1

Incident Detection Analyst Jobs (NOW HIRING)

Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows. * Maintain and update detection tools and signatures in response to evolving ...

... detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS ... The Incident Responder will perform the following: Coordinate investigation and response efforts ...

... detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS ... The Incident Responder will perform the following: • Coordinate investigation and response ...

The Incident Detection role helps security operations by responding to escalated alerts and monitoring alerts. This position conducts in-depth analysis of security events with the specific ability to ...

Lead advanced incident detection, analysis, response, containment, eradication, and recovery activities for complex and high-severity cybersecurity incidents. * Perform proactive threat hunting using ...

Principal Incident Response Analyst

SC · Remote

$101K - $132K/yr

We are looking for an accomplished, high-performing Principal Incident Response Analyst for our Threat Detection & Response team with experience performing digital forensics, incident response, and ...

We are looking for an accomplished, high-performing Principal Incident Response Analyst for our Threat Detection & Response team with experience performing digital forensics, incident response, and ...

Showing results 21-40

Incident Detection Analyst information

See salary details

$19

$38

$62

How much do incident detection analyst jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for incident detection analyst in the United States is $38.31, according to ZipRecruiter salary data. Most workers in this role earn between $28.85 and $43.51 per hour, depending on experience, location, and employer.

What cities are hiring for Incident Detection Analyst jobs?

Cities with the most Incident Detection Analyst job openings:

What states have the most Incident Detection Analyst jobs?

States with the most job openings for Incident Detection Analyst jobs include:

What are popular job titles related to Incident Detection Analyst jobs?

For Incident Detection Analyst jobs, the most frequently searched job titles are:

Infographic showing various Incident Detection Analyst job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 83% Physical, 7% Hybrid, and 10% Remote job distribution, with an average salary of $79,692 per year, or $38.3 per hour.

Detection Analyst (Elastic)

On-site

BreakPoint Labs LLC
Network Security • 11 - 50 employees

Other

Posted 12 days ago


Key responsibilities

  • Develop, implement, and maintain custom detection rules and logic in the Elastic Security platform targeting adversary TTPs.

  • Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.

  • Maintain and update detection tools and signatures in response to evolving threats and ensure compliance with applicable directives.


Job description

BreakPoint Labs is seeking a Detection Engineer with an expertise in Elastic to design, develop, and implement detection mechanisms to identify cyber threats within a Cybersecurity Service Provider (CSSP) environment. The candidate will focus on creating and managing IDS/IPS signatures, log correlation rules, and other detection tools based on indicator lifecycle analysis. The Detection Engineer collaborates with Defensive Cyber Operations (DCO) Watch Analysts and other teams to ensure timely and effective threat detection, adhering to CJCSM 6510.01B reporting requirements and supporting the CSSP’s mission to protect data across a wide spectrum of sources and locations.

Responsibilities include:
  • Develop, implement, and maintain custom, high-fidelity detection rules and logic in the Elastic Security platform specifically targeting adversary TTPs mapped to the MITRE ATT&CK® framework.
  • Develop and prioritize risk-based alerting mechanisms to focus detection efforts on high-impact threats, aligning with organizational risk assessments.
  • Analyze threat intelligence to create and refine detection mechanisms tailored to the customer’s environment.
  • Validate and test detection rules to ensure accuracy, minimize false positive and benign positive matches, and enhance threat identification capabilities.
  • Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.
  • Maintain and update detection tools and signatures in response to evolving threats, ensuring compliance with CJCSM 6510.01B and other applicable directives.
  • Compile and maintain internal standard operating procedure (SOP) documentation for detection creation and implementation processes.
  • Coordinate with reporting agencies and subscriber sites to align detection strategies with operational needs and threat intelligence.
  • Participate in program reviews, product evaluations, and onsite certification evaluations to assess detection tool efficacy.
  • Overtime may be required to support detection implementation or incident response actions (Surge).
  • Up to 10% travel may be required.
Required Experience:
  • 5+ years of experience working in a CSSP, SOC, or similar environment.
  • 2+ years of experience with signature development, detection logic creation and optimization on multiple platforms.
  • Experience in threat detection engineering, threat hunting, or a related role with hands-on experience using the Elastic Stack, Kibana Query Language (KQL), Event Query Language (EQL), Elasticsearch Query Language (ES|QL) and/or Elastic Defend.
  • Experience with threat intelligence platforms and indicator management.
  • Proficient knowledge of detection creation and implementation processes.
  • Expertise in IDS/IPS solutions, including signature development and optimization.
  • Strong understanding of the indicator lifecycle, including initial discovery, development, operational maturity, and long-term sustainment.
  • Effective verbal and written communication skills.
  • Ability to solve complex problems independently.
  • Preferred certifications: Elastic Certified Analyst; Elastic Certified SIEM Analyst, Elastic Certified Engineer.

Certifications Required: DoD 8570 IAT Level II and DoD 8140 CSSP-specific certification.

Security Clearance Required: DoD Secret Clearance.

Education Required: Bachelor’s Degree Area(s) of Study of relevant discipline and 5 years of experience. OR, at least 8 years of experience working in a CSSP, SOC, or similar.

#J-18808-Ljbffr