1

Incident Response Analyst Jobs (NOW HIRING)

The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...

Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US ...

Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US ...

ASMGi - Cyber Incident Response Analyst General Summary: As a key member of ASMGi's Information Security Incident Response Team this individual will be responsible for various parts of the incident ...

Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US ...

OR · On-site

$25 - $26/hr

The Incident Response Analyst I will also work with the customer through different types of media, to provide a superior customer experience through tactical troubleshooting, monitoring, and ...

OR

$25 - $26/hr

The Incident Response Analyst I will also work with the customer through different types of media, to provide a superior customer experience through tactical troubleshooting, monitoring, and ...

next page

Showing results 1-20

Incident Response Analyst information

See salary details

$22

$46

$62

How much do incident response analyst jobs pay per hour?

As of Aug 4, 2026, the average hourly pay for incident response analyst in the United States is $46.45, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $52.64 per hour, depending on experience, location, and employer.

What is the difference between Incident Response Analyst vs Security Analyst?

AspectIncident Response AnalystSecurity Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, CISSP, CEH (sometimes)
Work EnvironmentPrimarily in cybersecurity teams, focused on incident handling and responseBroader security operations, including monitoring, analysis, and policy enforcement
Employer & Industry UsageTech companies, government agencies, cybersecurity firmsFinancial institutions, healthcare, government, and corporate sectors

Incident Response Analysts specialize in identifying, managing, and mitigating cybersecurity incidents, while Security Analysts have a broader role in monitoring security systems, analyzing threats, and implementing security measures. Both roles require similar certifications and often work within the same organizations, but Incident Response Analysts focus more on reactive incident handling, whereas Security Analysts cover proactive security measures.

What are the key skills and qualifications needed to thrive as an incident response analyst, and why are they important?

To thrive as an Incident Response Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident handling, often supported by a degree in information security or related fields. Familiarity with security information and event management (SIEM) tools, forensic software, and certifications like GIAC or CISSP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for coordinating response efforts and reporting findings. These skills ensure rapid detection, containment, and resolution of security incidents, protecting organizational assets and reputation.

What types of incidents does an incident response analyst typically handle, and how do they prioritize them?

Incident Response Analysts commonly handle a variety of security incidents, including malware infections, phishing attacks, unauthorized access attempts, and data breaches. They prioritize incidents based on factors such as potential business impact, severity, and the sensitivity of affected data. Analysts often use established frameworks and playbooks to assess and triage incidents, ensuring the most critical threats are addressed first. Collaboration with IT, security teams, and sometimes legal or compliance departments is key to effective resolution and minimizing risk.

What does an incident response analyst do?

An Incident Response Analyst is responsible for identifying, investigating, and responding to cybersecurity incidents within an organization. They monitor networks and systems for security breaches, analyze potential threats, and take action to contain and mitigate any attacks. In addition, they document findings, coordinate with other IT and security teams, and help improve the organization's overall security posture by recommending preventative measures. Their role is critical in minimizing damage from cyber incidents and ensuring business continuity.

What does an incident response analyst do?

An incident response analyst works with an incident response team to identify and monitor security threats to an organization’s cyber systems. Your responsibilities as an incident response analyst are to prevent escalation of severe security threats, provide reports to the organization’s security team, utilize tools to minimize the effects of a security breach on the computer network, and perform an analysis to ensure that the organization’s computer network is clear of threats. Your duties also include implementing and optimizing security tools to prevent the same security issues from happening again. You may communicate with law enforcement about security threats if necessary.

What cities are hiring for Incident Response Analyst jobs? Cities with the most Incident Response Analyst job openings:
What are the most commonly searched types of Incident Response Analyst jobs? The most popular types of Incident Response Analyst jobs are:
Who are the top companies hiring for Incident Response Analyst jobs? The top employers for Incident Response Analyst jobs are:
What states have the most Incident Response Analyst jobs? States with the most job openings for Incident Response Analyst jobs include:
What are popular job titles related to Incident Response Analyst jobs? For Incident Response Analyst jobs, the most frequently searched job titles are:
Infographic showing various Incident Response Analyst job openings in the United States as of July 2026, with employment types broken down into 66% Full Time, 4% Part Time, and 30% Contract. Highlights an 61% Physical, 5% Hybrid, and 34% Remote job distribution, with an average salary of $96,618 per year, or $46.5 per hour.

Incident Response Analyst

Cyber Synergy Consulting Group

Washington, DC • On-site

$100K - $125K/yr

Full-time

Re-posted 21 days ago


Job description

Incident Response Analyst (Task 4 – Federal Cybersecurity Contract)

Location: Remote with occasional on-site (Washington, D.C. Metro Area)

Employment Type: Full-Time

Clearance: Public Trust (or eligibility to obtain)

We are seeking an experienced Incident Response Analyst to support Task 4 – Incident Response Management on a federal cybersecurity services contract. This role provides front-line security event triage, investigation, reporting, and coordination across multiple federal cybersecurity teams.

The ideal candidate has hands-on experience with enterprise IR tooling-CrowdStrike, FireEye (Trellix), Splunk, NetWitness, and Magnet AXIOM-and is comfortable working in a high-tempo operational environment aligned with federal cybersecurity frameworks (NIST, FISMA, OMB).


Key Responsibilities
  • Perform initial triage of security events from SIEM, EDR, NDR, and log sources, including CrowdStrike, FireEye/Trellix, Splunk, NetWitness, and related platforms.

  • Conduct incident investigations, including host and network forensics, log analysis, and evidence review using tools such as NetWitness and AXIOM.

  • Coordinate closely with HHS CSIRC, OpDiv incident response teams, system owners, and security engineering staff to validate findings and recommend containment actions.

  • Provide daily updates, SITREPs, and written documentation of incident status, investigative steps, and remediation recommendations.

  • Develop incident dashboards and knowledge base documentation within Splunk and other IR platforms.

  • Support containment, eradication, and recovery efforts aligned to federal IR procedures.

  • Participate in tabletop exercises, readiness assessments, and operational continuity testing.

  • Monitor and manage the Incident Response Team (IRT) mailbox; escalate urgent items within required SLAs.

  • Assist with audit support, evidence gathering, and post-incident reviews.

  • Contribute to continuous improvement of incident response processes and playbooks.


Required Qualifications
  • 2–5+ years of experience in cybersecurity operations, SOC analysis, or incident response.

  • Direct hands-on experience with IR tools, including:

    • CrowdStrike Falcon (EDR)

    • FireEye/Trellix (HX, Helix, or equivalent)

    • Splunk (SIEM, dashboards, search queries)

    • NetWitness (network forensics, packet analysis)

    • Magnet AXIOM (host forensics)

  • Strong understanding of adversary techniques, malware behavior, incident timelines, and forensic artifacts.

  • Familiarity with NIST 800-61, NIST 800-53, FISMA, OMB guidance.

  • Ability to clearly document investigations and communicate findings to technical and non-technical audiences.

  • Eligibility to obtain and maintain a Public Trust clearance.


Preferred Qualifications
  • Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.).

  • Certifications such as Security+, CySA+, CEH, GCIH, GCIA, CHFI, or related.

  • Experience performing threat hunting across EDR, SIEM, and NDR tools.

  • Familiarity with packet analysis tools (Wireshark) and scripting languages (Python, PowerShell).

  • Experience with ServiceNow or similar ticketing platforms


Work Schedule & Expectations
  • Core hours: 7:00 AM – 5:00 PM EST, Monday through Friday, with the flexibility to support after-hours incidents as needed.

  • Participation in on-call rotations may be required.

  • Remote work permitted with reliable connectivity and camera-enabled participation.