1

Incident Response Jobs in Raleigh, NC (NOW HIRING)

Lateral Firefighter

Apex, NC · On-site

$64K - $79K/yr

Firefighters participate in the operations of fire suppression, rescue, incident response, and daily maintenance activities at the fire station. These activities involve firefighting, performing ...

Partner with Security Operations Centers (SOC), Incident Response, Threat Intelligence, Cyber Threat Management, and engineering teams to define and deliver new cybersecurity capabilities. * Drive ...

Track, measure, and evaluate incident analysis and response activities. * Create, monitor, and report on KPIs, KRIs, and performance metrics for the ARC. * Recommend workflow changes or improvements ...

Track, measure, and evaluate incident analysis and response activities. * Create, monitor, and report on KPIs, KRIs, and performance metrics for the ARC. * Recommend workflow changes or improvements ...

Showing results 41-60

Incident Response information

See Raleigh, NC salary details

$39.9K

$123.6K

$193.9K

How much do incident response jobs pay per year?

As of Aug 21, 2026, the average yearly pay for incident response in Raleigh, NC is $123,619.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,500.00 and $167,200.00 per year, depending on experience, location, and employer.

What is incident response?

Incident response refers to the organized approach that organizations use to address and manage the aftermath of a security breach or cyberattack. The goal is to handle the situation in a way that limits damage, reduces recovery time and costs, and mitigates the risks associated with the incident. Incident response typically involves preparation, detection, containment, eradication, recovery, and lessons learned. A well-developed incident response plan helps organizations quickly identify threats, minimize impact, and restore normal operations.

What are the key skills and qualifications needed to thrive as an incident response professional?

To thrive as an Incident Response professional, you need strong analytical skills, a deep understanding of cybersecurity principles, and usually a degree in computer science or a related field. Familiarity with tools like SIEM platforms (e.g., Splunk), forensic analysis software, and certifications such as CISSP or GIAC is highly beneficial. Attention to detail, calmness under pressure, and effective communication are crucial soft skills for responding to security incidents and working with cross-functional teams. These skills and qualities enable quick detection, containment, and resolution of security threats, minimizing organizational risk and damage.

What are some common challenges faced by professionals in incident response roles and how can they be managed?

Incident Response professionals often face challenges such as rapidly evolving cyber threats, handling high-pressure situations, and coordinating effectively with cross-functional teams during security incidents. Managing these challenges requires staying updated with the latest threat intelligence, practicing incident simulations, and maintaining clear communication protocols. Building strong relationships with IT, legal, and management teams can also help ensure a swift and coordinated response to incidents, making the role both demanding and highly collaborative.

What is the difference between Incident Response vs Security Analyst?

AspectIncident ResponseSecurity Analyst
CertificationsGCIH, CISSP, CEHCISSP, Security+
Work EnvironmentResponding to security incidents, investigating breachesMonitoring networks, analyzing security data
Employer & Industry UsageCybersecurity firms, large organizationsIT departments, security teams

Incident Response specialists focus on managing and mitigating security incidents and breaches, often working in response teams. Security Analysts monitor systems proactively, analyze security data, and identify vulnerabilities. While both roles require similar certifications and work within cybersecurity, Incident Response is more reactive, whereas Security Analysts are more proactive in security monitoring.

How much do incident responders make?

Incident responders typically earn a median annual salary between $70,000 and $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand industries.

How to get a job in incident response?

To get a job in incident response, candidates should develop skills in cybersecurity, network analysis, and digital forensics, often through relevant certifications like GIAC Certified Incident Handler (GCIH) or Certified Ethical Hacker (CEH). Gaining experience through internships, entry-level security roles, or hands-on labs helps build practical knowledge. Strong problem-solving abilities and familiarity with security tools such as SIEM systems are also important for success in this field.

What are the career paths for incident response?

Incident response professionals can advance to roles such as senior analyst, incident response manager, cybersecurity director, or chief information security officer. Career progression often involves gaining experience, obtaining certifications like CISSP or GIAC, and developing skills in threat analysis, forensics, and security management.

What is an incident response job?

An incident response job involves identifying, managing, and mitigating cybersecurity incidents such as data breaches or malware attacks. Professionals in this role analyze security alerts, coordinate responses, and often use tools like intrusion detection systems, with certifications like CISSP or SANS being beneficial. The work typically requires strong problem-solving skills and the ability to work under pressure.

What are the most commonly searched types of Incident Response jobs in Raleigh, NC?

The most popular types of Incident Response jobs in Raleigh, NC are:

What are popular job titles related to Incident Response jobs in Raleigh, NC?

For Incident Response jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Incident Response jobs in Raleigh, NC look for?

The top searched job categories for Incident Response jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Incident Response jobs?

Cities near Raleigh, NC with the most Incident Response job openings:

Infographic showing various Incident Response job openings in Raleigh, NC as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% In-person job distribution, with an average salary of $123,619 per year, or $59.4 per hour.

Director Infrastructure & Operations

First Citizens Bank

Raleigh, NC • On-site

Full-time

Posted 3 days ago

New


First Citizens Bank rating

7.4

Company rating: 7.4 out of 10

Based on 106 frontline employees who took The Breakroom Quiz

106th of 171 rated banks


Job description

Overview

The Director, Technology Operations is responsible for leading critical production operations functions that ensure the availability, stability, resiliency, and operational excellence of the bank's technology ecosystem. This role oversees three core operational domains: 24x7 Enterprise Batch Operations, L1 Infrastructure & Application Monitoring and Incident Response, and L2 Infrastructure Support Services.

This leader will play a key role in advancing operational maturity, resiliency, observability, incident management, automation, and service reliability. The position will help drive the consolidation and modernization of multiple command center and technology operations functions into a unified Technology Operations organization capable of providing consistent 24x7 support across infrastructure, applications, and enterprise batch processing.

This role requires a leader with deep technical and operational experience, strong organizational leadership capabilities, and a demonstrated track record of driving operational transformation in complex, highly regulated environments.

This is a highly visible, executive-facing leadership position with regular interaction across senior technology leadership, business executives, risk management, audit, and regulatory stakeholders. The successful candidate must possess exceptional written and verbal communication skills, executive presence, and strategic thinking capabilities. The individual must be capable of translating complex operational and technical issues into concise business impacts, risks, and actions while maintaining confidence and alignment among senior stakeholders during both routine operations and high-severity incidents.


Responsibilities

Enterprise Batch Operations

Lead the bank's Batch Processing Support organization responsible for the continuous monitoring and support of enterprise batch processing across distributed, mainframe, and IBM i (AS/400) environments.

This role is accountable for the operational execution, monitoring, incident response, and support functions that ensure successful enterprise batch processing.

Responsibilities

  • Lead teams responsible for 24x7 monitoring and operational support of critical batch processing workloads.
  • Ensure successful execution of daily, weekly, monthly, quarterly, and year-end processing cycles.
  • Drive timely detection, triage, escalation, communication, and resolution of batch processing disruptions.
  • Maintain operational readiness procedures, support playbooks, escalation models, and recovery processes supporting business-critical processing.
  • Partner closely with Application Owners, Application Support teams, and Control-M Engineering to improve processing observability, reliability and operational effectiveness.
  • Coordinate enterprise response and recovery activities for critical batch failures, delays, dependency issues, and processing exceptions.
  • Establish and maintain operational metrics covering processing reliability, SLA attainment, incident response, and issue resolution performance.

L1 Infrastructure & Application Monitoring Operations

Lead first-line operational support functions responsible for enterprise monitoring, event management, production awareness, and incident response.

Responsibilities

  • Oversee enterprise monitoring and command center functions supporting infrastructure, applications, and critical business services.
  • Ensure timely identification, triage, engagement, escalation, and communication of technology events and service disruptions.
  • Lead operational teams responsible for event management, alert response, incident engagement, and stakeholder communications.
  • Drive improvements in monitoring effectiveness, alert quality, event correlation, operational workflows, and response procedures.
  • Partner with infrastructure, application, and engineering teams to improve observability and end-to-end service visibility.
  • Establish governance and operational metrics focused on reducing MTTD, improving service awareness, and strengthening operational responsiveness.
  • Support implementation of automation and tooling improvements that increase operational efficiency and reduce manual effort.
  • Coordinate seamlessly with India-based operational partners to provide consistent 24x7 support coverage and effective follow-the-sun operations.

L2 Infrastructure Support Services

Lead U.S.-based Level 2 Infrastructure Support teams responsible for restoration, troubleshooting, escalation support, and operational ownership across critical technology domains, including Network Services, Server Infrastructure, Middleware Platforms, Database Services, Storage Platforms, and Backup & Recovery Services.

Responsibilities

    • Provide leadership, oversight, and operational governance for global L2 infrastructure support functions.
    • Ensure timely diagnosis and restoration of services during infrastructure-related incidents.
    • Partner with engineering organizations to improve platform supportability, operational readiness, resiliency, and service stability.
    • Drive standardization of support processes, knowledge management, operational procedures, and escalation practices.
    • Improve support effectiveness through automation, process optimization, tooling enhancements, and operational maturity initiatives.
    • Coordinate seamlessly with India-based operational partners to provide consistent 24x7 support coverage and effective follow-the-sun operations.

Qualifications
  • Bachelor's Degree and 8 years of experience in Complex leadership and management responsibilities in an Infrastructure and Operations Enterprise environment OR High School Diploma or GED and 12 years of experience in Complex leadership and management responsibilities in an Infrastructure and Operations Enterprise environment
  • Proven experience leading large-scale 24x7 operational support organizations.
  • Deep understanding of enterprise batch processing environments utilizing Control-M or equivalent technologies.
  • Experience supporting distributed, mainframe, and IBM i (AS/400) technology environments.
  • Strong knowledge of infrastructure operations, production support, monitoring, observability, incident management, and service restoration processes.
  • Demonstrated success leading operational transformation, organizational maturity, or command center modernization initiatives.
  • Strong understanding of ITIL disciplines, including Incident Management, Problem Management, Change Management, and Event Management.
  • Experience working within highly regulated environments, preferably financial services.
Qualifications:
  • Bachelor's Degree and 8 years of experience in Complex leadership and management responsibilities in an Infrastructure and Operations Enterprise environment OR High School Diploma or GED and 12 years of experience in Complex leadership and management responsibilities in an Infrastructure and Operations Enterprise environment
  • Proven experience leading large-scale 24x7 operational support organizations.
  • Deep understanding of enterprise batch processing environments utilizing Control-M or equivalent technologies.
  • Experience supporting distributed, mainframe, and IBM i (AS/400) technology environments.
  • Strong knowledge of infrastructure operations, production support, monitoring, observability, incident management, and service restoration processes.
  • Demonstrated success leading operational transformation, organizational maturity, or command center modernization initiatives.
  • Strong understanding of ITIL disciplines, including Incident Management, Problem Management, Change Management, and Event Management.
  • Experience working within highly regulated environments, preferably financial services.
Education:UNAVAILABLEEmployment Type: FULL_TIME

What First Citizens Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom