1

Incident Handler Jobs (NOW HIRING)

Senior Incident Handler

IL · Remote

$18.25 - $22/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security events--driving the response, raising the bar on how we work, and helping mature the team toward a ...

Senior Incident Handler

$18.25 - $22/hr

As our Senior Incident Handler, you'll be the technical anchor for our most significant security events-driving the response, raising the bar on how we work, and helping mature the team toward a ...

Incident Handler Tier 2

Monterey, CA · On-site

$98K - $109K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 2 to work with cybersecurity incident response processes, procedures, and remediation practices. This is a great opportunity ...

Incident Handler Tier 2

Monterey, CA · On-site

$98K - $109K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 2 to work with cybersecurity incident response processes, procedures, and remediation practices. This is a great opportunity ...

Incident Handler Tier 2

Monterey, CA · On-site

$98K - $109K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 2 to work with cybersecurity incident response processes, procedures, and remediation practices. This is a great opportunity ...

Must have, or be able to obtain within 3 months, one of the following certifications: CERT Certified Computer Security Incident Handler (CSIH), ECC Certified Ethical Hacker (CEH), GIAC Certified ...

Incident Handler Tier I

Monterey, CA · On-site

$82K - $91K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 1 position offering on-the-job training (JOT) on cybersecurity incident response processes, procedures, and remediation ...

Incident Handler Tier I

Monterey, CA · On-site

$82K - $91K/yr

ARSIEM is looking for a motivated individual for an Incident Handler Tier 1 position offering on-the-job training (JOT) on cybersecurity incident response processes, procedures, and remediation ...

ARSIEM is looking for a motivated individual for an Incident Handler Tier 1 position offering on-the-job training (JOT) on cybersecurity incident response processes, procedures, and remediation ...

Relevant certifications including GIAC Certified Incident Handler (GCIH), Certified Incident Response Handler (GCFA) or similar * Experience with using SIEM systems, network security tools, and log ...

next page

Showing results 1-20

Incident Handler information

See salary details

$12

$19

$26

How much do incident handler jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for incident handler in the United States is $19.25, according to ZipRecruiter salary data. Most workers in this role earn between $17.07 and $20.67 per hour, depending on experience, location, and employer.

What is an incident handler?

Incident handlers are cybersecurity professionals responsible for managing and responding to security incidents within an organization. Their main duties include identifying, investigating, and mitigating cyber threats or breaches to minimize damage and recover normal operations. They also develop and implement incident response plans, analyze security alerts, and coordinate with other teams to ensure effective communication during incidents. Incident handlers play a crucial role in maintaining an organization’s security posture and ensuring regulatory compliance.

What are the most common challenges incident handlers face when responding to security incidents, and how can these be addressed in a team environment?

Incident Handlers often encounter challenges such as rapidly evolving threats, incomplete information, and coordinating with multiple departments under time pressure. Effective communication and a well-defined incident response plan are crucial for overcoming these obstacles. In a team environment, regularly practicing incident simulations and debriefing after real events help ensure everyone understands their roles and can collaborate efficiently, ultimately reducing response times and improving outcomes.

What are the key skills and qualifications needed to thrive as an incident handler, and why are they important?

To thrive as an Incident Handler, you need a solid understanding of cybersecurity principles, risk assessment, and network protocols, often supported by a degree in computer science or related certifications like CEH or CISSP. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and forensic analysis software is essential. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for coordinating responses and documenting incidents. These skills and qualities are vital to quickly mitigate threats, minimize damage, and maintain organizational security.

What is the difference between Incident Handler vs Security Analyst?

AspectIncident HandlerSecurity Analyst
CertificationsCompTIA Security+, GIAC GCIHCompTIA Security+, CISSP, GIAC GSEC
Work EnvironmentResponds to security incidents, investigates breachesMonitors security systems, analyzes threats
Employer & Industry UsageCybersecurity teams in various industries, incident response firmsIT departments, security operations centers (SOCs)

Incident Handlers focus on responding to and managing security incidents, while Security Analysts primarily monitor, analyze, and prevent threats. Both roles require similar certifications and often work within the same environments, but Incident Handlers are more reactive, dealing with incidents as they occur, whereas Security Analysts are proactive in threat detection and prevention.

More about Incident Handler jobs
Who are the top companies hiring for Incident Handler jobs? The top employers for Incident Handler jobs are:
What states have the most Incident Handler jobs? States with the most job openings for Incident Handler jobs include:
Infographic showing various Incident Handler job openings in the United States as of August 2026, with employment types broken down into 82% Full Time, and 18% Contract. Highlights an 100% In-person job distribution, with an average salary of $40,046 per year, or $19.3 per hour.

Senior Incident Handler

Allstate

IL • Remote

$18.25 - $22/hr

Full-time

This job post has expired today. Applications are no longer accepted.


Allstate Insurance rating

7.5

Company rating: 7.5 out of 10

Based on 564 frontline employees who took The Breakroom Quiz

217th of 304 rated insurance


Job description

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. 

Job Description

We're rebuilding incident response from the ground up—and we want a proven responder to help lead the way.
This is a chance to bring your hard-won expertise into a next-generation Security Operations program at Fortune 100 scale, where rapid response, automation, and AI-driven investigation are core to how we operate. As our Senior Incident Handler, you'll be the technical anchor for our most significant security events—driving the response, raising the bar on how we work, and helping mature the team toward a formal, scalable incident command model we're building for the future.
If you've handled the incidents that make headlines (or quietly prevented them from becoming headlines), bring the instincts of a seasoned incident commander, and can move seamlessly from the server room to the boardroom, this is where your experience turns into real influence. What You''ll Own
  • Incident Handling & Response Leadership: Serve as the lead responder during critical incidents—owning the full lifecycle from detection through containment, eradication, and recovery. You'll help run the war room, coordinate responders, and make confident calls with incomplete information. 

  • Cross-Functional Coordination: Unify analysts, infrastructure, application owners, legal, comms, and third-party partners into a single, fast-moving response. Relentless focus on reducing dwell time and mean-time-to-respond. 

  • Executive Communication: Be a trusted voice during high-severity events—translating fast-moving technical realities into clear business impact for stakeholders up to the C-suite. You build calm and confidence when it matters most. 

  • Deep Threat Investigation: Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs, network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss—leveraging EDR/XDR, SIEM, and cloud telemetry. 

  • AI & Automation Leadership: Help modernize our SOC by putting cutting-edge automation and AI-assisted tooling to work—accelerating triage and enrichment without sacrificing human judgment. 

  • Team Uplevel & Continuous Improvement: Raise the standard of how the team responds—sharpening detections, playbooks, and controls through meaningful after-action reviews, and helping shape the practices that will underpin our future incident command function. 

What You Bring
  • Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end. Financial services or insurance experience is a plus—but great responders come from everywhere. 

  • Command-level instincts: Demonstrated ability to act as an incident commander or technical lead in high-stakes moments—running major bridge calls and making decisive calls fast. You bring the judgment that helps a team operate like a mature command function. 

  • Technical depth: Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on-prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, PowerShell). 

  • Communication range: Exceptional written and verbal skills; equally credible with engineers and executives. 

  • Automation mindset: Enthusiasm for SOAR, ML-based tooling, and LLMs to elevate response workflows. 

  • Credentials: CISSP, GCIA, GCIH, GCFA, OSCP or other certifications preferred. 


Why This Role

You'll join at a pivotal moment—bringing your expertise to a team that's actively maturing, with the opportunity to help shape the incident command function we're building next. This is a role for someone who wants their fingerprints on how a Fortune 100 responds to the threats ahead. If you're ready to lead through crisis, outthink sophisticated adversaries, and elevate a team around you—let's talk. 
#LI-JJ1

Skills

Cross-Functional Collaboration, Cyber Incident Response, Cyber Investigations, Cybersecurity Operations, Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive Communications, Forensic Analysis, Incident Handling, IT Automation, IT Security Architecture, Malware Analysis, Network Security, Penetration Testing, Scripting, Security Incident Response, Technical Leadership, Technical Mentoring, Technology Leadership

Compensation

Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications.

The candidate(s) offered this position will be required to submit to a background investigation.

Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.

Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.


For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.

To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.

To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.

It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.

When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.


What Allstate Insurance employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom