1

Cyber Security Incident Handler Jobs (NOW HIRING)

Senior Incident Handler

Chicago, IL · On-site

$18.25 - $22.25/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security ... Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, witha track ...

Senior Incident Handler

$18.25 - $22/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security ... Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, witha track ...

IL · On-site

$93K - $103K/yr

The Cybersecurity Analyst - Tier 2 safeguards the Department of Veterans Affairs (VA) digital ... GIAC Certified Incident Handler, EC-Council's Certified Incident Handler (E|CIH), GIAC Certified ...

Senior Incident Handler

$18.25 - $22/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security ... Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a ...

$73K - $95K/yr

Cybersecurity Analyst/Incident Handler - Senior Level - Top SECRET/ ONSITE * Information Technology Visual Soft, Inc is seeking qualified candidates (US Citizens with active ACTIVE TOP SECRET ...

New

Incident Responder

Suitland, MD · On-site

$107K - $195K/yr

Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council ...

Incident Responder

Suitland, MD · On-site

$107K - $195K/yr

Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council ...

Showing results 21-40

Cyber Security Incident Handler information

See salary details

$40.5K

$122.9K

$180K

How much do cyber security incident handler jobs pay per year?

As of Sep 10, 2026, the average yearly pay for cyber security incident handler in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What does a Cyber Security Incident Handler do?

A Cyber Security Incident Handler is responsible for managing and responding to security breaches and cyber threats within an organization. Their main duties include identifying, analyzing, and mitigating security incidents, as well as developing procedures to prevent future attacks. They work closely with IT teams to investigate breaches, contain threats, and recover compromised systems. Additionally, they document incidents, report findings to management, and recommend improvements to enhance security posture.

What are the key skills and qualifications needed to thrive as a Cyber Security Incident Handler?

To thrive as a Cyber Security Incident Handler, you need a solid understanding of network security, threat detection, and incident response methodologies, often supported by a degree in cybersecurity or related fields. Familiarity with SIEM tools, forensic analysis software, and certifications such as CISSP or GIAC are typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals respond quickly and coordinate with teams during security incidents. These competencies are crucial for minimizing damage, ensuring rapid recovery, and protecting organizational assets from cyber threats.

What are some common challenges Cyber Security Incident Handlers face during incident response, and how can they effectively manage them?

Cyber Security Incident Handlers often encounter challenges such as rapidly evolving threats, incomplete information during investigations, and the need to coordinate with multiple stakeholders under pressure. Effectively managing these challenges requires strong communication skills, a solid understanding of technical environments, and the ability to prioritize tasks quickly. Utilizing well-established incident response frameworks, maintaining up-to-date documentation, and conducting regular training can help handlers remain prepared and efficient when incidents arise.

What is the difference between Cyber Security Incident Handler vs Cyber Security Analyst?

AspectCyber Security Incident HandlerCyber Security Analyst
CertificationsCompTIA Security+, GIAC GCIH, CISSP (optional)CompTIA Security+, GIAC GCIA, CISSP (optional)
Work EnvironmentResponds to security incidents, investigates breaches, manages incident response teamsMonitors security systems, analyzes threats, develops security strategies
Employer & Industry UsageSecurity teams in various organizations, focusing on incident responseIT security departments across industries, focusing on threat analysis and prevention

While both roles require cybersecurity certifications and involve protecting organizational assets, the Cyber Security Incident Handler primarily responds to and manages security incidents, whereas the Cyber Security Analyst focuses on monitoring, analyzing, and preventing threats proactively.

More about Cyber Security Incident Handler jobs

What cities are hiring for Cyber Security Incident Handler jobs?

Cities with the most Cyber Security Incident Handler job openings:

What are popular job titles related to Cyber Security Incident Handler jobs?

For Cyber Security Incident Handler jobs, the most frequently searched job titles are:

Infographic showing various Cyber Security Incident Handler job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

Senior Incident Handler

Chicago, IL • On-site

Allstate Insurance
Insurance Services • 10K+ employees

$18.25 - $22.25/hr

Other

Posted 29 days ago


Key responsibilities

  • Lead the response and manage the full incident lifecycle from detection to recovery.

  • Coordinate cross-functional teams and external partners to ensure a unified and efficient incident response.

  • Lead advanced investigations into security threats using logs, forensic data, and telemetry, and help modernize the SOC with automation and AI tools.


Allstate Insurance rating

7.4

Company rating: 7.4 out of 10

Based on 571 frontline employees who took The Breakroom Quiz


Job description

At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Job Description

We're rebuilding incident response from the ground up-and we want a proven responder to help lead the way.
This is a chance to bring your hard-won expertise into a next-generation Security Operations program at Fortune 100 scale, where rapid response, automation, and AI-driven investigation are core to how we operate. As our Senior Incident Handler, you'll be the technical anchor for our most significant security events-driving the response, raising the bar on how we work, and helping mature the team toward a formal, scalable incident command model we're building for the future.
If you've handled the incidents that make headlines (or quietly prevented them from becoming headlines), bring the instincts of a seasoned incident commander, and can move seamlessly from the server room to the boardroom, this is where your experience turns into real influence. What You''ll Own
  • Incident Handling & Response Leadership:Serve as the lead responder during critical incidents-owning the full lifecycle from detection through containment, eradication, and recovery.You'llhelp run the war room, coordinate responders, and make confident calls with incomplete information.

  • Cross-Functional Coordination:Unify analysts, infrastructure, application owners, legal, comms, and third-party partners into a single, fast-moving response. Relentless focus on reducing dwell time and mean-time-to-respond.

  • Executive Communication:Be a trusted voice during high-severity events-translating fast-moving technical realities into clear business impact for stakeholders up to the C-suite. You build calm and confidence when it matters most.

  • Deep Threat Investigation:Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs,network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss-leveraging EDR/XDR, SIEM, and cloud telemetry.

  • AI & Automation Leadership:Help modernize our SOCby puttingcutting-edgeautomation and AI-assisted tooling to work-accelerating triage and enrichment without sacrificing human judgment.

  • Team Uplevel & Continuous Improvement:Raise the standard of how the team responds-sharpening detections, playbooks, and controls through meaningful after-action reviews, and helping shape the practices that will underpin our future incident command function.

What You Bring
  • Battle-tested IR experience:5+ years in cybersecurity operations or incident response, witha track recordof leading complex, enterprise-scale incidents end-to-end. Financial services or insurance experience is a plus-but great responders come from everywhere.

  • Command-level instincts:Demonstratedability to act as an incident commander or technical lead in high-stakes moments-running major bridge calls and making decisive calls fast. You bring the judgment that helps a teamoperatelike a mature command function.

  • Technical depth:Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on-prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, PowerShell).

  • Communication range:Exceptional written and verbal skills; equally credible with engineers and executives.

  • Automation mindset:Enthusiasm for SOAR, ML-based tooling, and LLMs to elevate response workflows.

  • Credentials:CISSP, GCIA, GCIH, GCFA, OSCP or othercertifications preferred.


Why This Role

You'lljoin at a pivotal moment-bringing yourexpertiseto a teamthat'sactively maturing, with the opportunity to help shape the incident command functionwe'rebuilding next. This is a role for someone who wants their fingerprints on how a Fortune 100 responds to the threats ahead. Ifyou'reready to lead through crisis, outthink sophisticated adversaries, and elevate a team around you-let'stalk.
#LI-JJ1

Skills

Cross-Functional Collaboration, Cyber Incident Response, Cyber Investigations, Cybersecurity Operations, Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive Communications, Forensic Analysis, Incident Handling, IT Automation, IT Security Architecture, Malware Analysis, Network Security, Penetration Testing, Scripting, Security Incident Response, Technical Leadership, Technical Mentoring, Technology Leadership

Compensation

Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications.

The candidate(s) offered this position will be required to submit to a background investigation.

Joining our team isn't just a job - it's an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger - a winning team making a meaningful impact.

Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For jobs in San Francisco, please click "here" for information regarding the San Francisco Fair Chance Ordinance.


For jobs in Los Angeles, please click "here" for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.

To view the "EEO Know Your Rights" poster click "here". This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.

To view the FMLA poster, click "here". This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.

It is the Company's policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee's ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.

When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.


What Allstate Insurance employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Allstate Insurance logo

About Allstate Insurance

Sourced by ZipRecruiter

We're a purpose-driven company powered by purpose-driven people. We're reinventing protection and transforming the company for our customers, communities and each other. You could play a role in our transformation. Join a 90-year-old, Fortune 100 insurance company as we challenge the status quo, champion inclusion and strengthen our communities. If being a part of that future gives you goosebumps, you've come to the right place. Reinventing the future of protection means rethinking how we work together. From marketing to claims, our employees have flexibility in how, when and where they work — whether at home, the office or both. We're creating an inclusive, diverse and equitable workplace. We encourage collaboration, support taking chances and foster a strong sense of community. Let's build a new kind of Allstate together.

Industry

Insurance services, real estate, finance and insurance and insurance agencies and brokerages

Company size

10,000+ Employees

Headquarters location

Northbrook, IL, US