1

Detection Response Analyst Jobs in Utah (NOW HIRING)

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

Senior SOC Analyst - Weekends

Ogden, UT · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

Senior SOC Analyst - Weekends

Logan, UT · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

Senior SOC Analyst - Weekends

Orem, UT · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... our detection, response, and threat-informed defense capabilities. It's ideal for someone who ...

Direct security operations across monitoring, detection, response, and recovery activities to ... Strong expertise in cybersecurity operations, vulnerability analysis, and security architecture ...

This role is responsible for overseeing the detection, response, and remediation of cybersecurity ... Oversee root cause analysis and post-incident reviews to strengthen controls * Coordinate with ...

This role is responsible for overseeing the detection, response, and remediation of cybersecurity ... Oversee root cause analysis and post-incident reviews to strengthen controls * Coordinate with ...

Senior IT Security Engineer

Draper, UT · On-site

$107K - $146K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Support implementation of enterprise-wide security initiatives and modernization efforts Incident Detection & Response: * Assist with monitoring, analysis, and response activities related to ...

This role oversees the detection, response, and remediation of cybersecurity threats while ensuring ... Conduct root cause analysis and post-incident reviews to strengthen security controls * Coordinate ...

Apply threat intelligence to enhance detection and response capabilities Requirements * Bachelor ... Analytical and problem-solving mindset * Ability to balance reactive incident response with ...

Cyber Defense Analyst

Clearfield, UT · On-site

$101K - $121K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

This Cyber Defense Analyst will possess strong core competencies in security monitoring, log analysis, and incident detection and response. Duties will include auditing system logs, monitoring ...

next page

Showing results 1-20

Detection Response Analyst information

What is a detection response analyst?

A Detection Response Analyst is a cybersecurity professional responsible for monitoring, detecting, and responding to security threats within an organization’s IT environment. They analyze security alerts, investigate potential incidents, and coordinate responses to mitigate risks. Their work helps protect sensitive data and maintain the overall security posture of a company. Detection Response Analysts often use various security tools, such as Security Information and Event Management (SIEM) systems, to identify suspicious activities and ensure timely incident resolution.

What are the key skills and qualifications needed to thrive as a detection response analyst?

To thrive as a Detection Response Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response, often supported by a degree in computer science or cybersecurity and relevant certifications like CompTIA Security+ or GIAC. Familiarity with Security Information and Event Management (SIEM) tools, intrusion detection systems (IDS), and scripting languages such as Python or PowerShell is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts effectively investigate threats and coordinate with teams. These skills are essential for timely threat detection, minimizing risks, and safeguarding organizational assets.

How does a detection response analyst typically collaborate with other teams within an organization?

Detection Response Analysts work closely with various departments, including IT, network operations, and incident response teams, to ensure timely identification and mitigation of security threats. Collaboration often involves sharing threat intelligence, participating in incident response drills, and coordinating on investigations to minimize the impact of security incidents. Regular communication with other security professionals helps analysts stay updated on emerging threats and implement best practices across the organization. This teamwork is essential for maintaining a robust and proactive cybersecurity posture.

What is the difference between Detection Response Analyst vs Security Analyst?

AspectDetection Response AnalystSecurity Analyst
CertificationsCompTIA Security+, GIAC certificationsCompTIA Security+, CISSP, CEH
Work EnvironmentSecurity operations centers, incident response teamsIT departments, security teams, consulting firms
Employer & Industry UsageCybersecurity firms, large enterprises, government agenciesOrganizations across various industries, including finance, healthcare, and tech
Primary FocusDetecting and responding to security incidents in real-timeMonitoring, analyzing, and improving security posture

The Detection Response Analyst primarily focuses on identifying and responding to security threats as they occur, often working within security operations centers. Security Analysts have a broader role in monitoring, analyzing, and enhancing overall security measures across an organization. While both roles require similar certifications and work in cybersecurity environments, Detection Response Analysts are more incident-response oriented, whereas Security Analysts focus on ongoing security management.

What are popular job titles related to Detection Response Analyst jobs in Utah?

For Detection Response Analyst jobs in Utah, the most frequently searched job titles are:

What cities in Utah are hiring for Detection Response Analyst jobs?

Cities in Utah with the most Detection Response Analyst job openings:

Infographic showing various Detection Response Analyst job openings in Utah as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, 3% Contract, and 1% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution.

Incident Responder

JetBlue Airways Corporation

Salt Lake City, UT • On-site

Full-time

Medical, Life, Retirement

Posted 8 days ago


JetBlue rating

7.5

Company rating: 7.5 out of 10

Based on 82 frontline employees who took The Breakroom Quiz

10th of 26 rated airlines


Job description

Position Summary:

At JetBlue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment.

We are seeking an experienced Incident Response Analyst to support the Cyber Security Incident Response function through escalated alert triage, investigation, containment support, and response activities. The ideal candidate has hands-on experience analyzing security telemetry across multiple tools, can work independently through ambiguous investigations, and can clearly document findings, risk, and recommended next steps.

Essential Responsibilities:

  • Monitor, triage, and investigate escalated security alerts and cases from internal tools, managed security providers, and other reporting channels.
  • Analyze telemetry from multiple sources, including SIEM, endpoint detection and response tools, identity platforms, email security tools, cloud platforms, network devices, CDNs, and WAF technologies.
  • Investigate suspicious or malicious activity, including phishing, malware, suspicious authentication, anomalous network activity, unauthorized access, endpoint compromise, and potential data exposure.
  • Perform investigative scoping to identify affected users, hosts, accounts, applications, indicators, timelines, and potential business impact.
  • Support incident response activities, including evidence gathering, containment support, remediation validation, and communication of technical findings.
  • Execute approved response actions in accordance with established procedures, including account, endpoint, email, URL/domain, or indicator-based response steps.
  • Create clear, defensible case notes and incident documentation, including observed activity, entities involved, timeframe, scope, conclusion, and remediation or follow-up actions.
  • Collaborate with Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, and other stakeholders during investigations.
  • Identify detection gaps, logging gaps, process breakdowns, recurring alert patterns, and opportunities to improve security monitoring and response capabilities.
  • Build or support dashboards, searches, playbooks, reports, process documentation, and other operational improvements that improve incident response efficiency and quality.
  • Provide guidance and support to less experienced analysts during triage, investigation, documentation, and escalation activities.
  • Other duties as assigned.

Minimum Experience and Qualifications:

  • Bachelor's Degree in Cyber Security, Computer Science, Information Technology, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience on a SOC, Incident Response, Threat Detection, or cyber security operations team.
  • Three (3) years of hands-on experience performing alert triage, security investigations, incident response support, or similar technical security operations work.
  • Demonstrated ability to analyze disparate data sources such as network logs, endpoint activity, authentication logs, cloud logs, email data, and SIEM events to assess suspicious or malicious activity.
  • Experience investigating common security events such as phishing, malware, suspicious logins, anomalous network traffic, unauthorized access, suspicious process execution, or endpoint compromise.
  • Ability to assess risk, determine likely impact, scope activity, and make appropriate escalation recommendations based on available evidence.
  • Strong problem-solving and analytical skills, including the ability to work through ambiguous or incomplete information.
  • Ability to demonstrate a high level of critical thinking and sound judgment during technical investigations.
  • Ability to pass a live skills demonstration or technical interview on-site with JetBlue Crew Members.
  • Experience with scripting, querying, or automation languages such as PowerShell, Python, KQL, SPL, or similar technologies.
  • Ability to manage multiple cases and priorities in a fast-paced operational environment.
  • Excellent written and verbal communication skills, including the ability to clearly document investigations and summarize technical findings.
  • Available and willing to participate in periodic on-call duties and off-hours Incident Response as required.
  • Available for occasional overnight travel (10%).
  • Must pass a ten (10) year background check and pre-employment drug test.
  • Must be legally eligible to work in the country in which the position is located.
  • Authorization to work in the United States is required. This position is not eligible for visa sponsorship.
  • Must be eligible to hold a US government security clearance if JetBlue deems it relevant to the role.

Preferred Experience and Qualifications:

  • Five (5) or more years of experience in a SOC, Incident Response, Threat Detection, cybersecurity operations, or similar blue team function.
  • Experience triaging and investigating security incidents in an enterprise environment or managed security services environment.
  • Hands-on experience with SIEM platforms such as Splunk and EDR tools such as SentinelOne, CrowdStrike, Microsoft Defender, or similar technologies.
  • Experience with SOAR or case management platforms, including documenting investigations, tracking actions, and following structured playbooks.
  • Thorough understanding of networking principles such as DNS, TCP/IP, HTTP/S, proxies, firewalls, VPNs, and how they relate to security investigations.
  • Basic knowledge of one or more cloud environments such as AWS, Azure, or Google Cloud and related cloud security investigation concepts.
  • Experience with identity and access investigations, including MFA events, session activity, privileged access, and account compromise indicators.
  • Familiarity with common attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK.
  • Experience supporting phishing, business email compromise, malware, endpoint compromise, suspicious authentication, web application, or data exposure investigations.
  • Experience building dashboards, saved searches, alert logic, scripts, or other investigative content in security tooling.
  • Airline, transportation, critical infrastructure, or large-enterprise experience in Security Operations, Incident Response, Threat Detection, or Threat Intelligence.
  • Strong sense of urgency, ownership, and drive to continuously improve the craft of incident response.

Crewmember Expectations:

  • Regular attendance and punctuality.
  • Potential need to work flexible hours and be available to respond on short notice.
  • Able to maintain a professional appearance.
  • When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft.
  • Organizational fit for the JetBlue culture, that is, exhibit JetBlue's values of Safety, Caring, Integrity, Fun and Passion.
  • Promote JetBlue's #1 value of safety as a Safety Ambassador, supporting JetBlue's Safety Management System (SMS) components, Safety Policy and behavioral standards.
  • Must fulfill safety accountabilities as prescribed by JetBlue's Safety Management System.
  • Responsible for adhering to all applicable laws, regulations (FAA, OSHA, DOT, etc.) and Company policies, procedures and risk controls.
  • Responsible for ensuring crewmembers have requisite training, resources and support to achieve safety objectives.
  • Identify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue's confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR)).
  • The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.

Equipment:

  • Computer and other office equipment.

Work Environment:

  • Traditional office environment.

Physical Effort:

  • Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)

Compensation:

  • The base pay range for this position is between$90,500.00 and $128,600.00 per year. Base pay is one component of JetBlue's total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.

#LI-AC1

#LI-Hybrid


What JetBlue employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom