Description Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The ...
Description Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The ...
Senior Incident Response Engineer (Level 3)
Austin, TX ยท On-site
$58 - $75.75/hr
Senior Incident Response Engineer (Level 3) Location: Austin, TX 78744 Duration: 6 Months Experience: 15+ Years Summary: The Tier 3 Incident Response Engineer will provide advanced intrusion ...
Quick apply
Senior Incident Response Engineer (Level 3)
Austin, TX ยท On-site
$58 - $75.75/hr
Senior Incident Response Engineer (Level 3) Location: Austin, TX 78744 Duration: 6 Months Experience: 15+ Years Summary: The Tier 3 Incident Response Engineer will provide advanced intrusion ...
Threat and Incident Response Engineer
Seattle, WA ยท On-site
$140 - $190/hr
Description Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The ...
New
Threat and Incident Response Engineer
Seattle, WA ยท On-site
$140 - $190/hr
Description Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The ...
New
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiencyin bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiencyin bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiency in bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiency in bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiencyin bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiencyin bash and at least one interpreted programming language (Python ...
IT - Incident Response Engineer
Beachwood, OH ยท On-site
$113K - $165K/yr
Eaton's Corporate Sector division is currently seeking a IT - Incident Response Engineer. The expected annual salary range for this role is $113000 - $165000 a year. This role can sit out of any US ...
IT - Incident Response Engineer
Beachwood, OH ยท On-site
$113K - $165K/yr
Eaton's Corporate Sector division is currently seeking a IT - Incident Response Engineer. The expected annual salary range for this role is $113000 - $165000 a year. This role can sit out of any US ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiency in bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiency in bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiencyin bash and at least one interpreted programming language (Python ...
Incident Response: Lead and conduct comprehensive host forensics, network forensics, log analysis ... Programming Skills: Proficiencyin bash and at least one interpreted programming language (Python ...
The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and ...
The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across enterprise networks and mission-critical ...
Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across enterprise networks and mission-critical ...
Senior Security Operations & Incident Response Engineer
Chicago, IL ยท On-site
$112K - $150K/yr
Senior Security Operations & Incident Response Engineer Salary: $112,500-$150,000 The Engineer - Security Operations and Incident Response will be a critical function responsible for the ...
Senior Security Operations & Incident Response Engineer
Chicago, IL ยท On-site
$112K - $150K/yr
Senior Security Operations & Incident Response Engineer Salary: $112,500-$150,000 The Engineer - Security Operations and Incident Response will be a critical function responsible for the ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Threat and Incident Response Engineer
Seattle, WA ยท On-site
$120K - $139K/yr
Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The work spans ...
Threat and Incident Response Engineer
Seattle, WA ยท On-site
$120K - $139K/yr
Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The work spans ...
Incident Response
Los Angeles, CA ยท On-site
Incident Response Downey, CA 12+ months Skills Required Managed at least two data centers ... Computer Science, Engineering, Information Systems, etc.) or equivalent experience/combined ...
Incident Response
Los Angeles, CA ยท On-site
Incident Response Downey, CA 12+ months Skills Required Managed at least two data centers ... Computer Science, Engineering, Information Systems, etc.) or equivalent experience/combined ...
Sr Engineer - Incident Response Engineering
Minneapolis, MN ยท On-site
$98K - $176K/yr
JOIN TARGET CYBERSECURITY AS A SENIOR ENGINEER - INCIDENT RESPONSE ENGINEERING As a Senior Engineer, you serve as a specialist in the engineering team that supports the product. You help develop and ...
Sr Engineer - Incident Response Engineering
Minneapolis, MN ยท On-site
$98K - $176K/yr
JOIN TARGET CYBERSECURITY AS A SENIOR ENGINEER - INCIDENT RESPONSE ENGINEERING As a Senior Engineer, you serve as a specialist in the engineering team that supports the product. You help develop and ...
Partner 20, Staff Engineer, Incident Response
San Francisco, CA ยท On-site
$243 - $284/hr
The Role We're hiring a Senior Incident Response Engineer to anchor a16z's detection and response work. You'll own incident triage and response across AWS and GCP, write the detections that catch ...
New
Partner 20, Staff Engineer, Incident Response
San Francisco, CA ยท On-site
$243 - $284/hr
The Role We're hiring a Senior Incident Response Engineer to anchor a16z's detection and response work. You'll own incident triage and response across AWS and GCP, write the detections that catch ...
New
Sr Engineer - Incident Response Engineering
Brooklyn Park, MN ยท On-site
$98K - $176K/yr
JOIN TARGET CYBERSECURITY AS A SENIOR ENGINEER - INCIDENT RESPONSE ENGINEERING As a Senior Engineer, you serve as a specialist in the engineering team that supports the product. You help develop and ...
Sr Engineer - Incident Response Engineering
Brooklyn Park, MN ยท On-site
$98K - $176K/yr
JOIN TARGET CYBERSECURITY AS A SENIOR ENGINEER - INCIDENT RESPONSE ENGINEERING As a Senior Engineer, you serve as a specialist in the engineering team that supports the product. You help develop and ...
Incident Response Engineer information
See salary details
$17.79 - $22.25
8% of jobs
$22.25 - $26.70
1% of jobs
$29.56 is the 25th percentile. Wages below this are outliers.
$26.70 - $31.16
24% of jobs
$31.16 - $35.62
8% of jobs
$35.62 - $40.08
4% of jobs
The median wage is $41.19 / hr.
$40.08 - $44.54
15% of jobs
$47.22 is the 75th percentile. Wages above this are outliers.
$44.54 - $48.99
23% of jobs
$48.99 - $53.45
2% of jobs
$53.45 - $57.91
2% of jobs
$57.91 - $62.37
1% of jobs
$62.37 - $66.83
11% of jobs
$17
$41
$66
How much do incident response engineer jobs pay per hour?
What is an incident response engineer?
How does an incident response engineer typically collaborate with other teams during a security incident?
What are the key skills and qualifications needed to thrive as an incident response engineer, and why are they important?
What is the difference between Incident Response Engineer vs Security Analyst?
| Aspect | Incident Response Engineer | Security Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CEH | CISSP, Security+ |
| Work Environment | Responds to security incidents, investigates breaches | Monitors security systems, analyzes threats |
| Employer & Industry | Tech companies, cybersecurity firms, large enterprises | Financial institutions, government agencies, corporations |
Incident Response Engineers focus on investigating and mitigating security incidents, often working in a reactive capacity. Security Analysts monitor security systems proactively, analyzing threats and vulnerabilities. While both roles require similar certifications and work in cybersecurity environments, Incident Response Engineers are more involved in incident handling and response, whereas Security Analysts focus on threat detection and prevention.
How to get a job in incident response?
What are the career paths for incident response engineer?
What states have the most Incident Response Engineer jobs?
States with the most job openings for Incident Response Engineer jobs include:
What job categories do people searching Incident Response Engineer jobs look for?
The top searched job categories for Incident Response Engineer jobs are:

Job description
Description
Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The work spans the corporate IT network and the operational technology that runs transit systems. Time is split about evenly between responding to security incidents and proactive threat hunting, with detection tuning running underneath both.
On the incident side, this role owns alerts from the moment they arrive. That means triage out of SIEM, EDR, NDR, and the OT monitoring platform, then analysis, escalation, and guidance on containment, eradication, and recovery. This team member will write the root cause analyses and incident reports that go to Sound Transit leadership, keep incident metrics current, and build out response playbooks. In the OT environment the work also involves reading industrial network traffic and coordinating directly with plant and engineering staff, since a response step that is routine on a corporate network can take something offline that needs to stay running.
On the hunting side, this team member will form hypotheses and test them against endpoint, network, log, and OT protocol telemetry. What the hunts turn up becomes new detection content. Coverage is mapped against MITRE ATT&CK to guide where hunts focus next, and threat intelligence feeds back into the following round.
Alert quality runs through both halves of the job. Detection tuning is a standing part of the role, so expect meaningful time on rule tuning, suppression logic, correlation and enrichment, and SOAR automation.
This position will function within a highly motivated, dynamic team. We are looking for someone who works calmly during an active incident and who takes the initiative on hunting rather than waiting for work to be assigned.
Requirements
Required Background
Bachelor's degree from an accredited U.S. college or university in Computer Science, Information Security, Information Systems, or a related subject.
Minimum of ten (10) years of experience in cybersecurity operations for the senior position, or five (5) or more years for the mid-level position, covering both security incident response and proactive threat hunting.
Demonstrated experience responding to security incidents in an Operational Technology (OT), ICS, or SCADA environment, not enterprise IT alone.
Ability to pass a Sound Transit background check.
Ability to work Pacific Time business hours and to be onsite in the Seattle area on occasion.
Required Abilities, Knowledge & Skills
Proven experience managing security incidents end to end, from triage through containment, eradication, recovery, and post-incident review.
Working proficiency with a major SIEM such as Microsoft Sentinel, Splunk, or QRadar, including writing and tuning detection content.
Working proficiency with EDR such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne, and with network detection and response tooling.
Experience with OT monitoring platforms such as Dragos, Claroty, or Nozomi Networks.
Practical fluency with MITRE ATT&CK, including ATT&CK for ICS, and the ability to map detection and hunt coverage against it.
Ability to design and run hypothesis-driven threat hunts across endpoint, network, log, and OT protocol telemetry.
Detection engineering skills, including writing and refining correlation rules, queries, and use cases in SIEM and EDR platforms.
A track record of reducing false positives, alert noise, and duplicate ticketing, with metrics to support it.
Familiarity with industrial protocols and industrial network traffic analysis, such as Modbus, DNP3, OPC, or BACnet.
Experience folding threat intelligence into hunting and detection workflows.
Ability to produce incident documentation, root cause analysis reports, SOPs, playbooks, and metrics such as MTTD, MTTR, and SLA adherence.
Judgment to recognize when a standard IT containment action is unsafe in an operational environment, and to work out a safe alternative with engineering staff.
Strong written and verbal communication skills, with the ability to brief technical responders and executive stakeholders.
Ability to work independently within a client environment and coordinate across information security, infrastructure, operations, and engineering teams.
Preferred
Experience supporting a transit, rail, utility, or other critical infrastructure organization
Public sector or government client experience
Certifications such as GCIH, GCIA, GCFA, GNFA, GICSP, GRID, or CISSP
SOAR automation and playbook development using Sentinel Automation Rules, Splunk SOAR, Cortex XSOAR, or a comparable platform
Experience standing up or maturing a formal threat hunting program
Familiarity with the NIST Cybersecurity Framework, NIST SP 800-82, IEC 62443, and TSA Security Directives
Scripting for detection and automation, such as KQL, SPL, Python, or PowerShell
Digital forensics or malware analysis capability
Experience mentoring SOC analysts or leading post-incident reviews
Company Profile
Volanno is a certified woman-owned small business based in Washington, DC. As an IT solution provider, our services include custom software development, program management, and advanced data analytics. From scoping and defining to implementation and support, we are ready to support our clients' needs at any stage of development in designing and building solutions that prepare them for the future.
Volanno is an equal opportunity employer. Volanno will consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status.
About Volanno
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Washington, DC, US
Year founded
2003