1

Cyber Incident Response Analyst Jobs (NOW HIRING)

What we'll want you to have: * 8+ years of cyber incident response experience in a large and ... Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files ...

Principal Incident Response Analyst

SC Β· Remote

$101K - $132K/yr

What we'll want you to have: * 8+ years of cyber incident response experience in a large and ... Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files ...

What we'll want you to have: * 8+ years of cyber incident response experience in a large and ... Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files ...

Incident Response Analyst

Alexandria, VA Β· On-site

$87K - $157K/yr

Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation. * Experience performing analysis of cybersecurity events ...

Incident Response Analyst

Seaside, CA Β· On-site

$87K - $157K/yr

Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation. * Experience performing analysis of cybersecurity events ...

Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation. * Experience performing analysis of cybersecurity events ...

Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation * Experience analyzing cybersecurity events and ...

Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation. * Experience performing analysis of cybersecurity events ...

Showing results 21-40

Cyber Incident Response Analyst information

See salary details

$22

$46

$62

How much do cyber incident response analyst jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for cyber incident response analyst in the United States is $46.45, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $52.64 per hour, depending on experience, location, and employer.

What does a Cyber Incident Response Analyst do?

A Cyber Incident Response Analyst is responsible for detecting, investigating, and responding to security incidents within an organization’s computer systems and networks. They monitor security alerts, analyze potential threats, and take action to contain and mitigate breaches. Their role often includes conducting forensic analysis, developing incident response plans, and working to improve an organization’s cybersecurity posture. They also document incidents and recommend measures to prevent future attacks.

What are the key skills and qualifications needed to thrive as a Cyber Incident Response Analyst?

To thrive as a Cyber Incident Response Analyst, you need a strong understanding of cybersecurity principles, threat analysis, and incident management, often supported by a degree in computer science or information security and relevant certifications like CISSP or GIAC. Familiarity with security information and event management (SIEM) tools, forensic software, and network monitoring systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you quickly identify, analyze, and respond to security breaches. These skills are critical to minimizing damage, protecting sensitive data, and maintaining organizational resilience against cyber threats.

What are some common challenges Cyber Incident Response Analysts face when handling security incidents?

Cyber Incident Response Analysts often face the challenge of responding to incidents in real-time, which can require making quick decisions under pressure. They must also sift through large volumes of logs and data to identify the root cause of incidents, which can be both time-consuming and complex. Coordinating with other teams, such as IT and legal, is crucial to contain threats while ensuring business continuity and regulatory compliance. Staying current with evolving threats and maintaining readiness for emerging attack techniques are ongoing aspects of the role.

What is the difference between Cyber Incident Response Analyst vs Security Analyst?

AspectCyber Incident Response AnalystSecurity Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, CISSP, CEH (sometimes)
Work EnvironmentIncident response teams, cybersecurity operations centersSecurity operations centers, IT departments
Employer & IndustryFinancial, healthcare, government, tech firmsBroad industry, including finance, retail, tech
Primary FocusResponding to security incidents, analyzing breachesMonitoring security systems, vulnerability management

While both roles focus on cybersecurity, the Cyber Incident Response Analyst specializes in responding to and investigating security incidents, whereas the Security Analyst primarily monitors and manages overall security systems. The Incident Response Analyst acts swiftly during breaches, while the Security Analyst maintains ongoing security posture.

More about Cyber Incident Response Analyst jobs

What cities are hiring for Cyber Incident Response Analyst jobs?

Cities with the most Cyber Incident Response Analyst job openings:

What states have the most Cyber Incident Response Analyst jobs?

States with the most job openings for Cyber Incident Response Analyst jobs include:

What are popular job titles related to Cyber Incident Response Analyst jobs?

For Cyber Incident Response Analyst jobs, the most frequently searched job titles are:

Infographic showing various Cyber Incident Response Analyst job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 50% In-person, and 50% Remote job distribution, with an average salary of $96,618 per year, or $46.5 per hour.

Cyber Incident Response Analyst II

Cleveland, OH β€’ Hybrid

AmTrust Financial Services, Inc.
Insurance ServicesΒ β€’Β 5 - 10K employees

Full-time

Medical, Dental, Life, Retirement, PTO

This job post hasΒ expired 3 days ago.Β Applications are no longer accepted.


Job description

Overview

The Cyber Security Incident Response II is responsible for detecting, analyzing, investigating, and responding to cybersecurity threats and incidents across the enterprise. This role performs advanced threat detection, incident triage, forensic analysis, containment, and recovery activities coordinated across internal and external stakeholders.

The ideal candidate possesses a strong foundation in cyber security incident response, digital forensics, detection capabilities, and stakeholder engagement. This position requires the ability to independently manage complex cybersecurity incidents, collaborate effectively with business and technical teams, influence decision-making through risk-based recommendations, and perform successfully in time-sensitive and high-pressure environments.

This role partners with third-party service providers, vendors, infrastructure teams, and security engineering and architecture teams to strengthen the organization's security posture and improve incident response capabilities. The candidate will maintain a strong understanding of AmTrust's mission, vision, and values while upholding the highest standards of professionalism and service.

Responsibilities
  • Investigate security alerts, suspicious activity, and cybersecurity incidents to determine scope, impact, root cause, and remediation actions.
  • Lead the analysis and response efforts for medium- to high-complexity security incidents, ensuring timely containment, eradication, recovery, and documentation.
  • Perform digital forensics, log analysis, artifact collection and preservation, and host and network investigations using enterprise security monitoring and endpoint detection tools.
  • Analyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and threat intelligence to support investigations.
  • Utilize SIEM, EDR, threat intelligence, cloud security, and case management platforms to investigate and respond to security incidents.
  • Develop and maintain detection logic, correlation rules, analytics, and response playbooks to improve detection and response capabilities.
  • Document investigation findings, incident timelines, root cause analysis, and lessons learned in accordance with established procedures.
  • Collaborate with IT, Security, Legal, Risk, HR, and Compliance teams as required during incident investigations.
  • Participate in tabletop exercises, incident response simulations, and post-incident reviews to validate and improve response readiness.
  • Recommend improvements to security controls, detection content, monitoring coverage, and response processes based on investigative findings.
  • Participate in on-call and after-hours incident response support as required.
Qualifications
  • Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field. Equivalent practical experience may be considered in lieu of a degree.
  • 3-5+ years of experience in cyber security incident response, digital forensics, security operations, threat hunting, or related cyber security disciplines.
  • Experience investigating and responding to security incidents in enterprise environments.
  • Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks.
  • Experience working with security monitoring technologies, including SIEM, EDR/XDR, email security, identity security, and cloud security platforms.
  • Ability to manage multiple investigations while maintaining attention to detail and documentation quality.
  • Strong analytical, problem solving, written, and verbal communication skills.
  • Ability to effectively communicate technical findings and risk-based recommendations to both technical and non-technical audiences.
  • Proven ability to work independently, manage competing priorities, and perform effectively in fast-paced, high-pressure environments.

Preferred:

  • Industry certifications such as Security+, CySA+, SecurityX (formerly CASP+) GCIH, GCFA, GCIA, GNFA, CISSP, or other relevant cybersecurity certifications.
  • Experience investigating incidents across hybrid environments.
  • Experience conducting malware analysis, memory analysis, and digital forensic investigations.
  • Knowledge of scripting, automation, and query languages such as PowerShell, Python, KQL, SPL, or similar languages.
  • Experience operating in highly regulated industries and familiarity with applicable cybersecurity regulatory requirements.
What We Offer

AmTrust Financial Services offers a competitive compensation package and excellent career advancement opportunities. Our benefits include Medical & Dental Plans, Life Insurance, including eligible spouses & children, Health Care Flexible Spending, Dependent Care, 401k Savings Plans, Paid Time Off.

AmTrust strives to create a diverse and inclusive culture where thoughts and ideas of all employees are appreciated and respected. This concept encompasses but is not limited to human differences with regard to race, ethnicity, gender, sexual orientation, culture, religion or disabilities.

AmTrust values excellence and recognizes that by embracing the diverse backgrounds, skills, and perspectives of its workforce, it will sustain a competitive advantage and remain an employer of choice. Diversity is a business imperative, enabling us to attract, retain and develop the best talent available. We see diversity as more than just policies and practices. It is an integral part of who we are as a company, how we operate and how we see our future.

Employment Type: FULL_TIME