Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows. * Maintain and update detection tools and signatures in response to evolving ...
Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows. * Maintain and update detection tools and signatures in response to evolving ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows. * Maintain and update detection tools and signatures in response to evolving ...
Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows. * Maintain and update detection tools and signatures in response to evolving ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
Threat Detection Analyst (Expert)
$70K - $140K/yr
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
Threat Detection Analyst (Expert)
$70K - $140K/yr
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
The Threat Detection Analyst Expert works closely with Incident Response, Cybersecurity Operations, Threat Intelligence, Security Engineering, and IT Operations teams to improve detection coverage ...
Senior Incident Response Analyst
Arlington, VA · On-site
$131K - $237K/yr
... detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS ... The Incident Responder will perform the following: Coordinate investigation and response efforts ...
Senior Incident Response Analyst
Arlington, VA · On-site
$131K - $237K/yr
... detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS ... The Incident Responder will perform the following: Coordinate investigation and response efforts ...
... detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS ... The Incident Responder will perform the following: • Coordinate investigation and response ...
... detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS ... The Incident Responder will perform the following: • Coordinate investigation and response ...
Senior Incident Response Analyst
Piscataway, NJ · On-site
$108K/yr
Performs daily operations of the incident detection and response program, which includes finding ... Provides expert-level analytic, investigative and forensic support of complex security incidents to ...
Senior Incident Response Analyst
Piscataway, NJ · On-site
$108K/yr
Performs daily operations of the incident detection and response program, which includes finding ... Provides expert-level analytic, investigative and forensic support of complex security incidents to ...
SOC Analyst Level 1 and 2
Irving, TX · On-site
The Incident Detection role helps security operations by responding to escalated alerts and monitoring alerts. This position conducts in-depth analysis of security events with the specific ability to ...
SOC Analyst Level 1 and 2
Irving, TX · On-site
The Incident Detection role helps security operations by responding to escalated alerts and monitoring alerts. This position conducts in-depth analysis of security events with the specific ability to ...
Incident Detection/Response Manager (SOC Manager) with Security Clearance
Hampton, VA · On-site
$140K - $160K/yr
Lead post-incident reviews and root cause analysis to identify lessons learned and drive continuous improvement in SOC processes and detection capabilities. * Ensure compliance with NIST SP 800-61 ...
Incident Detection/Response Manager (SOC Manager) with Security Clearance
Hampton, VA · On-site
$140K - $160K/yr
Lead post-incident reviews and root cause analysis to identify lessons learned and drive continuous improvement in SOC processes and detection capabilities. * Ensure compliance with NIST SP 800-61 ...
Conduct real-time incident detection, analysis, and escalation * Perform log analysis, threat hunting, and root cause analysis * Support vulnerability management and endpoint detection * Maintain ...
Quick apply
Conduct real-time incident detection, analysis, and escalation * Perform log analysis, threat hunting, and root cause analysis * Support vulnerability management and endpoint detection * Maintain ...
Tier 3 Cybersecurity Analyst
Rockville, MD · On-site
$130K - $170K/yr
Lead advanced incident detection, analysis, response, containment, eradication, and recovery activities for complex and high-severity cybersecurity incidents. * Perform proactive threat hunting using ...
Tier 3 Cybersecurity Analyst
Rockville, MD · On-site
$130K - $170K/yr
Lead advanced incident detection, analysis, response, containment, eradication, and recovery activities for complex and high-severity cybersecurity incidents. * Perform proactive threat hunting using ...
TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission-critical ... As part of the Security Operations Center, you will help monitor, detect, investigate, and respond ...
Quick apply
TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission-critical ... As part of the Security Operations Center, you will help monitor, detect, investigate, and respond ...
Principal Incident Response Analyst
SC · Remote
$101K - $132K/yr
We are looking for an accomplished, high-performing Principal Incident Response Analyst for our Threat Detection & Response team with experience performing digital forensics, incident response, and ...
Principal Incident Response Analyst
SC · Remote
$101K - $132K/yr
We are looking for an accomplished, high-performing Principal Incident Response Analyst for our Threat Detection & Response team with experience performing digital forensics, incident response, and ...
Principal Incident Response Analyst
$101K - $132K/yr
We are looking for an accomplished, high-performing Principal Incident Response Analyst for our Threat Detection & Response team with experience performing digital forensics, incident response, and ...
Principal Incident Response Analyst
$101K - $132K/yr
We are looking for an accomplished, high-performing Principal Incident Response Analyst for our Threat Detection & Response team with experience performing digital forensics, incident response, and ...
Incident Detection Analyst information
See salary details
$19.23 - $23.21
5% of jobs
$23.21 - $27.19
16% of jobs
$28.84 is the 25th percentile. Wages below this are outliers.
$27.19 - $31.16
9% of jobs
$31.16 - $35.14
7% of jobs
The median wage is $37.05 / hr.
$35.14 - $39.12
25% of jobs
$41.75 is the 75th percentile. Wages above this are outliers.
$39.12 - $43.09
18% of jobs
$43.09 - $47.07
2% of jobs
$47.07 - $51.05
11% of jobs
$51.05 - $55.03
4% of jobs
$55.03 - $59
0% of jobs
$59 - $62.98
2% of jobs
$19
$38
$62
How much do incident detection analyst jobs pay per hour?
What cities are hiring for Incident Detection Analyst jobs?
Cities with the most Incident Detection Analyst job openings:
What states have the most Incident Detection Analyst jobs?
States with the most job openings for Incident Detection Analyst jobs include:
What are popular job titles related to Incident Detection Analyst jobs?
For Incident Detection Analyst jobs, the most frequently searched job titles are:

Detection Analyst (Elastic)
On-site
Other
Posted 12 days ago
Key responsibilities
Develop, implement, and maintain custom detection rules and logic in the Elastic Security platform targeting adversary TTPs.
Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.
Maintain and update detection tools and signatures in response to evolving threats and ensure compliance with applicable directives.
Job description
BreakPoint Labs is seeking a Detection Engineer with an expertise in Elastic to design, develop, and implement detection mechanisms to identify cyber threats within a Cybersecurity Service Provider (CSSP) environment. The candidate will focus on creating and managing IDS/IPS signatures, log correlation rules, and other detection tools based on indicator lifecycle analysis. The Detection Engineer collaborates with Defensive Cyber Operations (DCO) Watch Analysts and other teams to ensure timely and effective threat detection, adhering to CJCSM 6510.01B reporting requirements and supporting the CSSP’s mission to protect data across a wide spectrum of sources and locations.
Responsibilities include:- Develop, implement, and maintain custom, high-fidelity detection rules and logic in the Elastic Security platform specifically targeting adversary TTPs mapped to the MITRE ATT&CK® framework.
- Develop and prioritize risk-based alerting mechanisms to focus detection efforts on high-impact threats, aligning with organizational risk assessments.
- Analyze threat intelligence to create and refine detection mechanisms tailored to the customer’s environment.
- Validate and test detection rules to ensure accuracy, minimize false positive and benign positive matches, and enhance threat identification capabilities.
- Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.
- Maintain and update detection tools and signatures in response to evolving threats, ensuring compliance with CJCSM 6510.01B and other applicable directives.
- Compile and maintain internal standard operating procedure (SOP) documentation for detection creation and implementation processes.
- Coordinate with reporting agencies and subscriber sites to align detection strategies with operational needs and threat intelligence.
- Participate in program reviews, product evaluations, and onsite certification evaluations to assess detection tool efficacy.
- Overtime may be required to support detection implementation or incident response actions (Surge).
- Up to 10% travel may be required.
- 5+ years of experience working in a CSSP, SOC, or similar environment.
- 2+ years of experience with signature development, detection logic creation and optimization on multiple platforms.
- Experience in threat detection engineering, threat hunting, or a related role with hands-on experience using the Elastic Stack, Kibana Query Language (KQL), Event Query Language (EQL), Elasticsearch Query Language (ES|QL) and/or Elastic Defend.
- Experience with threat intelligence platforms and indicator management.
- Proficient knowledge of detection creation and implementation processes.
- Expertise in IDS/IPS solutions, including signature development and optimization.
- Strong understanding of the indicator lifecycle, including initial discovery, development, operational maturity, and long-term sustainment.
- Effective verbal and written communication skills.
- Ability to solve complex problems independently.
- Preferred certifications: Elastic Certified Analyst; Elastic Certified SIEM Analyst, Elastic Certified Engineer.
Certifications Required: DoD 8570 IAT Level II and DoD 8140 CSSP-specific certification.
Security Clearance Required: DoD Secret Clearance.
Education Required: Bachelor’s Degree Area(s) of Study of relevant discipline and 5 years of experience. OR, at least 8 years of experience working in a CSSP, SOC, or similar.
About BreakPoint Labs
Sourced by ZipRecruiter
Industry
Network security
Company size
11 - 50 Employees
Headquarters location
Falls Church, VA, US
Year founded
2015