1

Incident Handler Jobs (NOW HIRING)

Incident Response Team Lead

Reston, VA · On-site

$155K - $180K/yr

GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH); GIAC Certified Forensic Analyst (GCFA); SANS GIAC Certified Enterprise Defender (GCED) or Other Information Assurance ...

Incident Response Team Lead

Reston, VA · On-site

$155K - $180K/yr

GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH); GIAC Certified Forensic Analyst (GCFA); SANS GIAC Certified Enterprise Defender (GCED) or Other Information Assurance ...

Manager, Incident Response

Mclean, VA · On-site +1

$150K - $175K/yr

GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE, or equivalent certifications * Proven track record of complex ...

Preferred certifications include GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE or equivalent credentials If you ...

GIAC Certified Incident Handler * EC-Council's Certified Incident Handler (ECIH) * GIAC Certified Incident Handler (GCIH) * Incident Handling & Response Professional (IHRP) * Certified Computer ...

Manager, Incident Response

Mclean, VA · Remote

$150K - $175K/yr

GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE, or equivalent certifications * Proven track record of complex ...

Senior Incident Response Consultant

Mclean, VA · On-site +1

$110K - $136K/yr

Preferred certifications include GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE or equivalent credentials If you ...

Showing results 41-60

Incident Handler information

See salary details

$12

$19

$26

How much do incident handler jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for incident handler in the United States is $19.25, according to ZipRecruiter salary data. Most workers in this role earn between $17.07 and $20.67 per hour, depending on experience, location, and employer.

What is an incident handler?

Incident handlers are cybersecurity professionals responsible for managing and responding to security incidents within an organization. Their main duties include identifying, investigating, and mitigating cyber threats or breaches to minimize damage and recover normal operations. They also develop and implement incident response plans, analyze security alerts, and coordinate with other teams to ensure effective communication during incidents. Incident handlers play a crucial role in maintaining an organization’s security posture and ensuring regulatory compliance.

What are the most common challenges incident handlers face when responding to security incidents, and how can these be addressed in a team environment?

Incident Handlers often encounter challenges such as rapidly evolving threats, incomplete information, and coordinating with multiple departments under time pressure. Effective communication and a well-defined incident response plan are crucial for overcoming these obstacles. In a team environment, regularly practicing incident simulations and debriefing after real events help ensure everyone understands their roles and can collaborate efficiently, ultimately reducing response times and improving outcomes.

What are the key skills and qualifications needed to thrive as an incident handler, and why are they important?

To thrive as an Incident Handler, you need a solid understanding of cybersecurity principles, risk assessment, and network protocols, often supported by a degree in computer science or related certifications like CEH or CISSP. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and forensic analysis software is essential. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for coordinating responses and documenting incidents. These skills and qualities are vital to quickly mitigate threats, minimize damage, and maintain organizational security.

What is the difference between Incident Handler vs Security Analyst?

AspectIncident HandlerSecurity Analyst
CertificationsCompTIA Security+, GIAC GCIHCompTIA Security+, CISSP, GIAC GSEC
Work EnvironmentResponds to security incidents, investigates breachesMonitors security systems, analyzes threats
Employer & Industry UsageCybersecurity teams in various industries, incident response firmsIT departments, security operations centers (SOCs)

Incident Handlers focus on responding to and managing security incidents, while Security Analysts primarily monitor, analyze, and prevent threats. Both roles require similar certifications and often work within the same environments, but Incident Handlers are more reactive, dealing with incidents as they occur, whereas Security Analysts are proactive in threat detection and prevention.

More about Incident Handler jobs
Who are the top companies hiring for Incident Handler jobs? The top employers for Incident Handler jobs are:
What states have the most Incident Handler jobs? States with the most job openings for Incident Handler jobs include:
Infographic showing various Incident Handler job openings in the United States as of August 2026, with employment types broken down into 82% Full Time, and 18% Contract. Highlights an 100% In-person job distribution, with an average salary of $40,046 per year, or $19.3 per hour.

Lead Analyst - Cyber Incident Response

Raymondjames

Saint Petersburg, FL • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 2 days ago


Job description

Job Description Summary

Job Description

The financial services industry is constantly under attack by sophisticated cyber adversaries that range from nation-states to criminals. In response, the Raymond James Cyber Threat Center (CTC) is charged with ensuring all equities are secure against all tiers of adversaries. We are the central hub for Computer Network Operations and are on the front lines of security incident response, threat hunting, and intelligence. You'll be working with emerging technologies to solve challenging security problems in a fast-paced and continually evolving environment while helping steer the direction and evolution of the team. This highly visible team within the organization evaluates threats to the environment and dynamically adjusts to the ever-changing threat landscape by applying practical security knowledge to developing new detective measures to protect the firm.

The Lead Analyst - Cyber Incident Response, is a key member of the Cyber Threat Center (CTC) who serves as both a lead incident response leader and a technical engineering lead responsible for driving intelligent automation and AI-enabled cybersecurity operations. The position combines deep expertise in cyber incident response, threat hunting, malware analysis, and forensic investigations with advanced engineering capabilities in SOAR automation, AI/ML integration, orchestration platforms, and security workflow development.

This role leads security operations initiatives, mentors analysts, develops advanced automation and AI-enabled response capabilities, and operationalizes intelligent security solutions that improve threat detection, triage, containment, and remediation across the enterprise. The position partners with incident response, threat detection, security engineering, and technology teams to design scalable workflows, streamline investigations, reduce manual effort, and improve response consistency.


Essential Duties and Responsibilities:

  • Serves as a primary member of the Cyber Threat Center (CTC) who handles security events and incidents in a fast-paced environment.

  • Acts as an Incident Handler capable of managing severity 1 and severity 2 security incidents within the defined Computer Security Incident Response process.

  • Design, build, and maintain scalable automation solutions, including AI-enabled workflows to improve threat detection, triage, and incident response efficiency.

  • Develops new forensic detective and investigative capabilities using current and emerging technical solutions.

  • Shares in a weekly on-call rotation and acts as an escalation point for managed security services and Raymond James associates.

  • Leverage programming and data science techniques to develop, operationalize, and optimize machine learning models and data-driven security use cases.

  • Develop and implement advanced data correlation, enrichment, and processing strategies leveraging automation, data science, AI/ML, and LLM capabilities for threat hunting and incident response analysis.

  • Apply AI engineering principles within security operations to design, deploy, and maintain intelligent detection and response capabilities.

  • Design and execute automated and intelligent response actions to validate, contain, eradicate, and remediate security incidents.

  • Prototype, evaluate, and deploy emerging AI-driven technologies to enhance detection accuracy, reduce false positives, and accelerate response times.

  • Ensure Security Operations applications, automation pipelines, and incident ingestion processes remain healthy, resilient, and performant.

  • Drive continuous improvement by identifying gaps, recommending enhancements, and implementing innovative SOAR and AI-driven solutions.

  • Collaborate with incident response, threat intelligence, and threat hunting teams to strengthen detection and response capabilities.

Experience and Skills:

  • Bachelor's degree in Computer Science, Computer Engineering, Management Information Systems, Cybersecurity, or a related field, and 5-8 years of relevant experience in Information Security, Cybersecurity Operations and Incident Response.

  • Minimum of 4 years of hands-on incident response experience, including triage, investigation, containment, eradication, recovery, and post-incident analysis.

  • Minimum of 2 years of programming or scripting experience using at least one modern language such as Python, JavaScript, PowerShell, or Rust, with a focus on automation, data enrichment, and security operations workflows.

  • Experience designing, developing, and maintaining automation workflows that support incident response, alert triage, threat enrichment, case management, and analyst productivity.

  • Experience with API development, integration, and orchestration across security tools, cloud platforms, ticketing systems, and enterprise data sources.

  • Familiarity with agentic AI workflows, AI-assisted security operations, or the application of GenAI/LLMs to automate investigation, summarization, enrichment, decision support, and response actions.

  • Experience with Security Orchestration, Automation, and Response platforms, case management tools, or similar technologies used to streamline incident response processes.

  • Strong understanding of incident response frameworks, common attack techniques, security telemetry, and investigation workflows, including endpoint, network, identity, cloud, and email-based incidents.

  • Experience working with SIEM, EDR, SOAR, threat intelligence, log management, and cloud security platforms.

  • Ability to translate complex incident response processes into repeatable, scalable automation requirements, playbooks, and technical solutions.

  • Strong analytical, troubleshooting, and problem-solving skills with the ability to work independently and lead efforts during high-priority security incidents.

  • Excellent written and verbal communication skills, including the ability to document technical findings, explain automation logic, and communicate incident details to technical and non-technical stakeholders.

  • Ability to mentor analysts, promote automation adoption, and identify opportunities to improve incident response speed, consistency, and quality.


Licenses/Certifications:

  • One or more of the following certifications preferred: CISSP, SANS GCIH (Incident Handler), SANS GCIA (Intrusion Analyst), SANS GCFE (Forensic Analyst), Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH)


Competencies and Behaviors:

  • Analysis: Identifies, investigates, and interprets complex security issues, incidents, and operational challenges. Correlates data from multiple sources, including security tools, logs, threat intelligence, case records, and automation outputs, to draw sound conclusions and recommend effective response actions.

  • Communication: Clearly communicates technical information, incident details, automation logic, and recommendations to technical and non-technical audiences. Produces clear documentation, status updates, executive summaries, and post-incident findings that support timely understanding and decision-making.

  • Judgment and Decision Making: Applies sound judgment when evaluating incident severity, response options, automation outcomes, and operational risk. Makes or recommends timely decisions based on available facts, business impact, constraints, and probable consequences, while escalating appropriately when needed.

  • Technical and Professional Knowledge: Maintains strong knowledge of incident response, security operations, automation, scripting, AI-enabled workflows, and relevant security technologies. Stays current with emerging threats, tools, techniques, and industry practices, and applies that knowledge to improve response capabilities.

  • Building Effective Relationships: Builds trusted, collaborative relationships across Cybersecurity, Technology, business units, vendors, and leadership. Partners effectively with stakeholders to resolve incidents, improve workflows, implement automation, and support shared security objectives.

  • Automation Mindset: Identifies opportunities to improve speed, consistency, and quality through automation, orchestration, and repeatable playbooks. Balances automation with appropriate validation, oversight, and risk controls.

  • Leadership and Influence: Provides guidance to analysts, promotes best practices, and helps drive continuous improvement across incident response processes. Influences outcomes through expertise, collaboration, and clear recommendations, even without direct authority.

  • Adaptability: Responds effectively to changing priorities, emerging threats, and high-pressure incident situations. Adjusts approach as new information becomes available while maintaining focus on containment, recovery, risk reduction, and stakeholder communication.

Education

Bachelor's

Work Experience

General Experience - 6 to 10 years

Certifications

Travel

Less than 25%

Workstyle

Hybrid

The total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.

At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view.
We expect our associates at all levels to:
Grow professionally and inspire others to do the same
Work with and through others to achieve desired outcomes
Make prompt, pragmatic choices and act with the client in mind
Take ownership and hold themselves and others accountable for delivering results that matter
Contribute to the continuous evolution of the firm

At Raymond James - as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates. When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs.