1

Incident Response Soc Analyst Jobs (NOW HIRING)

Incident Response Analyst

California, MO · On-site

$125 - $150/hr

Coordinate incident-response activities with SOC analysts, CSSPs, system owners, technical teams, and Government stakeholders * Support escalation of significant cybersecurity events and incidents in ...

New

SOC Analyst

Washington, DC · On-site

$100K - $120K/yr

SOC Analyst Expression is seeking a SOC Analyst to join our team in support of the National ... In this role, you will provide cyber threat monitoring, analysis, and incident response support ...

... incident response operations. Additionally, the Mid SOC Analyst candidates must be willing to work ... in a 24x7x365 SOC environment, demonstrate intuitive problem-solving skills, and allow for flexible ...

The SOC Analyst will play a critical role in monitoring, analyzing, and responding to security ... This position involves collaboration with Incident Response teams, conducting research, managing ...

SOC Analyst I

Monterey, CA · On-site

$38.72 - $40/hr

May assist with the design of incident response for cloud service models. Qualifications * As a ... The SOC Analyst I will provide support Monday - Thursday, 6:45am - 5:15pm PST. Pay Transparency ...

May assist with the design of incident response for cloud service models. * As a requirement of ... The SOC Analyst I will provide support Monday - Thursday, 6:45am - 5:15pm PST. AMERICAN SYSTEMS is ...

The ideal candidate will have a strong foundation in security operations and incident response ... As a SOC Analyst at Mantis Security, you'll help protect critical customer environments by ...

SOC Analyst

Reston, VA · On-site

$125 - $150/hr

The ideal candidate will have a strong foundation in security operations and incident response ... As a SOC Analyst at Mantis Security, you'll help protect critical customer environments by ...

Incident Response Analyst

Alexandria, VA · On-site

$94K - $127K/yr

Description Incident Response Analyst Xcelerate Solutions is seeking an Incident Response Analyst ... Coordinate with SOC analysts, Cybersecurity Service Providers, system owners, technical teams, and ...

next page

Showing results 1-20

Incident Response Soc Analyst information

See salary details

$22

$46

$62

How much do incident response soc analyst jobs pay per hour?

As of Sep 8, 2026, the average hourly pay for incident response soc analyst in the United States is $46.45, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $52.64 per hour, depending on experience, location, and employer.

What is an incident response SOC analyst?

An Incident Response SOC Analyst is a cybersecurity professional responsible for monitoring, detecting, analyzing, and responding to security incidents within an organization. Working in a Security Operations Center (SOC), they investigate alerts, contain threats, and coordinate with other teams to mitigate potential damage. They also help develop and refine security procedures, ensure compliance with policies, and create detailed reports on incidents. Their work is crucial in protecting an organization's digital assets and reducing the impact of cyberattacks.

What are some common challenges incident response SOC analysts face when handling real-time security incidents?

Incident Response SOC Analysts often face the challenge of quickly distinguishing between genuine threats and false positives, as alerts can be numerous and sometimes ambiguous. They must remain calm and methodical under pressure, especially during active incidents where rapid decisions are critical to minimize potential damage. Effective collaboration with IT, network teams, and sometimes external partners is vital for gathering information and executing containment or remediation steps. Additionally, staying updated with evolving cyber threats and maintaining detailed incident documentation are ongoing demands that can shape daily responsibilities.

What are the key skills and qualifications needed to thrive as an incident response SOC analyst, and why are they important?

To thrive as an Incident Response SOC Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response methodologies, often supported by a degree in computer science or cybersecurity and relevant certifications like CompTIA Security+ or GIAC. Familiarity with Security Information and Event Management (SIEM) tools, intrusion detection systems (IDS), and forensic analysis software is typically required. Attention to detail, analytical thinking, and effective communication are essential soft skills for identifying, investigating, and resolving security incidents. These skills and qualifications are crucial to quickly detect threats, minimize damage, and enhance an organization’s overall security posture.

What is the difference between Incident Response Soc Analyst vs Security Operations Center (SOC) Analyst?

AspectIncident Response Soc AnalystSecurity Operations Center (SOC) Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, GIAC certifications, CISSP (preferred)
Work EnvironmentResponds to security incidents, investigates breaches, often in a reactive roleMonitors security alerts, analyzes threats, maintains security tools
Employer & Industry UsageUsed in cybersecurity teams across various industries, focusing on incident handlingCommon in security operations centers across industries, focusing on threat detection

Both roles require similar certifications and work in cybersecurity environments, but Incident Response Soc Analysts focus on investigating and responding to security incidents, while SOC Analysts primarily monitor and analyze security alerts to prevent incidents.

Do incident response SOC analysts get paid well?

Incident response SOC analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level analysts may start with lower pay, but with certifications like CISSP or GIAC and experience, salaries can increase significantly, often reflecting the specialized skills required for cybersecurity incident handling.

Is incident response SOC analyst still in demand?

Incident Response SOC analysts are in high demand due to increasing cybersecurity threats and the need for organizations to detect and respond to security incidents quickly. The role often requires knowledge of security tools, threat intelligence, and certifications like CISSP or GIAC, and job growth is expected to remain strong in the coming years.
More about Incident Response Soc Analyst jobs

What cities are hiring for Incident Response Soc Analyst jobs?

Cities with the most Incident Response Soc Analyst job openings:

What job categories do people searching Incident Response Soc Analyst jobs look for?

The top searched job categories for Incident Response Soc Analyst jobs are:

Infographic showing various Incident Response Soc Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, 2% Contract, and 1% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $96,618 per year, or $46.5 per hour.

Incident Response Analyst

Jobtailor

California, MO • On-site

$125 - $150/hr

Other

Posted 2 days ago

New


Job description

  • Support preparation, detection, analysis, containment, eradication, recovery, and post-incident activities for cybersecurity events and incidents
  • Investigate cybersecurity incidents affecting NIPRNet and SIPRNet environments
  • Perform proactive security monitoring and analysis to identify potential intrusion attempts and malicious activity
  • Analyze security information from SIEM platforms, endpoint-security capabilities, firewalls, IDS, IPS, web-security systems, antispam capabilities, malware-prevention systems, and related enforcement technologies
  • Assess cybersecurity events to determine scope, potential impact, affected systems, and required response actions
  • Support containment and mitigation of active cybersecurity threats in accordance with approved Government procedures
  • Coordinate eradication and recovery activities with system owners, administrators, network personnel, cybersecurity teams, and technical stakeholders
  • Collect and preserve technical evidence associated with cybersecurity events and incidents
  • Maintain accurate incident records, timelines, supporting evidence, investigative findings, response actions, and status information
  • Develop and contribute to required cybersecurity event and incident reporting
  • Coordinate incident-response activities with SOC analysts, CSSPs, system owners, technical teams, and Government stakeholders
  • Support escalation of significant cybersecurity events and incidents in accordance with established procedures
  • Provide timely status updates during active investigations and incident-response activities
  • Support post-incident analysis and lessons learned to improve monitoring, detection, response procedures, and defensive capabilities
  • Participate in after-hours incident response when assigned and meet the contract-required one-hour recall requirement
Requirements
  • Bachelor’s degree and 5 or more years of relevant cybersecurity experience; specific experience, education and training may be considered in lieu of degree
  • Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation
  • Experience analyzing cybersecurity events and determining appropriate response or escalation actions
  • Experience supporting incident containment, eradication, recovery, and post-incident activities
  • Experience monitoring and analyzing enterprise cybersecurity tools and security telemetry
  • Experience documenting incident timelines, investigative findings, evidence, response actions, and status
  • Experience coordinating cybersecurity incidents across technical teams and stakeholder organizations
  • Working knowledge of network, endpoint, and enterprise cybersecurity monitoring concepts
  • Ability to recognize potential intrusion activity and support rapid mitigation of cybersecurity threats
  • Ability to communicate clearly during active cybersecurity incidents and maintain accurate documentation under time-sensitive conditions
  • Ability to support after-hours incident response and the required one-hour recall when assigned
  • U.S. Citizenship required
  • Active Secret security clearance required at time of consideration
  • Preferred: experience supporting cybersecurity incident response within Department of Defense or Federal environments
  • Preferred: experience responding to incidents in both unclassified and classified network environments
  • Preferred: experience with SIEM platforms and enterprise security-monitoring capabilities
  • Preferred: experience analyzing endpoint-security, firewall, IDS, IPS, web-security, antispam, or malware-prevention data
  • Preferred: experience supporting evidence collection and preservation during cybersecurity investigations
  • Preferred: experience coordinating incident response with SOC personnel, CSSPs, system owners, network teams, and other technical organizations
  • Preferred: experience operating in a 24x7 cybersecurity operations environment or supporting after-hours incident response
  • Preferred: familiarity with Department of Defense cybersecurity incident-response processes and requirements
  • Preferred: familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments
Core Competencies

Demonstrates expertise in cybersecurity incident response, including containment, eradication, and recovery activities. Proficient in analyzing security information from various cybersecurity tools and coordinating incident response across technical teams and stakeholders.

Highest-signal resume keywords
  • Cybersecurity Incident Response
  • Security Operations Center Operations
  • SIEM Platform Analysis
  • Incident Documentation and Reporting
  • Network and Endpoint Security Monitoring
Hard Skills
  • Cybersecurity Analysis
  • Incident Containment
  • Malware Prevention
  • Intrusion Detection Systems
  • Firewall Management
  • Endpoint Security
  • Security Telemetry Monitoring
  • Evidence Collection
  • Post-Incident Analysis
  • Cyber Defense
Soft Skills
  • Clear Communication
  • Time Management
  • Collaboration
Certifications & Qualifications
  • Active Secret Security Clearance
Industry Keywords
  • NIPRNet
  • SIPRNet
  • Department of Defense
  • Federal Environments
  • Cybersecurity Operations
  • Incident Response Procedures
Tools & Technologies
  • SIEM Platforms
  • Endpoint-Security Tools
  • Firewalls
  • Intrusion Detection Systems
  • Intrusion Prevention Systems
  • Web-Security Systems
  • Antispam Technologies
  • Malware-Prevention Systems
#J-18808-Ljbffr