1

Endpoint Analyst Jobs in Raleigh, NC (NOW HIRING)

Lead, coach, and mentor MDR Analysts: regular 1:1s, performance feedback, onboarding, and the T1-to ... Correlate alerts across EDR (SentinelOne, Defender for Endpoint), ITDR (M365, Google Workspace ...

Job Title: IT Service Desk Analyst - Level 1 Pay Rate: $26 - $28 / Hr Location: Raleigh, NC (onsite ... Knowledge of endpoint response or antivirus solution management preferred. * Knowledge of Microsoft ...

Job Title: IT Service Desk Analyst - Level 1 Pay Rate: $26 - $28 / Hr Location: Raleigh, NC (onsite ... Knowledge of endpoint response or antivirus solution management preferred. * Knowledge of Microsoft ...

Experience analyzing security-related data sources, including: * Authentication logs * Endpoint telemetry * Network logs * Application security logs * Ability to convert complex security data into ...

Showing results 41-60

Endpoint Analyst information

See Raleigh, NC salary details

$30.1K

$71.2K

$126.4K

How much do endpoint analyst jobs pay per year?

As of Aug 18, 2026, the average yearly pay for endpoint analyst in Raleigh, NC is $71,216.00, according to ZipRecruiter salary data. Most workers in this role earn between $51,000.00 and $84,600.00 per year, depending on experience, location, and employer.

What is an endpoint analyst?

An Endpoint Analyst is a cybersecurity professional responsible for monitoring, managing, and securing endpoint devices such as computers, mobile devices, and servers within an organization. They analyze endpoint activity to detect threats, respond to incidents, and implement security measures to protect data and systems. Endpoint Analysts often use specialized tools to ensure devices comply with security policies and remain protected against malware, unauthorized access, and other vulnerabilities.

How does an endpoint analyst typically collaborate with other IT teams to ensure endpoint security and performance?

Endpoint Analysts work closely with various IT teams, such as network security, help desk support, and systems administration, to monitor and secure all endpoint devices like laptops, desktops, and mobile devices. They often coordinate incident response efforts with cybersecurity teams when threats are detected and assist in deploying patches and updates provided by system administrators. Regular communication and documentation are essential, as Endpoint Analysts must relay technical findings and recommend best practices to both technical and non-technical stakeholders. This collaborative environment helps ensure endpoints remain secure, compliant, and efficient across the organization.

What are the key skills and qualifications needed to thrive as an endpoint analyst, and why are they important?

To thrive as an Endpoint Analyst, you need strong knowledge of endpoint security, operating systems, and threat detection, usually supported by a degree in IT or cybersecurity and relevant experience. Familiarity with endpoint detection and response (EDR) tools, antivirus software, and security information and event management (SIEM) systems is typically required, with certifications like CompTIA Security+ or CISSP being advantageous. Analytical thinking, attention to detail, and effective communication are vital soft skills for excelling in this role. These skills ensure the protection of organizational assets, timely response to incidents, and clear collaboration with IT teams and stakeholders.

What is the difference between Endpoint Analyst vs Network Security Analyst?

AspectEndpoint AnalystNetwork Security Analyst
CertificationsCompTIA Security+, Cisco CCNA, Microsoft certificationsCompTIA Security+, CISSP, Cisco CCNP Security
Work EnvironmentFocuses on endpoint devices like laptops, desktops, mobile devicesFocuses on network infrastructure and security protocols
Industry UsageCommon in IT support, cybersecurity teams, enterprise environmentsCommon in cybersecurity, network operations, and defense teams
Job FocusManaging and securing endpoint devices, troubleshooting endpoint issuesMonitoring and protecting network traffic, preventing intrusions

While both roles are vital in cybersecurity, an Endpoint Analyst primarily manages and secures individual devices within an organization, whereas a Network Security Analyst focuses on protecting the entire network infrastructure. Both roles often require similar certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

What are the most commonly searched types of Endpoint Analyst jobs in Raleigh, NC?

The most popular types of Endpoint Analyst jobs in Raleigh, NC are:

What are popular job titles related to Endpoint Analyst jobs in Raleigh, NC?

For Endpoint Analyst jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Endpoint Analyst jobs in Raleigh, NC look for?

The top searched job categories for Endpoint Analyst jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Endpoint Analyst jobs?

Cities near Raleigh, NC with the most Endpoint Analyst job openings:

Senior Cyber Security Analyst (Incident Response)

First Citizens Bank

Raleigh, NC • Remote

$140K - $188K/yr

Full-time

Posted 10 days ago


First Citizens Bank rating

7.4

Company rating: 7.4 out of 10

Based on 106 frontline employees who took The Breakroom Quiz

106th of 171 rated banks


Job description

Overview

This is a remote role that may be hired in several markets across the United States.

As a Senior Incident Response Analyst, you'll be a member of the bank's Cyber Incident Response team. We are looking for an experienced senior level analyst with proven skillsets to detect and respond to threats in the environment, interact with business stakeholders and work to restore operations. This is a technical role and will support the Threat Hunting, Intelligence, and Monitoring functions with content creation, threat analysis, detection recommendations, and colleague mentoring. Seeking a candidate with strong communication skills to complement their technical skillset providing the ability to distill down complex issues for broader understanding expedited incident management. 


Responsibilities
  • Incident Analyst/handler –investigate SIEM/SOAR events as necessary; bring experience in malware analysis, network/endpoint security to respond to and contain incidents. 
  • Incident Responder/Incident Lead – Lead Incidents, coordinating the investigation, mitigation, and remediation from a technical perspective. Liaise with technical and business stakeholders. 
  • Incident Management – Ensures Information Security incidents are properly detected, documented, investigated, and resolved. 
  • Content Development - Support the creation of countermeasures and mitigations in response to an incident. 
  • Threat Hunting - Support the operational driven inputs (eg. on the heels of an incident or event) into threat hunting and help build countermeasures/mitigations to address commodity and targeted threats. Also build a capability to track evolving threat actor techniques. 
  • Post Incident Review – Provide recommendations to improve communication, processes, procedures, and mitigation options based on high severity incidents. 

Qualifications

Bachelor's Degree and 8 years of experience in Information security OR High School Diploma or GED and 12 years of experience in Information security

  • Experience with all aspects of Incident response including stakeholder management. 
  • 2+ years of Threat Hunting experience.
  • Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus. 
  • Experience analyzing/dispositioning and escalating security events (systems, application, network, authentication email events) 
  • Experience translating threat actor techniques to building mitigations across a variety of security technologies. This could take the form of Yara, Sigma or Regular Expressions. 
  • Ability to define security requirements and drive project deliverables. 
  • Ability to keep track of multiple incidents and ensure responses are provided in a timely fashion. 
  • Experience responding to cloud-related incidents in Azure, AWS and Google cloud.
  • Cloud administrative experience preferred.
  • Cyber Incident Response experience – 3+ years required in which your primary job was an Incident Response role.
  • This role requires participation in the afterhours on call rotation. Rotations will cycle on a weekly basis.

The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

This job posting is expected to remain active for 45 days from the initial posting date listed above.  If it is necessary to extend this deadline, the posting will remain active as appropriate.  Job postings may come down early due to business need or a high volume of applicants

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Qualifications:

Bachelor's Degree and 8 years of experience in Information security OR High School Diploma or GED and 12 years of experience in Information security

  • Experience with all aspects of Incident response including stakeholder management. 
  • 2+ years of Threat Hunting experience.
  • Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus. 
  • Experience analyzing/dispositioning and escalating security events (systems, application, network, authentication email events) 
  • Experience translating threat actor techniques to building mitigations across a variety of security technologies. This could take the form of Yara, Sigma or Regular Expressions. 
  • Ability to define security requirements and drive project deliverables. 
  • Ability to keep track of multiple incidents and ensure responses are provided in a timely fashion. 
  • Experience responding to cloud-related incidents in Azure, AWS and Google cloud.
  • Cloud administrative experience preferred.
  • Cyber Incident Response experience – 3+ years required in which your primary job was an Incident Response role.
  • This role requires participation in the afterhours on call rotation. Rotations will cycle on a weekly basis.

The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

This job posting is expected to remain active for 45 days from the initial posting date listed above.  If it is necessary to extend this deadline, the posting will remain active as appropriate.  Job postings may come down early due to business need or a high volume of applicants

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Education:UNAVAILABLEEmployment Type: FULL_TIME

What First Citizens Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom