Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks. * Experience working with security monitoring technologies ...
Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks. * Experience working with security monitoring technologies ...
Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
Quick apply
Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks. * Experience working with security monitoring technologies ...
Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks. * Experience working with security monitoring technologies ...
Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks. * Experience working with security monitoring technologies ...
Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks. * Experience working with security monitoring technologies ...
The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding cybersecurity ...
Quick apply
The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding cybersecurity ...
Cyber Incident Response Analyst- Junior
$83K - $87K/yr
The Work The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
Cyber Incident Response Analyst- Junior
$83K - $87K/yr
The Work The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
The Work The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
Quick apply
The Work The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
Cyber Incident Response Analyst- Junior
$83K - $87K/yr
The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding cybersecurity ...
Cyber Incident Response Analyst- Junior
$83K - $87K/yr
The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding cybersecurity ...
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
The Work The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
The Work The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding ...
Cyber Incident Response Analyst- Junior
Washington, DC · On-site
$83K - $87K/yr
The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding cybersecurity ...
Cyber Incident Response Analyst- Junior
Washington, DC · On-site
$83K - $87K/yr
The Cyber Incident Response Analyst role is pivotal in reinforcing the client's cybersecurity framework by serving as the primary entry point for all external communications regarding cybersecurity ...
Manager, Incident Response
Austin, TX · On-site
Lead and manage cyber incident response activities, including triage, containment, eradication, and recovery efforts for client incidents * Oversee and coordinate incident investigations across cyber ...
Manager, Incident Response
Austin, TX · On-site
Lead and manage cyber incident response activities, including triage, containment, eradication, and recovery efforts for client incidents * Oversee and coordinate incident investigations across cyber ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
Senior Cyber Incident Response Attorney
New York, NY · On-site +1
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
Senior Cyber Incident Response Attorney
New York, NY · On-site +1
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines * Coordinate with JFHQ-DODIN on cyber incident reporting and remediation * Support insider threat response ...
Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines * Coordinate with JFHQ-DODIN on cyber incident reporting and remediation * Support insider threat response ...
Senior Cyber Incident Response Attorney
Miami, FL · On-site +1
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
Senior Cyber Incident Response Attorney
Miami, FL · On-site +1
If you are a motivated professional looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Senior Cyber Incident Response ...
Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines * Coordinate with JFHQ-DODIN on cyber incident reporting and remediation * Support insider threat response ...
Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines * Coordinate with JFHQ-DODIN on cyber incident reporting and remediation * Support insider threat response ...
... Cyber and Key Resources. * Evaluating current information and develop responses to critical ... incident. * Other duties as assigned. Qualifications * Bachelor's Degree in a related discipline ...
... Cyber and Key Resources. * Evaluating current information and develop responses to critical ... incident. * Other duties as assigned. Qualifications * Bachelor's Degree in a related discipline ...
Cyber Incident Response information
See salary details
$41K - $55.4K
6% of jobs
$55.4K - $69.8K
7% of jobs
$69.8K - $84.2K
6% of jobs
$87.6K is the 25th percentile. Wages below this are outliers.
$84.2K - $98.6K
21% of jobs
$98.6K - $113K
7% of jobs
The median wage is $118.4K / yr.
$113K - $127.5K
4% of jobs
$127.5K - $141.9K
3% of jobs
$141.9K - $156.3K
7% of jobs
$167.9K is the 75th percentile. Wages above this are outliers.
$156.3K - $170.7K
15% of jobs
$170.7K - $185.1K
19% of jobs
$185.1K - $199.5K
3% of jobs
$41K
$127.2K
$199.5K
How much do cyber incident response jobs pay per year?
What is a cyber incident response?
A Cyber Incident Response job involves identifying, analyzing, and mitigating security incidents to protect an organization's digital assets. Professionals in this role monitor systems for threats, investigate breaches, and coordinate responses to minimize damage. They also develop incident response plans, conduct forensic analysis, and work to improve security defenses. Strong analytical skills, knowledge of cybersecurity tools, and the ability to act quickly under pressure are essential for success in this field.
What does a cyber incident response professional do?
Professionals in Cyber Incident Response spend their days monitoring security alerts, investigating potential breaches, analyzing suspicious activity, and documenting their findings. They use specialized tools to detect, respond to, and recover from cyber threats in real-time, and may also conduct forensic analysis to determine the root cause of incidents. Regular collaboration with IT, legal, and management teams is essential to craft and execute effective remediation plans. The role often requires quick thinking and adaptability, as new and sophisticated threats may arise unexpectedly. This makes every day dynamic, with opportunities to continually learn and grow within the cybersecurity field.
What are the key skills and qualifications needed for cyber incident response?
To thrive in Cyber Incident Response, you need a strong understanding of network security, threat analysis, operating systems, and incident response procedures, typically backed by a degree in cybersecurity, information technology, or a related field. Familiarity with SIEM tools, forensic analysis platforms, and recognized certifications such as CISSP, CEH, or GIAC is often required. Excellent communication, problem-solving skills, and the ability to remain calm under pressure distinguish top performers in this area. These abilities are crucial to quickly detect, investigate, and mitigate security incidents while ensuring clear coordination with internal teams and stakeholders.
What cities are hiring for Cyber Incident Response jobs?
Cities with the most Cyber Incident Response job openings:
What are the most commonly searched types of Cyber Incident Response jobs?
The most popular types of Cyber Incident Response jobs are:
What states have the most Cyber Incident Response jobs?
States with the most job openings for Cyber Incident Response jobs include:
What job categories do people searching Cyber Incident Response jobs look for?
The top searched job categories for Cyber Incident Response jobs are:

Full-time
Medical, Dental, Life, Retirement, PTO
Posted 20 days ago
Job description
The Cyber Security Incident Response II is responsible for detecting, analyzing, investigating, and responding to cybersecurity threats and incidents across the enterprise. This role performs advanced threat detection, incident triage, forensic analysis, containment, and recovery activities coordinated across internal and external stakeholders.
The ideal candidate possesses a strong foundation in cyber security incident response, digital forensics, detection capabilities, and stakeholder engagement. This position requires the ability to independently manage complex cybersecurity incidents, collaborate effectively with business and technical teams, influence decision-making through risk-based recommendations, and perform successfully in time-sensitive and high-pressure environments.
This role partners with third-party service providers, vendors, infrastructure teams, and security engineering and architecture teams to strengthen the organization's security posture and improve incident response capabilities. The candidate will maintain a strong understanding of AmTrust's mission, vision, and values while upholding the highest standards of professionalism and service.
- Investigate security alerts, suspicious activity, and cybersecurity incidents to determine scope, impact, root cause, and remediation actions.
- Lead the analysis and response efforts for medium- to high-complexity security incidents, ensuring timely containment, eradication, recovery, and documentation.
- Perform digital forensics, log analysis, artifact collection and preservation, and host and network investigations using enterprise security monitoring and endpoint detection tools.
- Analyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and threat intelligence to support investigations.
- Utilize SIEM, EDR, threat intelligence, cloud security, and case management platforms to investigate and respond to security incidents.
- Develop and maintain detection logic, correlation rules, analytics, and response playbooks to improve detection and response capabilities.
- Document investigation findings, incident timelines, root cause analysis, and lessons learned in accordance with established procedures.
- Collaborate with IT, Security, Legal, Risk, HR, and Compliance teams as required during incident investigations.
- Participate in tabletop exercises, incident response simulations, and post-incident reviews to validate and improve response readiness.
- Recommend improvements to security controls, detection content, monitoring coverage, and response processes based on investigative findings.
- Participate in on-call and after-hours incident response support as required.
- Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field. Equivalent practical experience may be considered in lieu of a degree.
- 3-5+ years of experience in cyber security incident response, digital forensics, security operations, threat hunting, or related cyber security disciplines.
- Experience investigating and responding to security incidents in enterprise environments.
- Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks.
- Experience working with security monitoring technologies, including SIEM, EDR/XDR, email security, identity security, and cloud security platforms.
- Ability to manage multiple investigations while maintaining attention to detail and documentation quality.
- Strong analytical, problem solving, written, and verbal communication skills.
- Ability to effectively communicate technical findings and risk-based recommendations to both technical and non-technical audiences.
- Proven ability to work independently, manage competing priorities, and perform effectively in fast-paced, high-pressure environments.
Preferred:
- Industry certifications such as Security+, CySA+, SecurityX (formerly CASP+) GCIH, GCFA, GCIA, GNFA, CISSP, or other relevant cybersecurity certifications.
- Experience investigating incidents across hybrid environments.
- Experience conducting malware analysis, memory analysis, and digital forensic investigations.
- Knowledge of scripting, automation, and query languages such as PowerShell, Python, KQL, SPL, or similar languages.
- Experience operating in highly regulated industries and familiarity with applicable cybersecurity regulatory requirements.
AmTrust Financial Services offers a competitive compensation package and excellent career advancement opportunities. Our benefits include: Medical & Dental Plans, Life Insurance, including eligible spouses & children, Health Care Flexible Spending, Dependent Care, 401k Savings Plans, Paid Time Off.
AmTrust strives to create a diverse and inclusive culture where thoughts and ideas of all employees are appreciated and respected. This concept encompasses but is not limited to human differences with regard to race, ethnicity, gender, sexual orientation, culture, religion or disabilities.
AmTrust values excellence and recognizes that by embracing the diverse backgrounds, skills, and perspectives of its workforce, it will sustain a competitive advantage and remain an employer of choice. Diversity is a business imperative, enabling us to attract, retain and develop the best talent available. We see diversity as more than just policies and practices. It is an integral part of who we are as a company, how we operate and how we see our future.
About AmTrust Financial Services
Sourced by ZipRecruiter
Industry
Insurance services
Company size
5,001 - 10,000 Employees
Headquarters location
New York, NY, US
Year founded
1998