1

Cyber Security Incident Response Analyst Jobs (NOW HIRING)

Cybersecurity Incident Response Analyst

Mclean, VA · On-site

$91K - $153K/yr

  • Medical

  • Life

  • Retirement

  • PTO

MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most ...

Cybersecurity Incident Response Analyst

Mclean, VA · On-site

$114K - $190K/yr

  • Medical

  • Life

  • Retirement

  • PTO

MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most ...

next page

Showing results 1-20

Cyber Security Incident Response Analyst information

See salary details

$65.5K

$116K

$162K

How much do cyber security incident response analyst jobs pay per year?

As of Aug 15, 2026, the average yearly pay for cyber security incident response analyst in the United States is $116,028.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,000.00 and $130,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Security Incident Response Analyst?

To thrive as a Cyber Security Incident Response Analyst, you need a solid understanding of network security, threat analysis, digital forensics, and incident response methodologies, often supported by a degree in cybersecurity or IT and relevant certifications such as CISSP, CEH, or GCIA. Familiarity with SIEM platforms, intrusion detection/prevention systems, and malware analysis tools is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts respond quickly and coordinate across teams during security incidents. These skills and qualities are essential to quickly identify, mitigate, and recover from cyber threats, protecting organizational assets and data.

What are some common challenges faced by Cyber Security Incident Response Analysts during incident investigations?

Cyber Security Incident Response Analysts often encounter challenges such as rapidly evolving threats, incomplete or ambiguous evidence, and the need to coordinate with multiple teams under tight timelines. Analysts must balance thorough investigation with the urgency to contain and remediate incidents, all while maintaining clear documentation. Additionally, dealing with sophisticated attacks may require continuous learning and adaptation to new tactics used by threat actors, making strong problem-solving and communication skills essential for success.

What does a Cyber Security Incident Response Analyst do?

A Cyber Security Incident Response Analyst is responsible for identifying, investigating, and responding to security incidents within an organization. Their role involves monitoring networks and systems for signs of suspicious activity, analyzing security breaches, and coordinating efforts to contain and recover from attacks. They also document incidents, perform forensic analysis, and help implement improvements to prevent future incidents. This position requires strong analytical skills, attention to detail, and up-to-date knowledge of cybersecurity threats and tools.

What is the difference between Cyber Security Incident Response Analyst vs Security Operations Center (SOC) Analyst?

AspectCyber Security Incident Response AnalystSecurity Operations Center (SOC) Analyst
Primary FocusResponding to and managing security incidentsMonitoring and analyzing security alerts
CertificationsCompTIA Security+, GIAC GCIH, CISSP (preferred)CompTIA Security+, GIAC GCIA, CISSP (preferred)
Work EnvironmentIncident response teams, forensic labs, client sitesSecurity operations centers, 24/7 monitoring centers
Industry UsageUsed across various industries for incident handlingPrimarily in organizations with security monitoring teams

Both roles require similar certifications and work in security environments, but the Incident Response Analyst focuses on managing security breaches and incidents, while the SOC Analyst primarily monitors security alerts and detects threats in real-time.

More about Cyber Security Incident Response Analyst jobs

What states have the most Cyber Security Incident Response Analyst jobs?

States with the most job openings for Cyber Security Incident Response Analyst jobs include:

What job categories do people searching Cyber Security Incident Response Analyst jobs look for?

The top searched job categories for Cyber Security Incident Response Analyst jobs are:

Infographic showing various Cyber Security Incident Response Analyst job openings in the United States as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $116,028 per year, or $55.8 per hour.

Cybersecurity Incident Response Analyst II

Merit321, Launching Careers

Bethesda, MD • On-site

Full-time

Re-posted 25 days ago


Job description

Job Summary:
Merit321 is a company focused on launching careers, and they are seeking a Tier 2 Cybersecurity Incident Response Analyst. This role provides advanced incident response support for NIH enterprise and cloud environments, responding to incidents, conducting investigations, and coordinating response activities according to established policies and standards.
Responsibilities:
• Respond to and manage incidents reported through the NIH cybersecurity hotline
• Log, categorize, investigate, and escalate incidents per NIH procedures
• Perform Tier 2/3 incident response across on-premises and cloud environments (Azure, AWS, GCP)
• Conduct forensic analysis, threat hunting, and log correlation
• Coordinate response activities with NIH stakeholders and service providers
• Develop executive summaries for significant incidents and third-party events
• Develop and maintain incident response playbooks, SOPs, and KB documentation
• Support annual updates to the NIH Incident Response Plan
• Contribute to incident response maturity assessments and improvement roadmaps
Qualifications:
Required:
• At least 3 years of cybersecurity incident response experience
• Bachelor' degree in related field
• Experience supporting federal, NIH, HHS, or healthcare environments
• Working knowledge of: NIST Cybersecurity Framework (CSF)
• Working knowledge of: NIST SP 800-61 Rev. 2
• Working knowledge of: NIST SP 800-53 Rev. 5 (IR, AU, SI, CA families)
• Working knowledge of: Client CISA guidance
• Hands-on experience responding to incidents in cloud environments
• Strong written communication skills, including executive-level reporting
Preferred:
• Experience developing or maintaining incident response playbooks
• Incident response or security certifications (GCIH, GCIA, CISSP, etc.)
Company:
What do you get when you bring together the most qualified, motivated, and talented individuals and place them into exciting and fast-paced environments that challenge them to be their best? You get a fast-growing company that has your best interest in mind and that supports your career growth. Founded in 2014, the company is headquartered in Rockville, USA, with a team of 11-50 employees. The company is currently Early Stage.