1

Incident Response Jobs (NOW HIRING)

Incident Response Lead

Boston, MA · On-site

$130K - $170K/yr

We are seeking a Incident Response Lead to drive security incident response across the enterprise. In this role, you will serve as the primary internal escalation point and hands-on responder for ...

Incident Response Lead

Boston, MA · On-site

$130K - $170K/yr

We are seeking a Incident Response Lead to drive security incident response across the enterprise. In this role, you will serve as the primary internal escalation point and hands-on responder for ...

Incident Response Lead

Boston, MA · On-site

$130K - $170K/yr

We are seeking a Incident Response Lead to drive security incident response across the enterprise. In this role, you will serve as the primary internal escalation point and hands-on responder for ...

Incident Response Manager MUST HAVE: * 5+ years' hands-on experience in Incident Response management * Experience with legal operations * Experience working with a SOC/NOC * Hands-on experience with ...

Perform cybersecurity incident detection, response, remediation, or mitigation * Analyze security incidents, preserve digital evidence, identify root causes, and create mitigation or remediation ...

next page

Showing results 1-20

People also search for

Incident Response information

See salary details

$41K

$127.2K

$199.5K

How much do incident response jobs pay per year?

As of Jun 11, 2026, the average yearly pay for incident response in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

Is 40 too old for cyber security?

Incident response professionals can succeed at any age, as the field values skills, experience, and continuous learning. Many individuals transition into cybersecurity later in their careers, often bringing valuable expertise and certifications like CISSP or CEH. Age is generally not a barrier if you have relevant skills and stay current with industry developments.

What are some common challenges faced by professionals in Incident Response roles and how can they be managed?

Incident Response professionals often face challenges such as rapidly evolving cyber threats, handling high-pressure situations, and coordinating effectively with cross-functional teams during security incidents. Managing these challenges requires staying updated with the latest threat intelligence, practicing incident simulations, and maintaining clear communication protocols. Building strong relationships with IT, legal, and management teams can also help ensure a swift and coordinated response to incidents, making the role both demanding and highly collaborative.

What is an incident response job?

An incident response job involves identifying, managing, and mitigating cybersecurity incidents such as data breaches or malware attacks. Professionals in this role analyze security alerts, coordinate responses, and often use tools like intrusion detection systems, with certifications like CISSP or SANS being beneficial. The work typically requires strong problem-solving skills and the ability to work under pressure in a fast-paced environment.

Can I make $200,000 a year in cyber security?

Incident response professionals in cybersecurity can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISA, and roles in high-demand industries or senior positions. Salary levels vary based on location, company size, and individual expertise, with senior incident responders and security managers often reaching or exceeding this threshold.

How much do incident responders make?

Incident responders typically earn a median annual salary between $70,000 and $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand industries or regions with a strong cybersecurity focus.

What is incident response?

Incident response refers to the organized approach that organizations use to address and manage the aftermath of a security breach or cyberattack. The goal is to handle the situation in a way that limits damage, reduces recovery time and costs, and mitigates the risks associated with the incident. Incident response typically involves preparation, detection, containment, eradication, recovery, and lessons learned. A well-developed incident response plan helps organizations quickly identify threats, minimize impact, and restore normal operations.

What is the difference between Incident Response vs Security Analyst?

AspectIncident ResponseSecurity Analyst
CertificationsGCIH, CISSP, CEHCISSP, Security+
Work EnvironmentResponding to security incidents, investigating breachesMonitoring networks, analyzing security data
Employer & Industry UsageCybersecurity firms, large organizationsIT departments, security teams

Incident Response specialists focus on managing and mitigating security incidents and breaches, often working in response teams. Security Analysts monitor systems proactively, analyze security data, and identify vulnerabilities. While both roles require similar certifications and work within cybersecurity, Incident Response is more reactive, whereas Security Analysts are more proactive in security monitoring.

What are the key skills and qualifications needed to thrive as an Incident Response professional, and why are they important?

To thrive as an Incident Response professional, you need strong analytical skills, a deep understanding of cybersecurity principles, and usually a degree in computer science or a related field. Familiarity with tools like SIEM platforms (e.g., Splunk), forensic analysis software, and certifications such as CISSP or GIAC is highly beneficial. Attention to detail, calmness under pressure, and effective communication are crucial soft skills for responding to security incidents and working with cross-functional teams. These skills and qualities enable quick detection, containment, and resolution of security threats, minimizing organizational risk and damage.
What cities are hiring for Incident Response jobs? Cities with the most Incident Response job openings:
What are the most commonly searched types of Incident Response jobs? The most popular types of Incident Response jobs are:
What states have the most Incident Response jobs? States with the most job openings for Incident Response jobs include:

Incident Response Coordinator

Carnegie Mellon University

Pittsburgh, PA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 2 days ago


Carnegie Mellon University rating

8.6

Company rating: 8.6 out of 10

Based on 24 frontline employees who took The Breakroom Quiz

51st of 535 rated colleges and universities


Job description

The Computing Services central IT department provides services that have a strategic impact on university goals. We make service decisions based on interaction and valuable input from colleagues engaged in the education, research, and administration efforts of the university. We are a learning organization and approach successes and mistakes as a learning experience to continually cultivate a culture of intelligent risk taking. We want to hire versatile team members who are inspired and passionate about their work. Join us and be part of a team committed to excellence, innovation, diversity, team and individual growth.

CMU's Computing Services' Information Security Office is searching for a Principal Information Security Engineer/Incident Response Coordinator.

This is an excellent opportunity for someone who thrives in an interesting and challenging work environment. The Principal Information Security Engineer/Incident Response Coordinator (PISE/IRC) is responsible for managing and coordinating the organization's prevention and response to cybersecurity incidents. This role ensures that incidents are prevented, detected, contained, investigated, and remediated efficiently and consistently, minimizing business impact and strengthening cyber resilience.

The PISE/IRC leads in the planning, coordination, and review of incident management and control functions and advises on preventive and detective measures in pursuit of adequate information, computer, and network security on campus. This includes responding to incidents, policy violations, and DMCA notices; analyzing and securing compromised computer systems; working with other groups in the division to assist in securing services as needed; providing documentation and announcements as regards incident handling, reporting on trends and apparent control gaps, and responding to requests from law enforcement, the Office of General Counsel, and other campus constituents related to information security concerns.

The ideal candidate combines strong technical understanding with exceptional oral and written communication, organization, and decision-making skills.

Your core responsibilities will include:

  • Lead and coordinate the end-to-end incident response process from prevention, detection, and response through to post-incident review.

  • Serve as the primary point of contact during active security incidents, ensuring timely escalation and clear communication across teams.

  • Collaborate with SOC analysts, threat hunters, and system owners to analyze, contain, and remediate threats.

  • Maintain and continuously improve incident response plans, playbooks, and communication protocols.

  • Facilitate incident response exercises, simulations, and tabletop scenarios to build readiness.

  • Coordinate with external stakeholders, including law enforcement, regulatory bodies, and third-party service providers, when required.

  • Track incident metrics and produce executive-level reporting and after-action reviews.

  • Contribute to threat intelligence sharing and ensure lessons learned are incorporated into security controls and training.

  • Support policy and compliance efforts related to incident handling, data protection, and reporting obligations.

  • Provide front-line support including SOC coverage and 24x7 on-call rotation, forensic analysis, tool evaluation, eDiscovery support, and training.

  • Supervise incident response team staff.

  • A combination of education and relevant experience from which comparable knowledge is demonstrated may be considered.

  • Other related duties as assigned.

Flexibility, excellence, and passion are vital qualities within Computing Services. Inclusion, collaboration, and cultural sensitivity are valued competencies at CMU. Therefore, we are in search of a team member who is able to effectively interact with a varied population of internal and external partners at a high level of integrity. We are looking for someone who shares our values and who will support the mission of the university through their work.

Qualifications:

  • Bachelor's Degree

  • 8-10 years of years experience with information security and incident handling in a complex, distributed computing environment. Knowledge of contemporary computing technologies,

Requirements:

  • Successful background check

  • This position involves access to items or technical data controlled under the U.S. International Traffic in Arms Regulations ("ITAR"). Under U.S. export control laws, restrictions apply to the release or disclosure within the United States of ITAR-controlled technical data to individuals who are NOT "U.S. Persons." U.S. Persons include U.S. citizens, U.S. nationals, persons lawfully admitted for U.S. permanent residence ("green card" holders), persons granted U.S. asylum status and persons granted U.S. refugee status.

  • Carnegie Mellon's Computing Services can rely on ITAR authorizations to provide access to ITAR-controlled items for certain eligible applicants who are not U.S. Persons. However, for Computing Services to ensure compliance with the ITAR, applicants who are NOT U.S. Persons are not eligible for this position if they are current or former permanent residents, nationals, or citizens of the following arms-embargoed or ITAR-restricted countries: Afghanistan, Belarus, Burma, Cambodia, Central African Republic, China, Cuba, Cyprus, Democratic Republic of Congo, Ethiopia, Eritrea, Haiti, Iran, Iraq, Lebanon, Libya, Nicaragua, North Korea, Russia, Somalia, South Sudan, Sudan, Syria, Venezuela, and Zimbabwe.

"Applicants for this position must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity."

Are you interested in this exciting opportunity?! Apply today!

Joining the CMU team opens the door to an array of exceptional benefits.

Benefits eligible employees enjoy a wide array of benefits including comprehensive medical, prescription, dental, and vision insurance as well as a generous retirement savings program with employer contributions. Unlock your potential with tuition benefits, take well-deserved breaks with ample paid time off and observed holidays, and rest easy with life and accidental death and disability insurance.

Additional perks include a free Pittsburgh Regional Transit bus pass, access to our Family Concierge Team to help navigate childcare needs, fitness center access, and much more!

For a comprehensive overview of the benefits available, explore our Benefits page.

At Carnegie Mellon, we value the whole package when extending offers of employment. Beyond credentials, we evaluate the role and responsibilities, your valuable work experience, and the knowledge gained through education and training. We appreciate your unique skills and the perspective you bring. Your journey with us is about more than just a job; it's about finding the perfect fit for your professional growth and personal aspirations.

Are you interested in an exciting opportunity with an exceptional organization?! Apply today!

Location

Pittsburgh, PA

Job Function

Security

Position Type

Staff - Regular

Full Time/Part time

Full time

Pay Basis

Salary

More Information:

  • Please visit "Why Carnegie Mellon" to learn more about becoming part of an institution inspiring innovations that change the world.

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.

  • Statement of Assurance


What Carnegie Mellon University employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom