring security alerts, investigating potential breaches, analyzing suspicious activity, and documenting their findings. They use specialized tools to detect, respond to, and recover from cyber threats in real-time, and may also conduct forensic analysis to determine the root cause of incidents. Regular collaboration with IT, legal, and management teams is essential to craft and execute effective remediation plans. The role often requires quick thinking and adaptability, as new and sophisticated threats may arise unexpectedly. This makes every day dynamic, with opportunities to continually learn and grow within the cybersecurity field.

More about Cyber Incident Response jobs
What cities are hiring for Cyber Incident Response jobs? Cities with the most Cyber Incident Response job openings:
What are the most commonly searched types of Cyber Incident Response jobs? The most popular types of Cyber Incident Response jobs are:
What states have the most Cyber Incident Response jobs? States with the most job openings for Cyber Incident Response jobs include:
Infographic showing various Cyber Incident Response job openings in the United States as of July 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.
Cyber Incident Response Analyst

Cyber Incident Response Analyst

3B Staffing LLC

Austin, TX โ€ข On-site

Contractor

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Cyber Incident Response Analyst Location: Austin, TX / San Antonio, TX (Onsite) Duration: 12 Months Contract Interview: Onsite Cyber Incident Response, Digital Forensics, Windows & Linux Security, SIEM, EDR, IDS/IPS, Threat Hunting, Malware Analysis, Memory & Disk Forensics, MITRE ATT&CK, CrowdStrike, SentinelOne, Microsoft Sentinel, NetWitness, Corelight, Gravwell, Google SecOps, Incident Command, Threat Intelligence, Security Operations (SOC). Job Description We are seeking an experienced Cyber Incident Response Analyst to join our cybersecurity team. The ideal candidate will be responsible for investigating and responding to cybersecurity incidents, conducting forensic analysis, and collaborating with internal teams to protect critical systems and infrastructure. This role requires strong analytical skills, hands-on experience with incident response tools, and the ability to communicate technical findings to both technical and non-technical stakeholders. Responsibilities
  • Perform incident response activities, including triage, investigation, containment, eradication, and recovery.
  • Conduct host-based forensic investigations across Windows and Linux environments.
  • Analyze logs, memory, file systems, and malware to determine the scope and impact of security incidents.
  • Monitor and investigate alerts from SIEM, EDR, IDS/IPS, and network monitoring tools.
  • Correlate endpoint, network, and threat intelligence data to identify attack patterns and build incident timelines.
  • Serve as the Incident Commander during major cybersecurity events when required.
  • Analyze attacker tactics, techniques, and procedures (TTPs) and map findings to the MITRE ATT&CK framework.
  • Prepare detailed incident reports, executive summaries, and technical documentation.
  • Collaborate with cross-functional teams to improve detection capabilities and strengthen security controls.
  • Participate in post-incident reviews and contribute to updating incident response playbooks.
  • Provide on-call support for critical security incidents as needed.
Required Qualifications
  • 5+ years of experience in Cybersecurity Incident Response, Security Operations, or Digital Forensics.
  • Strong experience with Windows and Linux incident response and forensic investigations.
  • Hands-on experience with SIEM, EDR, IDS/IPS, and security monitoring platforms.
  • Experience using tools such as CrowdStrike, SentinelOne, Microsoft Sentinel, NetWitness, Corelight, Gravwell, or Google SecOps.
  • Knowledge of malware analysis, memory analysis, and digital forensic techniques.
  • Strong understanding of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies.
  • Experience producing incident reports and documenting technical findings.
  • Excellent analytical, troubleshooting, and communication skills.
  • Ability to work effectively in a fast-paced, collaborative environment.
Preferred Qualifications
  • Experience with threat intelligence platforms such as Recorded Future, GreyNoise, VirusTotal, Mandiant, or Google Threat Intelligence.
  • Experience with security orchestration and automation tools such as Cyware CSAP.
  • Previous experience supporting government, public sector, or critical infrastructure environments.
  • Industry certifications such as CISSP, GCIH, Security+, GCFA, or GCFE.