1

Incident Handler Jobs in Arizona (NOW HIRING)

SOC Watch Officer

Chandler, AZ · On-site

$17.50 - $20.25/hr

... Incident Handler), GCIA (GIAC Certified Intrusion Analyst), or GECD (GIAC Enterprise Cloud Defense) Group 2 -- DoD 8570 CSSP * Any certification qualifying under the DoD 8570 CSSP Analyst ...

... Incident Handler), GCIA (GIAC Certified Intrusion Analyst), or GECD (GIAC Enterprise Cloud Defense) Group 2 -- DoD 8570 CSSP * Any certification qualifying under the DoD 8570 CSSP Analyst ...

... Incident Handler), GCIA (GIAC Certified Intrusion Analyst), or GECD (GIAC Enterprise Cloud Defense) Group 2 -- DoD 8570 CSSP * Any certification qualifying under the DoD 8570 CSSP Analyst ...

RESIDENT CARE COORDINATOR

Phoenix, AZ · On-site

$17.25 - $22.50/hr

Respond to emergencies and ensure proper incident reporting * Participate in care conferences and ... Provide and maintain current Food Handlers Certification * Clean driving record and valid driver ...

RESIDENT CARE COORDINATOR

Phoenix, AZ · On-site

$17.25 - $22.50/hr

Respond to emergencies and ensure proper incident reporting * Participate in care conferences and ... Provide and maintain current Food Handlers Certification * Clean driving record and valid driver ...

Kids Club Team Member

Tucson, AZ · On-site

$15.70 - $16.87/hr

Create detailed incident reports for little Chuzers as needed Perks & Benefits: * 401k * Free CPR, First Aid, and AED Training * Free food handler training and certification (for locations with ...

Kids Club Team Member

Tucson, AZ · On-site

$15.70 - $16.87/hr

Create detailed incident reports for little Chuzers as needed Perks & Benefits: * 401k * Free CPR, First Aid, and AED Training * Free food handler training and certification (for locations with ...

next page

Showing results 1-20

Incident Handler information

See Arizona salary details

$11

$17

$25

How much do incident handler jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for incident handler in Arizona is $17.94, according to ZipRecruiter salary data. Most workers in this role earn between $15.91 and $19.28 per hour, depending on experience, location, and employer.

What is an incident handler?

Incident handlers are cybersecurity professionals responsible for managing and responding to security incidents within an organization. Their main duties include identifying, investigating, and mitigating cyber threats or breaches to minimize damage and recover normal operations. They also develop and implement incident response plans, analyze security alerts, and coordinate with other teams to ensure effective communication during incidents. Incident handlers play a crucial role in maintaining an organization’s security posture and ensuring regulatory compliance.

What are the most common challenges incident handlers face when responding to security incidents, and how can these be addressed in a team environment?

Incident Handlers often encounter challenges such as rapidly evolving threats, incomplete information, and coordinating with multiple departments under time pressure. Effective communication and a well-defined incident response plan are crucial for overcoming these obstacles. In a team environment, regularly practicing incident simulations and debriefing after real events help ensure everyone understands their roles and can collaborate efficiently, ultimately reducing response times and improving outcomes.

What are the key skills and qualifications needed to thrive as an incident handler, and why are they important?

To thrive as an Incident Handler, you need a solid understanding of cybersecurity principles, risk assessment, and network protocols, often supported by a degree in computer science or related certifications like CEH or CISSP. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and forensic analysis software is essential. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for coordinating responses and documenting incidents. These skills and qualities are vital to quickly mitigate threats, minimize damage, and maintain organizational security.

What is the difference between Incident Handler vs Security Analyst?

AspectIncident HandlerSecurity Analyst
CertificationsCompTIA Security+, GIAC GCIHCompTIA Security+, CISSP, GIAC GSEC
Work EnvironmentResponds to security incidents, investigates breachesMonitors security systems, analyzes threats
Employer & Industry UsageCybersecurity teams in various industries, incident response firmsIT departments, security operations centers (SOCs)

Incident Handlers focus on responding to and managing security incidents, while Security Analysts primarily monitor, analyze, and prevent threats. Both roles require similar certifications and often work within the same environments, but Incident Handlers are more reactive, dealing with incidents as they occur, whereas Security Analysts are proactive in threat detection and prevention.

What are popular job titles related to Incident Handler jobs in Arizona? For Incident Handler jobs in Arizona, the most frequently searched job titles are:
What job categories do people searching Incident Handler jobs in Arizona look for? The top searched job categories for Incident Handler jobs in Arizona are:
Infographic showing various Incident Handler job openings in Arizona as of August 2026, with employment types broken down into 82% Full Time, and 18% Contract. Highlights an 100% In-person job distribution, with an average salary of $37,318 per year, or $17.9 per hour.

SOC Watch Officer

Harmonia | Revolutional

Chandler, AZ • On-site

$17.50 - $20.25/hr

Other

Re-posted 9 days ago


Job description

SOC Watch Officer

As a SOC Watch Officer at Revolutional, you are the senior authority on the floor during your watch. You are responsible for the operational integrity of a 24/7/365 security operations mission — overseeing analyst activity, managing active security events, and making real-time decisions that protect a large-scale federal network environment.

You are not a passive supervisor. You monitor what your analysts are working, catch what they miss, direct response actions on active incidents, and ensure nothing falls through the cracks across your shift. When events escalate, you are the first line of senior judgment before it reaches the SOC Team Lead.

Responsibilities
  • Maintain situational awareness across all active monitoring queues, open incidents, and security events during assigned watch
  • Supervise SOC analysts on shift; direct workload, review analyst actions, and ensure response quality and timeliness meet program standards
  • Make real-time operational decisions on event triage, escalation, and response prioritization during your watch
  • Serve as the shift escalation point for complex or high-severity events; determine when incidents require SOC Team Lead or program leadership notification
  • Ensure accurate, timely documentation of all security events, analyst actions, and incident status throughout the shift
  • Conduct shift turnover briefings; communicate open incidents, active threats, and watch floor status to incoming personnel with full fidelity
  • Monitor SOC tooling and sensor coverage during watch; escalate gaps, outages, or anomalies that affect detection capability
  • Enforce adherence to SOC playbooks, standard operating procedures, and incident handling protocols across the shift team
  • Support incident response activities through containment and remediation, coordinating with relevant technical teams as needed
  • Contribute to after-action reviews, shift reports, and continuous improvement of watch floor operations
What You Bring (Requirements) Baseline Requirements
  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 3 or more years of supervisory experience in a security operations or related technical environment
  • Substantial hands-on security operations experience, including monitoring, detection, and incident response in enterprise network environments
  • Active Secret clearance; Top Secret/SCI eligibility required
Technical & Domain Capabilities
  • Deep familiarity with SOC operations: continuous monitoring, alert triage, log analysis, and threat detection across complex network environments
  • Experience managing or directing analyst teams during active security incidents
  • Proficiency with SIEM platforms, EDR tools, and network monitoring technologies used in enterprise SOC environments
  • Understanding of incident response procedures from detection through containment and remediation
  • Familiarity with FISMA, NIST incident response frameworks, and federal security operations standards
  • Working knowledge of network security architectures including LANs, WANs, and cloud environments
Core Strengths
  • Decisive under pressure — you make sound calls on active incidents without waiting for perfect information
  • Strong situational awareness: you track multiple active events simultaneously and know which ones need your attention first
  • Effective shift supervisor who holds analysts accountable and maintains operational discipline across the watch floor
  • Clear communicator who writes clean incident documentation and delivers crisp shift handoffs
Certifications

One certification from each of the following groups is required:

Group 1 — Security Operations
  • CASP+ (CompTIA Advanced Security Practitioner), CCSP (Certified Cloud Security Professional), SSCP (Systems Security Certified Practitioner), GMON (GIAC Continuous Monitoring), GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), or GECD (GIAC Enterprise Cloud Defense)
Group 2 — DoD 8570 CSSP
  • Any certification qualifying under the DoD 8570 CSSP Analyst, Infrastructure Support, or Incident Responder categories

Note: 6 years of equivalent hands-on security operations experience may be considered in lieu of one certification requirement.

Nice to Have (Differentiators)
  • Experience as a watch officer or shift lead in a federal civilian, defense, or intelligence SOC environment
  • Familiarity with tier-less SOC operations and cross-functional incident coordination
  • Background in threat hunting, APT detection, or kill-chain-based response methodologies
  • Experience with Zero Trust monitoring or cloud-based security operations
  • Active TS/SCI clearance