1

Cyber Incident Response Analyst Jobs (NOW HIRING)

ASMGi - Cyber Incident Response Analyst General Summary: As a key member of ASMGi's Information Security Incident Response Team this individual will be responsible for various parts of the incident ...

The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...

The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...

next page

Showing results 1-20

Cyber Incident Response Analyst information

See salary details

$22

$46

$62

How much do cyber incident response analyst jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for cyber incident response analyst in the United States is $46.45, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $52.64 per hour, depending on experience, location, and employer.

What does a Cyber Incident Response Analyst do?

A Cyber Incident Response Analyst is responsible for detecting, investigating, and responding to security incidents within an organization’s computer systems and networks. They monitor security alerts, analyze potential threats, and take action to contain and mitigate breaches. Their role often includes conducting forensic analysis, developing incident response plans, and working to improve an organization’s cybersecurity posture. They also document incidents and recommend measures to prevent future attacks.

What are the key skills and qualifications needed to thrive as a Cyber Incident Response Analyst?

To thrive as a Cyber Incident Response Analyst, you need a strong understanding of cybersecurity principles, threat analysis, and incident management, often supported by a degree in computer science or information security and relevant certifications like CISSP or GIAC. Familiarity with security information and event management (SIEM) tools, forensic software, and network monitoring systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you quickly identify, analyze, and respond to security breaches. These skills are critical to minimizing damage, protecting sensitive data, and maintaining organizational resilience against cyber threats.

What are some common challenges Cyber Incident Response Analysts face when handling security incidents?

Cyber Incident Response Analysts often face the challenge of responding to incidents in real-time, which can require making quick decisions under pressure. They must also sift through large volumes of logs and data to identify the root cause of incidents, which can be both time-consuming and complex. Coordinating with other teams, such as IT and legal, is crucial to contain threats while ensuring business continuity and regulatory compliance. Staying current with evolving threats and maintaining readiness for emerging attack techniques are ongoing aspects of the role.

What is the difference between Cyber Incident Response Analyst vs Security Analyst?

AspectCyber Incident Response AnalystSecurity Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, CISSP, CEH (sometimes)
Work EnvironmentIncident response teams, cybersecurity operations centersSecurity operations centers, IT departments
Employer & IndustryFinancial, healthcare, government, tech firmsBroad industry, including finance, retail, tech
Primary FocusResponding to security incidents, analyzing breachesMonitoring security systems, vulnerability management

While both roles focus on cybersecurity, the Cyber Incident Response Analyst specializes in responding to and investigating security incidents, whereas the Security Analyst primarily monitors and manages overall security systems. The Incident Response Analyst acts swiftly during breaches, while the Security Analyst maintains ongoing security posture.

More about Cyber Incident Response Analyst jobs

What cities are hiring for Cyber Incident Response Analyst jobs?

Cities with the most Cyber Incident Response Analyst job openings:

What states have the most Cyber Incident Response Analyst jobs?

States with the most job openings for Cyber Incident Response Analyst jobs include:

What are popular job titles related to Cyber Incident Response Analyst jobs?

For Cyber Incident Response Analyst jobs, the most frequently searched job titles are:

Infographic showing various Cyber Incident Response Analyst job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 50% In-person, and 50% Remote job distribution, with an average salary of $96,618 per year, or $46.5 per hour.

Cyber Incident Response Analyst

Cleveland, OH • On-site

ASMGi
IT Services • 51 - 200 employees

Full-time

Re-posted 3 days ago


Job description

ASMGi - Cyber Incident Response Analyst
General Summary:
As a key member of ASMGi’s Information Security Incident Response Team this individual will be responsible for various parts of the incident response process - detection, validation, containment, remediation, and communication - for IT based security events and incidents impacting ASMGi’s clients.
This individual will be responsible for the rapid response and resolution of security incidents including the ASMGi MDR / MSOC plus client’s environments. This will involve coordinating with teams including Legal, Security Operations and Forensics experts, internal or external, to identify root cause, restore services and communicate status to affected stakeholders.
This role will act as the escalation path for the ASMGi Operations Team to validate findings and identify scope of events and support during larger investigations. This individual will act as an internal and client facing resource while interacting with the third-party Security Operations Center as applicable.
Principal Accountabilities:
25% - Client Incident Response Onboarding and Program Development.
  • Work with ASMGi MDR / MSOC plus Service clients as part of the overall service and specifically the Incident Response Program Development including Incident Response Policy, Incident Response Plan, and Incident Response Playbook development and adoption.
  • Conduct client Tabletop Exercises on an annual basis based on the adopted Incident Response Playbook as part of the ASMGi MDR / MSOC plus Incident Response Service.
50% - Incident Response
  • Perform Level 2 and Level 3 computer security incident response activities including coordinating with the Security Operations Center and Forensics experts, internal and external.
  • Analyze, track and triage anomalies that have been escalated to ensure appropriate identification of risk to ASMGi MDR / MSOC plus clients.
  • Oversee the forensic analysis of cybersecurity incidents impacting ASMGi MDR / MSOC plus clients.
  • Understand and research emerging threats and current trends that may impact customers along with mitigation/resolutions for such threats.
  • Communicate and coordinate response efforts including working with ASMGi MDR / MSOC plus client’s I.T., Business Leaders, and Third Parties to mitigate the impact of the risk and provide a lead role as part of the ASMGi Computer Security Incident Response Team (CSIRT).
  • Prepare incident reports of analysis and methodology and results of investigation to be submitted to ASMGi MDR / MSOC plus clients.
25% - Assist with Incident Management Strategy Development, Consulting and Management of Third-Party Security Operations Center.
  • Leverage lessons learned, threat modeling and emerging industry better practice, to analyze the effectiveness of the existing program (policies, technology, and awareness) to continuously improve the Incident Management Program.
  • Review industry frameworks, emerging threats, and best practice to advance the ASMGi MDR / MSOC plus Service.
  • Partner with ASMGi partners and internal groups to improve the ASMGi MDR / MSOC plus service and capabilities.
  • Assist with management of third-party business relationships for the security operations center and service levels. Identify potential gaps including procedures needed to mitigate risk and assist with appropriate solutions.
Job Complexity
  • Appropriately balances security risk and business impact to ensure that ASMGi’s use of detection/response controls are effective.
  • Ability to build operational processes using industry best-practice that are tailored to the ASMGi MDR / MSOC plus client’s organization, system, and processes.
  • Ability to effectively communicate risk including corrective action plans/recommendations to non-technical audiences including the ASMGi MDR / MSOC plus client’s Executives and the Board of Directors leveraging the MDR / MSOC plus service.
  • Ability to create effective reports and presentations tailored to different audiences to ensure transparency and understanding of the ASMGi MDR / MSOC plus Service.
  • Assist with development of MDR / MSOC plus Service roadmap.
Job Specifications
Minimum education required: Bachelor's Degree Required
Education desired: Bachelor of Science
Years of relevant experience: 7 – 10 +
Knowledge, skills, and abilities required:
  • High level of technical expertise in information security, including deep familiarity with relevant penetration and intrusion techniques and attack vectors.
  • Cybersecurity in large complex companies including knowledge of security and privacy breach laws and regulatory reporting.
  • Proven experience working with Security Operations Center services, forensics firms.
  • Demonstrated ability to lead and develop cohesive and collaborative management and operational teams internally and with a third-party.
  • Proven experience implementing policies, procedures, and technology to detect and recover from a cybersecurity attack.
  • Ability to demonstrate strong computer knowledge networks, desktops, servers, cloud, and software as a service technology.
  • Expertise with next generation firewalls, Endpoint Detection and Response, Microsoft Advanced Threat Protection, Azure, and Office 365, Zero Day Threat Detection Technology, Threat Intelligence Feeds, Forensics, Data Loss Prevention Software, Web Proxies, Web Application Firewalls.
  • Strong problem-solving and trouble-shooting skills.
  • Strong communication skills including writing reports and presenting to senior executives.
  • Demonstrated connections to external Incident Response leaders and learning organizations.
Working Conditions
  • Normal corporate office environment and remote / virtual based on COVID-19.
  • On call work is required.