1

Detection Investigation Analyst Jobs (NOW HIRING)

Detection and Response Engineer

New York, NY ยท On-site

$150K - $270K/yr

Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable ... Experience in detection engineering, incident response, security engineering, or software ...

Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable ... Experience in detection engineering, incident response, security engineering, or software ...

Showing results 21-40

Detection Investigation Analyst information

See salary details

$32K

$84.2K

$133.5K

How much do detection investigation analyst jobs pay per year?

As of Sep 11, 2026, the average yearly pay for detection investigation analyst in the United States is $84,207.00, according to ZipRecruiter salary data. Most workers in this role earn between $65,000.00 and $98,500.00 per year, depending on experience, location, and employer.

What is the difference between Detection Investigation Analyst vs Fraud Analyst?

AspectDetection Investigation AnalystFraud Analyst
CredentialsTypically requires certifications like ACFE or related investigative trainingOften requires certifications such as CFE or fraud examination credentials
Work EnvironmentInvestigates security alerts, monitors systems, analyzes suspicious activityReviews fraud cases, analyzes financial data, conducts interviews
Industry UsageUsed in cybersecurity, banking, and financial sectorsPrimarily in banking, insurance, and financial services

Both roles involve investigation and analysis, but Detection Investigation Analysts focus on security alerts and system monitoring, while Fraud Analysts concentrate on financial fraud detection and prevention. They share similar skills and certifications but differ in their specific focus areas within the industry.

What does a detection investigation analyst do?

A detection investigation analyst reviews security alerts and data to identify potential threats or security breaches. They analyze logs, use security tools, and follow procedures to determine the legitimacy of incidents, often working with cybersecurity teams to respond and mitigate risks. Strong analytical skills and knowledge of security protocols are essential for this role.

What cities are hiring for Detection Investigation Analyst jobs?

Cities with the most Detection Investigation Analyst job openings:

What states have the most Detection Investigation Analyst jobs?

States with the most job openings for Detection Investigation Analyst jobs include:

What are popular job titles related to Detection Investigation Analyst jobs?

For Detection Investigation Analyst jobs, the most frequently searched job titles are:

Infographic showing various Detection Investigation Analyst job openings in the United States as of September 2026, with employment types broken down into 92% Full Time, and 8% Contract. Highlights an 69% In-person, 8% Hybrid, and 23% Remote job distribution, with an average salary of $84,207 per year, or $40.5 per hour.

Cybersecurity Defense Analyst II

Colorado Springs, CO โ€ข On-site

Invictus International Consulting, LLC
Guided Missile and Space Vehicle Manufacturingย โ€ขย 11 - 50 employees

$150K/yr

Full-time

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Title: Cyber Defense Analyst II
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
  • Independently monitor, triage, and investigate routine and moderately complex security alerts and suspected incidents.
  • Perform cyber defense monitoring and analysis using security information from enterprise systems, networks, security sensors, firewalls, intrusion detection/prevention technologies, endpoint sources, and other available telemetry.
  • Analyze log files and network activity to identify anomalous or malicious behavior, determine potential security impact, and document investigative findings in the authorized case or ticketing system
  • Perform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalation
  • Support incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and procedures
  • Correlate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related events
  • Collect and preserve relevant intrusion artifacts and investigative evidence in accordance with established procedures
  • Communicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriate
  • Develop and test investigative hypotheses by correlating network, host, identity, firewall, vulnerability, and threat data
  • Identify related activity beyond the initially alerted system and appropriately expand investigative scope
  • Execute established incident response and escalation procedures and coordinate with technical teams when containment or remediation action is required
  • Identify recurring alert-quality, telemetry, or process issues and recommend improvements to senior analysts

Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum four (4) years of relevant experience in addition to education level
  • Working knowledge of TCP/IP, DNS, HTTP/S, authentication, enterprise networking, Windows/Linux security events, and common adversary techniques
  • Hands-on experience using SIEM and one or more network, endpoint, firewall, IDS/IPS, or security-analysis technologies
  • Ability to independently investigate security activity, distinguish facts from assumptions, and communicate evidence-based conclusions
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled