1

Cyber Security Incident Response Jobs (NOW HIRING)

Job Summary Serves as the dedicated lead responder for Transocean's Cyber Security Incident Response Team (CSIRT), responsible for leading major investigation, coordination, containment, eradication ...

next page

Showing results 1-20

Cyber Security Incident Response information

See salary details

$57K

$133K

$186K

How much do cyber security incident response jobs pay per year?

As of Aug 11, 2026, the average yearly pay for cyber security incident response in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

How to become a cyber security incident response specialist?

To become a cyber security incident response specialist, individuals typically need a bachelor's degree in cybersecurity, computer science, or a related field, along with experience in network security and threat analysis. Certifications such as GIAC Certified Incident Handler (GCIH) or Certified Computer Security Incident Handler (CSIH) can enhance job prospects. Developing skills in intrusion detection, malware analysis, and familiarity with security tools like SIEM systems are also important for this role.

What is the difference between Cyber Security Incident Response vs Cyber Security Analyst?

AspectCyber Security Incident ResponseCyber Security Analyst
CertificationsGCIH, CISSP, CEHCISSP, Security+, CEH
Work EnvironmentResponds to security incidents, investigates breachesMonitors networks, analyzes security data
Employer & Industry UsageIncident response teams in various sectorsSecurity teams across industries

Cyber Security Incident Responders focus on managing and mitigating security incidents, while Cyber Security Analysts monitor systems and analyze threats. Both roles require similar certifications and often work within the same security teams, but their core responsibilities differ: incident responders act during and after breaches, whereas analysts proactively identify vulnerabilities.

What are the key skills and qualifications needed to thrive as a cyber security incident response specialist?

To thrive as a Cyber Security Incident Response specialist, you need expertise in network security, threat analysis, digital forensics, and a relevant degree or certifications such as CISSP, CEH, or GIAC. Familiarity with SIEM tools, intrusion detection systems, and forensic analysis software is essential for investigating and mitigating cyber threats. Strong problem-solving skills, attention to detail, and the ability to communicate complex issues clearly are standout soft skills in this role. These abilities are crucial for quickly detecting, analyzing, and responding to security incidents to protect organizational assets and minimize risk.

How much does a cyber security incident response make?

Cyber security incident response professionals typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Entry-level roles may start lower, while experienced analysts with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand areas.

What is cyber security incident response?

Cyber security incident response refers to the process and procedures organizations use to detect, investigate, and respond to security incidents such as data breaches, malware attacks, or unauthorized access. The goal is to minimize damage, recover affected systems, and prevent future incidents by analyzing what happened and implementing corrective actions. Incident response teams follow structured plans that typically include preparation, identification, containment, eradication, recovery, and lessons learned. Effective incident response helps organizations protect sensitive information, maintain business continuity, and comply with legal or regulatory requirements.

What are some common challenges faced by professionals in cyber security incident response roles?

Professionals in Cyber Security Incident Response often face challenges such as rapidly evolving threat landscapes, high-pressure situations requiring quick decision-making, and the need to coordinate across multiple departments during incidents. Handling large volumes of alerts and distinguishing between real threats and false positives can also be demanding. Additionally, staying up to date with the latest tools, techniques, and compliance requirements is essential for success and can require ongoing learning and adaptation.

What does a cyber security incident response do?

A cyber security incident response professional is responsible for identifying, managing, and mitigating cybersecurity incidents such as data breaches, malware infections, or system intrusions. They analyze security alerts, coordinate containment and recovery efforts, and implement measures to prevent future incidents, often using tools like intrusion detection systems and forensic analysis. This role requires strong problem-solving skills and knowledge of security frameworks and protocols.
More about Cyber Security Incident Response jobs
What cities are hiring for Cyber Security Incident Response jobs? Cities with the most Cyber Security Incident Response job openings:
What states have the most Cyber Security Incident Response jobs? States with the most job openings for Cyber Security Incident Response jobs include:
What job categories do people searching Cyber Security Incident Response jobs look for? The top searched job categories for Cyber Security Incident Response jobs are:
Infographic showing various Cyber Security Incident Response job openings in the United States as of August 2026, with employment types broken down into 85% Full Time, 12% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Full-time

Posted 10 days ago


Job description

Please reference the schedule and minimum qualifications listed below before applying.

If you need assistance with filling out our application form or during any phase of the application, interview, or employment process, please notify our Human Resources Team at 801-366-6947 option 1 or email macurecruiting@macu.com and every reasonable effort will be made to accommodate your needs in a timely manner.

Job SummaryThe Director of Cybersecurity Incident Response & Insider Threat leads MACU's enterprise-wide cyber incident response, digital forensics, threat intelligence, and insider threat program. This role is responsible for preparing the organization to detect, respond to, and recover from cybersecurity incidents while protecting member data, intellectual property, and critical systems.
In this highly visible leadership role, you will partner closely with Cybersecurity, IT, Legal, HR, Governance, Risk Management, and Executive Leadership to manage high-impact incidents, insider risk, and crisis situations. You will define response strategy, mature operational capabilities, and ensure the organization is resilient against both externalJob Description

LOCATION: UTAH

9800 S MONROE ST

SANDY UT 84070

SCHEDULE: FULL-TIME

To be effective, an individual must be able to perform each job duty successfully. This is a Director level role that will be tasked to come into the organization and be a hands-on leader to re-establish, build, manage, and guide the team.

Key Responsibilities

Incident Response & Crisis Management

  • Lead the enterprise cybersecurity incident response program, including preparation, detection, containment, eradication, and recovery activities.
  • Serve as the executive incident commander for high-severity cybersecurity events, coordinating technical teams, business stakeholders, and leadership.
  • Define and maintain incident response plans, playbooks, escalation models, and crisis communication procedures.
  • Conduct executive-level briefings during and after incidents, including post-incident reports, root cause analysis, and lessons learned.
  • Oversee breach investigations, digital forensics, and evidence preservation in coordination with Legal and Compliance.
  • Lead tabletop exercises, red/blue team simulations, and ransomware readiness scenarios.
  • Lead the organization's brand protection efforts to safeguard reputation and identity.
  • Lead proactive threat-hunting initiatives to identify advanced threats, vulnerabilities, and anomalous activities across the enterprise environment.
  • Define and maintain incident response plans, playbooks, escalation models, and crisis communication procedures.

Insider Threat Program Leadership

  • Own and operate the enterprise Insider Threat Program, addressing malicious, negligent, and compromised insider risks.
  • Define insider threat detection, triage, investigation, and response processes across people, process, and technology.
  • Partner with HR, Legal, Privacy, and Risk Management teams to ensure investigations are lawful and appropriate.
  • Implement behavioral, technical, and contextual monitoring capabilities.
  • Establish governance, oversight, and separation of duties for insider investigations.

Security Operations & Capability Maturity

  • Collaborate with SOC leadership to enhance monitoring, alerting, and response automation.
  • Drive continuous improvement using metrics and maturity models.
  • Translate threat intelligence into actionable detection and response strategies.

Governance, Risk, and Compliance

  • Ensure alignment with regulatory frameworks including NCUA, FFIEC, and NIST.
  • Support audits, regulatory exams, and breach notification requirements.
  • Partner with Risk Management and Internal Audit to remediate gaps.

Leadership & Influence

  • Lead and mentor incident response and insider threat professionals.
  • Partner across IT, Digital Solutions, Legal, HR, Communications, and executives.
  • Act as a trusted advisor during high-impact and sensitive situations.
KNOWLEDGE, SKILLS, and ABILITIES

The requirements listed are representative of the knowledge, skills, and/or abilities required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential job functions.

Education and Experience

  • 8+ years of experience in cybersecurity operations or incident response with progressive responsibility.
  • 5+ years in a leadership role responsible for cybersecurity operations or incident response.
  • Experience leading enterprise-scale incident response programs.
  • Financial services or regulated industry experience preferred.
  • Bachelor's degree in a related discipline or equivalent experience required.

Licenses, Certifications, Registrations

  • CISSP strongly preferred.
  • GCIH, GCFA, CISM, CISA, or GIAC certifications highly desirable.

Other Skills and Abilities

  • Expertise in incident response and digital forensics.
  • Strong understanding of insider threat risk and investigations.
  • Executive-level communication and leadership under pressure.
  • Proven ability to balance security, privacy, and business needs.
  • Data driven decision making and the ability to drive a program through metrics and tell the story of why things matter
  • Strategic thinking.
  • Problem-solving skills.
  • Verbal/written communication skills.
  • Leadership and talent management skills.
  • Public speaking skills.
PHYSICAL ABILITIES / WORKING CONDITIONS

Physical Demands
Ability to sit, talk and hear consistently

Vision Requirements
Close vision (clear vision at 20 inches or less)
Distance vision (clear vision at 20 feet or more)
Color vision (ability to identify and distinguish colors)

Weight Lifted or Force Exerted
Ability to lift up to 10 pounds frequently and up to 25 pounds occasionally

Environmental
There are no unusual environmental factors (such as a typical office)

Noise Environment
Moderate noise (business office with computers and printers, light traffic)

***This Job is not eligible to be performed in Colorado or Connecticut, either remotely or in-person.***

Mountain America Credit Union is an EEO/AA/ADA/Veterans employer.