1

Incident Response Analyst Jobs (NOW HIRING)

ASMGi - Cyber Incident Response Analyst General Summary: As a key member of ASMGi's Information Security Incident Response Team this individual will be responsible for various parts of the incident ...

What You Can Expect We're seeking a Senior Incident Response Analyst to join our cybersecurity incident response team. This is a hands-on technical role responsible for investigating and responding ...

Position Summary The Sr. Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role blends technical ...

As a Senior Incident Response Analyst, you'll be watching over our corporate environment and cloud services, hunting for signs of compromise, safeguarding the data and systems belonging to Atlassian ...

Incident Response Analyst I

Austin, TX · On-site

$59K - $94K/yr

Incident Response Analyst III Location: Austin, TX * Scope * Entry-level monitoring; triages basic alerts; supports investigations. * Conducts initial incident investigations, escalates confirmed ...

Showing results 41-60

Incident Response Analyst information

See salary details

$22

$46

$62

How much do incident response analyst jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for incident response analyst in the United States is $46.45, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $52.64 per hour, depending on experience, location, and employer.

What does an incident response analyst do?

An Incident Response Analyst is responsible for identifying, investigating, and responding to cybersecurity incidents within an organization. They monitor networks and systems for security breaches, analyze potential threats, and take action to contain and mitigate any attacks. In addition, they document findings, coordinate with other IT and security teams, and help improve the organization's overall security posture by recommending preventative measures. Their role is critical in minimizing damage from cyber incidents and ensuring business continuity.

What does an incident response analyst do?

An incident response analyst works with an incident response team to identify and monitor security threats to an organization’s cyber systems. Your responsibilities as an incident response analyst are to prevent escalation of severe security threats, provide reports to the organization’s security team, utilize tools to minimize the effects of a security breach on the computer network, and perform an analysis to ensure that the organization’s computer network is clear of threats. Your duties also include implementing and optimizing security tools to prevent the same security issues from happening again. You may communicate with law enforcement about security threats if necessary.

What types of incidents does an incident response analyst typically handle, and how do they prioritize them?

Incident Response Analysts commonly handle a variety of security incidents, including malware infections, phishing attacks, unauthorized access attempts, and data breaches. They prioritize incidents based on factors such as potential business impact, severity, and the sensitivity of affected data. Analysts often use established frameworks and playbooks to assess and triage incidents, ensuring the most critical threats are addressed first. Collaboration with IT, security teams, and sometimes legal or compliance departments is key to effective resolution and minimizing risk.

What are the key skills and qualifications needed to thrive as an incident response analyst, and why are they important?

To thrive as an Incident Response Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident handling, often supported by a degree in information security or related fields. Familiarity with security information and event management (SIEM) tools, forensic software, and certifications like GIAC or CISSP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for coordinating response efforts and reporting findings. These skills ensure rapid detection, containment, and resolution of security incidents, protecting organizational assets and reputation.

What is the difference between Incident Response Analyst vs Security Analyst?

AspectIncident Response AnalystSecurity Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, CISSP, CEH (sometimes)
Work EnvironmentPrimarily in cybersecurity teams, focused on incident handling and responseBroader security operations, including monitoring, analysis, and policy enforcement
Employer & Industry UsageTech companies, government agencies, cybersecurity firmsFinancial institutions, healthcare, government, and corporate sectors

Incident Response Analysts specialize in identifying, managing, and mitigating cybersecurity incidents, while Security Analysts have a broader role in monitoring security systems, analyzing threats, and implementing security measures. Both roles require similar certifications and often work within the same organizations, but Incident Response Analysts focus more on reactive incident handling, whereas Security Analysts cover proactive security measures.

What cities are hiring for Incident Response Analyst jobs?

Cities with the most Incident Response Analyst job openings:

What are the most commonly searched types of Incident Response Analyst jobs?

The most popular types of Incident Response Analyst jobs are:

Who are the top companies hiring for Incident Response Analyst jobs?

The top employers for Incident Response Analyst jobs are:

What states have the most Incident Response Analyst jobs?

States with the most job openings for Incident Response Analyst jobs include:

What are popular job titles related to Incident Response Analyst jobs?

For Incident Response Analyst jobs, the most frequently searched job titles are:

Infographic showing various Incident Response Analyst job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 76% Full Time, 21% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $96,618 per year, or $46.5 per hour.

Cyber Incident Response Analyst

Cleveland, OH • On-site

ASMGi
IT Services • 51 - 200 employees

Full-time

Re-posted 6 days ago


Job description

ASMGi - Cyber Incident Response Analyst
General Summary:
As a key member of ASMGi’s Information Security Incident Response Team this individual will be responsible for various parts of the incident response process - detection, validation, containment, remediation, and communication - for IT based security events and incidents impacting ASMGi’s clients.
This individual will be responsible for the rapid response and resolution of security incidents including the ASMGi MDR / MSOC plus client’s environments. This will involve coordinating with teams including Legal, Security Operations and Forensics experts, internal or external, to identify root cause, restore services and communicate status to affected stakeholders.
This role will act as the escalation path for the ASMGi Operations Team to validate findings and identify scope of events and support during larger investigations. This individual will act as an internal and client facing resource while interacting with the third-party Security Operations Center as applicable.
Principal Accountabilities:
25% - Client Incident Response Onboarding and Program Development.
  • Work with ASMGi MDR / MSOC plus Service clients as part of the overall service and specifically the Incident Response Program Development including Incident Response Policy, Incident Response Plan, and Incident Response Playbook development and adoption.
  • Conduct client Tabletop Exercises on an annual basis based on the adopted Incident Response Playbook as part of the ASMGi MDR / MSOC plus Incident Response Service.
50% - Incident Response
  • Perform Level 2 and Level 3 computer security incident response activities including coordinating with the Security Operations Center and Forensics experts, internal and external.
  • Analyze, track and triage anomalies that have been escalated to ensure appropriate identification of risk to ASMGi MDR / MSOC plus clients.
  • Oversee the forensic analysis of cybersecurity incidents impacting ASMGi MDR / MSOC plus clients.
  • Understand and research emerging threats and current trends that may impact customers along with mitigation/resolutions for such threats.
  • Communicate and coordinate response efforts including working with ASMGi MDR / MSOC plus client’s I.T., Business Leaders, and Third Parties to mitigate the impact of the risk and provide a lead role as part of the ASMGi Computer Security Incident Response Team (CSIRT).
  • Prepare incident reports of analysis and methodology and results of investigation to be submitted to ASMGi MDR / MSOC plus clients.
25% - Assist with Incident Management Strategy Development, Consulting and Management of Third-Party Security Operations Center.
  • Leverage lessons learned, threat modeling and emerging industry better practice, to analyze the effectiveness of the existing program (policies, technology, and awareness) to continuously improve the Incident Management Program.
  • Review industry frameworks, emerging threats, and best practice to advance the ASMGi MDR / MSOC plus Service.
  • Partner with ASMGi partners and internal groups to improve the ASMGi MDR / MSOC plus service and capabilities.
  • Assist with management of third-party business relationships for the security operations center and service levels. Identify potential gaps including procedures needed to mitigate risk and assist with appropriate solutions.
Job Complexity
  • Appropriately balances security risk and business impact to ensure that ASMGi’s use of detection/response controls are effective.
  • Ability to build operational processes using industry best-practice that are tailored to the ASMGi MDR / MSOC plus client’s organization, system, and processes.
  • Ability to effectively communicate risk including corrective action plans/recommendations to non-technical audiences including the ASMGi MDR / MSOC plus client’s Executives and the Board of Directors leveraging the MDR / MSOC plus service.
  • Ability to create effective reports and presentations tailored to different audiences to ensure transparency and understanding of the ASMGi MDR / MSOC plus Service.
  • Assist with development of MDR / MSOC plus Service roadmap.
Job Specifications
Minimum education required: Bachelor's Degree Required
Education desired: Bachelor of Science
Years of relevant experience: 7 – 10 +
Knowledge, skills, and abilities required:
  • High level of technical expertise in information security, including deep familiarity with relevant penetration and intrusion techniques and attack vectors.
  • Cybersecurity in large complex companies including knowledge of security and privacy breach laws and regulatory reporting.
  • Proven experience working with Security Operations Center services, forensics firms.
  • Demonstrated ability to lead and develop cohesive and collaborative management and operational teams internally and with a third-party.
  • Proven experience implementing policies, procedures, and technology to detect and recover from a cybersecurity attack.
  • Ability to demonstrate strong computer knowledge networks, desktops, servers, cloud, and software as a service technology.
  • Expertise with next generation firewalls, Endpoint Detection and Response, Microsoft Advanced Threat Protection, Azure, and Office 365, Zero Day Threat Detection Technology, Threat Intelligence Feeds, Forensics, Data Loss Prevention Software, Web Proxies, Web Application Firewalls.
  • Strong problem-solving and trouble-shooting skills.
  • Strong communication skills including writing reports and presenting to senior executives.
  • Demonstrated connections to external Incident Response leaders and learning organizations.
Working Conditions
  • Normal corporate office environment and remote / virtual based on COVID-19.
  • On call work is required.