1

Incident Response Jobs (NOW HIRING)

Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC) support, cyber analysis ...

The Incident Response Coordinator is a role for those experienced with leading, managing and coordinating cybersecurity incident response activities. This role serves as a single point of contact for ...

The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...

The Incident Response Analyst is a experienced position that supports TrendAI efforts to provide incident response for TrendAI and its customers. This role blends technical knowledge and experience ...

Conduct and participate in incident response training and exercises * Upkeep and development of IR documentation * Support the overall B&H IR program. * Provide monthly reporting for the IR function.

The Incident Response Manager serves as a senior technical leader responsible for managing complex cybersecurity incident response engagements, mentoring and developing incident responders ...

DESCRIPTION The Senior Incident Response Engineer is a senior technical expert responsible for leading and executing the most complex and high-impact incident response activities within the ...

Incident Response Manager MUST HAVE: * 5+ years' hands-on experience in Incident Response management * Experience with legal operations * Experience working with a SOC/NOC * Hands-on experience with ...

The Role We are seeking a highly skilled and motivated Incident Response Expert to join our elite global team. In this role, you will lead and participate in complex forensic investigations and ...

We are seeking a battle-tested, highly self-driven Manager, Incident Response to lead, inspire, and continuously mature our Incident Response Team. In this role, you will not just help to manage ...

About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...

About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...

Showing results 41-60

Incident Response information

See salary details

$41K

$127.2K

$199.5K

How much do incident response jobs pay per year?

As of Sep 2, 2026, the average yearly pay for incident response in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is incident response?

Incident response refers to the organized approach that organizations use to address and manage the aftermath of a security breach or cyberattack. The goal is to handle the situation in a way that limits damage, reduces recovery time and costs, and mitigates the risks associated with the incident. Incident response typically involves preparation, detection, containment, eradication, recovery, and lessons learned. A well-developed incident response plan helps organizations quickly identify threats, minimize impact, and restore normal operations.

What are the key skills and qualifications needed to thrive as an incident response professional?

To thrive as an Incident Response professional, you need strong analytical skills, a deep understanding of cybersecurity principles, and usually a degree in computer science or a related field. Familiarity with tools like SIEM platforms (e.g., Splunk), forensic analysis software, and certifications such as CISSP or GIAC is highly beneficial. Attention to detail, calmness under pressure, and effective communication are crucial soft skills for responding to security incidents and working with cross-functional teams. These skills and qualities enable quick detection, containment, and resolution of security threats, minimizing organizational risk and damage.

What are some common challenges faced by professionals in incident response roles and how can they be managed?

Incident Response professionals often face challenges such as rapidly evolving cyber threats, handling high-pressure situations, and coordinating effectively with cross-functional teams during security incidents. Managing these challenges requires staying updated with the latest threat intelligence, practicing incident simulations, and maintaining clear communication protocols. Building strong relationships with IT, legal, and management teams can also help ensure a swift and coordinated response to incidents, making the role both demanding and highly collaborative.

What is the difference between Incident Response vs Security Analyst?

AspectIncident ResponseSecurity Analyst
CertificationsGCIH, CISSP, CEHCISSP, Security+
Work EnvironmentResponding to security incidents, investigating breachesMonitoring networks, analyzing security data
Employer & Industry UsageCybersecurity firms, large organizationsIT departments, security teams

Incident Response specialists focus on managing and mitigating security incidents and breaches, often working in response teams. Security Analysts monitor systems proactively, analyze security data, and identify vulnerabilities. While both roles require similar certifications and work within cybersecurity, Incident Response is more reactive, whereas Security Analysts are more proactive in security monitoring.

How much do incident responders make?

Incident responders typically earn a median annual salary between $70,000 and $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand industries.

How to get a job in incident response?

To get a job in incident response, candidates should develop skills in cybersecurity, network analysis, and digital forensics, often through relevant certifications like GIAC Certified Incident Handler (GCIH) or Certified Ethical Hacker (CEH). Gaining experience through internships, entry-level security roles, or hands-on labs helps build practical knowledge. Strong problem-solving abilities and familiarity with security tools such as SIEM systems are also important for success in this field.

What are the career paths for incident response?

Incident response professionals can advance to roles such as senior analyst, incident response manager, cybersecurity director, or chief information security officer. Career progression often involves gaining experience, obtaining certifications like CISSP or GIAC, and developing skills in threat analysis, forensics, and security management.

What is an incident response job?

An incident response job involves identifying, managing, and mitigating cybersecurity incidents such as data breaches or malware attacks. Professionals in this role analyze security alerts, coordinate responses, and often use tools like intrusion detection systems, with certifications like CISSP or SANS being beneficial. The work typically requires strong problem-solving skills and the ability to work under pressure.

What cities are hiring for Incident Response jobs?

Cities with the most Incident Response job openings:

What are the most commonly searched types of Incident Response jobs?

The most popular types of Incident Response jobs are:

What states have the most Incident Response jobs?

States with the most job openings for Incident Response jobs include:

Infographic showing various Incident Response job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, 2% Contract, and 1% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Incident Response Manager

Fortuna Cysec Inc

Atlanta, GA • On-site

Full-time

Re-posted 3 days ago


Job description

Description:

Company Overview


Fortuna Cysec delivers unified cybersecurity operations through TheFense platform—our integrated MDR, SIEM, EDR, and response ecosystem designed for regulated industries, nonprofits, healthcare, education, and mission-driven organizations. Our global SOC/NOC operates 24×7×365, providing real-time visibility, rapid containment, and deep technical expertise across diverse customer environments.

We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.


 Role Summary

The Cybersecurity Incident Response Manager leads and directly participates in high-severity investigations across Fortuna Cysec’s customer base. This role blends technical depth, operational leadership, and customer-facing communication. You will serve as the senior escalation point for complex incidents, drive containment and remediation, and strengthen TheFense platform’s detection and response capabilities.


Requirements:

Lead and Execute Incident Response

· Command all phases of incident response—triage, investigation, containment, eradication, and recovery—while performing hands-on technical analysis. 

· Analyze EDR telemetry, SIEM alerts, network logs, cloud audit logs, and identity events across Microsoft, AWS, and hybrid environments. 

· Execute containment actions including endpoint isolation, identity disablement, MFA resets, OAuth token revocation, and firewall/network segmentation changes.

· Conduct forensic acquisition and analysis using Velociraptor, KAPE, FTK, EnCase, and Volatility.

· Reverse-engineer or sandbox suspicious binaries/scripts to determine behavior and impact.

· Lead hypothesis-driven threat hunts mapped to MITRE ATT&CK using TheFense’s unified telemetry.

Strengthen IR Operations

· Oversee daily IR operations across global SOC/NOC teams, ensuring SLA adherence and seamless follow-the-sun handoffs.

· Review and enhance IR playbooks, runbooks, and automated response actions within TheFense.

· Ensure high-quality incident documentation, evidence handling, and customer-ready reporting.

· Conduct root-cause analysis and deliver technically detailed post-incident reviews.

· Partner with engineering to refine detection logic, reduce false positives, and improve automation.

Engage Directly with Customers

· Serve as the technical authority during active breaches, guiding CISOs, IT directors, and executive stakeholders.

· Deliver clear, concise briefings that include attack path analysis, forensic findings, and prioritized remediation steps.

· Support customer teams with hands-on remediation across identity, cloud, endpoint, and email ecosystems.

· Provide strategic recommendations aligned with NIST, CIS Controls, and Fortuna Cysec best practices.

Advance Threat Intelligence and Detection

· Translate emerging threat intelligence into new detection rules, response playbooks, and threat-hunting queries.

· Validate detection logic through lab testing, simulated attacks, and historical telemetry review.

· Identify detection gaps and collaborate with TI teams to enrich investigations with IOCs and adversary behavior patterns.

Build Team and Platform Maturity

· Mentor analysts across global SOC/NOC teams in IR, forensics, cloud investigations, and threat hunting.

· Develop internal tooling and automation using Python or PowerShell.

· Participate in tabletop exercises, purple-team engagements, and breach simulations.

· Contribute to the evolution of TheFense platform by evaluating new telemetry sources and response capabilities.

Required Qualifications

  • 5–10+      years of hands-on experience in incident response, threat hunting, SOC      operations, or digital forensics.
  • Deep      technical expertise with EDR platforms (Microsoft Defender, SentinelOne,      CrowdStrike, Carbon Black).
  • Strong      SIEM experience with log parsing, correlation, and custom detection      creation (Wazuh, Microsoft Sentinel, Elastic, Splunk).
  • Strong      Windows Servers, Office 365 & Azure EntraID / Intune Experience
  • Hands-on      experience with cloud IR in Azure, AWS, and hybrid environments.
  • Proficiency      with forensic tools (Velociraptor, KAPE, FTK, EnCase) and memory analysis      frameworks (Volatility).
  • Strong      understanding of identity security (Entra ID, Okta), email security (M365,      Proofpoint), and SaaS compromise patterns.
  • Familiarity      with MITRE ATT&CK, NIST 800-61, CIS Controls, ISO 27035.
  • Ability      to communicate complex technical findings to both technical and executive      audiences.
  • Relevant      certifications: GCIA, GCFA, GCIH, GNFA, CISSP, or equivalent experience.

Preferred Qualifications

  • Experience      in an MDR, MSSP, or IR consulting environment.
  • Scripting/automation      skills in Python or PowerShell.
  • Experience      with malware analysis, cloud forensics, or identity compromise      investigations.
  • Experience      supporting regulated industries (HIPAA, FERPA, PCI-DSS, SOX, CJIS) and      mission-driven organizations.


Fortuna Cysec is an equal opportunity employer. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, pregnancy, age, sexual orientation, transgender status, gender identity, disability, alienage or citizenship status, marital status or partnership status, genetic information, veteran status or any other characteristic protected under applicable law.