1

Cyber Security Incident Handler Jobs (NOW HIRING)

Cybersecurity SOC Analyst

Alpharetta, GA · On-site

$97K - $164K/yr

As a member of Fiserv's Cybersecurity Incident Response Team (CSIRT), you will support ... 2 incident handlers. You will be required to work in a shift which includes work on holidays ...

CSOC CIR Tier II Analyst

Hines, IL · On-site

$79 - $110/hr

... Handler (CSIH) * Certified Incident Handling Engineer (CIHE) * EC-Council's Certified Ethical Hacker Responsibilities * Perform real-time monitoring and triage of security alerts in cybersecurity ...

New

... Handler (CSIH) * Certified Incident Handling Engineer (CIHE) * EC-Council's Certified Ethical Hacker Responsibilities * Perform real-time monitoring and triage of security alerts in Cybersecurity ...

Role Overview We are seeking an experienced Cybersecurity Engineer (Splunk SIEM) to strengthen ... GIAC Certified Incident Handler (GCIH) * Certified Information Systems Security Professional (CISSP)

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST ... Certified Incident Handler, Certified Intrusion Analyst, Certified Ethical Hacker, or similar ...

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST ... Certified Incident Handler, Certified Intrusion Analyst, Certified Ethical Hacker, or similar ...

Showing results 21-40

Cyber Security Incident Handler information

See salary details

$40.5K

$122.9K

$180K

How much do cyber security incident handler jobs pay per year?

As of Aug 20, 2026, the average yearly pay for cyber security incident handler in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What does a Cyber Security Incident Handler do?

A Cyber Security Incident Handler is responsible for managing and responding to security breaches and cyber threats within an organization. Their main duties include identifying, analyzing, and mitigating security incidents, as well as developing procedures to prevent future attacks. They work closely with IT teams to investigate breaches, contain threats, and recover compromised systems. Additionally, they document incidents, report findings to management, and recommend improvements to enhance security posture.

What are the key skills and qualifications needed to thrive as a Cyber Security Incident Handler?

To thrive as a Cyber Security Incident Handler, you need a solid understanding of network security, threat detection, and incident response methodologies, often supported by a degree in cybersecurity or related fields. Familiarity with SIEM tools, forensic analysis software, and certifications such as CISSP or GIAC are typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals respond quickly and coordinate with teams during security incidents. These competencies are crucial for minimizing damage, ensuring rapid recovery, and protecting organizational assets from cyber threats.

What are some common challenges Cyber Security Incident Handlers face during incident response, and how can they effectively manage them?

Cyber Security Incident Handlers often encounter challenges such as rapidly evolving threats, incomplete information during investigations, and the need to coordinate with multiple stakeholders under pressure. Effectively managing these challenges requires strong communication skills, a solid understanding of technical environments, and the ability to prioritize tasks quickly. Utilizing well-established incident response frameworks, maintaining up-to-date documentation, and conducting regular training can help handlers remain prepared and efficient when incidents arise.

What is the difference between Cyber Security Incident Handler vs Cyber Security Analyst?

AspectCyber Security Incident HandlerCyber Security Analyst
CertificationsCompTIA Security+, GIAC GCIH, CISSP (optional)CompTIA Security+, GIAC GCIA, CISSP (optional)
Work EnvironmentResponds to security incidents, investigates breaches, manages incident response teamsMonitors security systems, analyzes threats, develops security strategies
Employer & Industry UsageSecurity teams in various organizations, focusing on incident responseIT security departments across industries, focusing on threat analysis and prevention

While both roles require cybersecurity certifications and involve protecting organizational assets, the Cyber Security Incident Handler primarily responds to and manages security incidents, whereas the Cyber Security Analyst focuses on monitoring, analyzing, and preventing threats proactively.

More about Cyber Security Incident Handler jobs

What cities are hiring for Cyber Security Incident Handler jobs?

Cities with the most Cyber Security Incident Handler job openings:

Infographic showing various Cyber Security Incident Handler job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

Cybersecurity Analyst - Tier 2 (On-Site)

Oxley Enterprises, Inc.

Martinsburg, WV • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 19 days ago


Job description

The following states/districts are excluded from this job ad: AK, CA, CO, CT, DC, HI, IL, LA, MA, MN, MO, NE, NV, NH, NJ, NM, NY, ND, OR, PR, RI, VT, WA, WY

Future Need - Actively Interviewing

Location(s): Capital Region Readiness Center (CRRC) 221 Butler Avenue, Martinsburg, West Virginia, 25405

Are you ready to defend critical systems against today's most advanced cyber threats? We are seeking a Cybersecurity Analyst - Tier 2 to monitor alerts, investigate incidents, and ensure swift, effective responses to protect data and systems.

Position Description: The Cybersecurity Analyst - Tier 2 safeguards the Department of Veterans Affairs (VA) digital assets and responds to, investigates, and mitigates potential cyber threats.

Minimum/General Experience: 3 years of experience supporting incident response in an enterprise-level Security Operations Center (SOC)

Minimum Education: Bachelors degree in computer science, cybersecurity, information technology or related field; Must have or be willing to obtain one of the following certifications: GIAC Certified Incident Handler, EC-Council's Certified Incident Handler (E|CIH), GIAC Certified Incident Handler (GCIH), Incident Handling & Response Professional (IHRP), Certified Computer Security Incident Handler (CSIH), Certified Incident Handling Engineer (CIHE), EC-Council's Certified Ethical Hacker

Essential Skills/Qualifications:

  • Above average understanding of cybersecurity principles and incident response methodologies
  • Strong experience with security technologies (e.g., Security Information and Event Management (SIEM), Intrusion Detection System/Intrusion Prevention System (IDS/IPS), Endpoint Detection and Response (EDR), network monitoring tools)
  • Experience with enterprise ticketing systems (e.g., ServiceNow)
  • Ability to work independently and in a team environment to identify errors, pinpoint root causes, and devise solutions
  • Ability to learn and function in multiple capacities
  • Ability to be proactive in a high-pressure environment to ensure SOC operates effectively
  • Excellent analytical and problem-solving skills
  • Excellent verbal and written communication skills
  • Ability to work third shift (10:30PM ET - 7:00AM ET) to support 24/7 cybersecurity operations

General Physical Requirements needed to perform the essential functions of this job may vary based on the location of the assignment.

  • Assignment Location(s) - Capital Region Readiness Center (CRRC) 221 Butler Avenue, Martinsburg, West Virginia, 25405
  • Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.
  • Typing, communicating, repetitive motions.
  • Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting.
  • Inside environmental conditions with protection from outside elements.

Security: Ability to obtain/maintain a Federal Civilian Public Trust

  • U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years

Federal Civilian Public Trust Consists of a review of up to but not limited to:

  • Covers 10 year period and in some instances lifetime events
  • OPM Security Investigations Index (SII)
  • DOD Defense Central Investigations Index (DCII)
  • National Agency Check (NAC) records
  • FBI name check
  • FBI fingerprint check
  • Credit report check
  • Written inquiries to previous employers and references listed on the application for employment
  • Potential interviews with the subject, spouse, neighbors, supervisor, coworkers
  • Law enforcement check
  • Court records check
  • Education check- Attendance and Degrees

Acceptable Credentials

Tasks/activities include, but are not limited to:

  • Performs real-time monitoring and triage of security alerts in Cybersecurity toolsets including SIEM and EDR
  • Makes accurate determination of what alerts are false positives or require further investigation and prioritization
  • Leads and actively participates in the investigation, analysis, and resolution of cybersecurity incidents
  • Analyzes attack patterns, determines the root cause, and recommends appropriate remediation measures to prevent future occurrences
  • Ensures accurate and detailed documentation of incident response activities, including analysis, actions taken, and lessons learned
  • Collaborates with knowledge management teams to maintain up-to-date incident response playbooks
  • Collaborates effectively with cross-functional teams, including forensics, threat intelligence, IT, and network administrators
  • Communicates clear technical information and incident-related updates to management and stakeholders
  • Identifies and actions opportunities for tuning alerts to make the incident response team more efficient
  • Monitors the performance of security analytics and automation processes regularly, identifying areas for improvement and taking proactive measures to enhance their efficacy
  • Leverages Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate incident response processes, including enrichment, containment, and remediation actions
  • Supports the mentoring and training of more junior incident response staff
  • Stays informed about the latest cybersecurity threats, trends, and best practices
  • Participates in cybersecurity exercises, drills, and simulations to improve incident response capabilities

Compensation & Benefits: The annual projected pay range for this position is $92,490.00 - $102,790.00 with consideration being given to various factors including but not limited to qualifications, experience, job responsibilities, and geographic location.

Oxley Enterprises, Inc. offers a full array of benefits including:

  • Medical, dental, vision and prescription drug coverage for you and your family.
  • Life Insurance, short-term disability and long-term disability paid for by the Company.
  • Supplemental coverages including Accident, Critical Illness, and Hospital.
  • Additional Life insurance coverage for you and your dependents.
  • 401k plan with various options to select based on your retirement goals.

Oxley Enterprises, Inc. is a certified service-disabled veteran-owned (SDVOSB), veteran-owned (VOSB), and woman-owned small business (WOSB) that has 26 years of experience building and delivering quality IT systems and programs. Oxley is ranked in the INC 5000 7 times (2016, 2017, 2018, 2021, 2023, 2024, 2025). Oxley is a 2019 - 2025 Department of Labor HIRE Vets Medallion Award Winner. Oxley is Virginia Values Veterans certified.

All qualified applicants will receive consideration for employment without regard to any status protected by applicable federal, state, or local law.

If you require a reasonable accommodation to apply for a position at Oxley Enterprises, Inc., please send an email to our Human Resources Department at: careers@oxleyenterprises.com with the following information:

Subject Line: Accommodation Request

Provide a description of your accommodation request

Include your contact information: Full name, Email address, Best number to reach you (optional)

We participate in the E-Verify program. http://www.dhs.gov/E-Verify