2

Remote Critical Incident Response Jobs (NOW HIRING)

A $500 Home office setup if you're a remote employee. * Global Gatherings - We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites.

Senior Security Engineer, Incident Response

$117K - $160K/yr

  • Medical

  • Retirement

  • PTO

Our dedication to remote-first work, and strong culture of connection and global inclusion means ... See yourself at Twilio Join the team as Twilio's next Senior Security Engineer, Incident Response ...

Remote Staff Psychologist

Columbia, SC · Remote

$95K - $115K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Conduct remote critical incident debriefings. About You The Remote Staff Psychologist will have: * An independent, unrestricted license to practice psychology in your state (license-eligible will be ...

Showing results 41-60

Remote Critical Incident Response information

See salary details

$41K

$127.2K

$199.5K

How much do remote critical incident response jobs pay per year?

As of Aug 15, 2026, the average yearly pay for remote critical incident response in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What is a remote critical incident response?

A Remote Critical Incident Response specialist is a cybersecurity professional who responds to and manages security incidents, such as data breaches or cyberattacks, from a remote location. Their primary duties include identifying, analyzing, containing, and mitigating threats to an organization's information systems. They work closely with IT teams to investigate incidents, minimize damage, and restore normal operations. Remote responders often use specialized tools and secure communication channels to handle incidents efficiently without being physically present on-site.

What are the key skills and qualifications needed to thrive as a remote critical incident response professional, and why are they important?

To thrive as a Remote Critical Incident Response professional, you need strong analytical skills, in-depth cybersecurity knowledge, and experience in incident detection and response, typically supported by a relevant degree and certifications like CISSP or GIAC. Familiarity with security information and event management (SIEM) tools, forensic analysis software, and remote collaboration platforms is essential. Excellent problem-solving abilities, calmness under pressure, and effective communication are crucial soft skills for managing high-stress situations. These competencies ensure quick, coordinated, and effective responses to security breaches, minimizing organizational risk and damage.

What is the difference between Remote Critical Incident Response vs Remote Cybersecurity Analyst?

AspectRemote Critical Incident ResponseRemote Cybersecurity Analyst
Required CredentialsCertifications like GIAC, CISSP, or SANSCertifications like CompTIA Security+, CISSP, or GIAC
Work EnvironmentRapid response teams, incident handling centers, remote or on-siteSecurity operations centers, remote monitoring, threat analysis
Employer & Industry UsageIT security firms, large corporations, government agenciesIT companies, financial institutions, government agencies
Common Search & ComparisonYesYes

Remote Critical Incident Response and Remote Cybersecurity Analyst roles both require cybersecurity certifications and involve protecting organizations from cyber threats. While incident responders focus on immediate response to security breaches, analysts monitor and analyze security data to prevent incidents. Both roles are vital in cybersecurity teams and often overlap in skills and work environments.

How does a remote critical incident response professional typically collaborate with onsite teams during a security incident?

Remote Critical Incident Response professionals work closely with onsite IT and security teams by leveraging secure communication tools and incident management platforms. They guide local teams through containment, eradication, and recovery steps, often providing real-time analysis and recommendations. Strong documentation, timely updates, and clear communication are essential to ensure coordinated efforts and minimize response time. This collaborative structure allows for effective incident resolution even when the responder is not physically present.
More about Remote Critical Incident Response jobs

What cities are hiring for Remote Critical Incident Response jobs?

Cities with the most Remote Critical Incident Response job openings:

What states have the most Remote Critical Incident Response jobs?

States with the most job openings for Remote Critical Incident Response jobs include:

What job categories do people searching Remote Critical Incident Response jobs look for?

The top searched job categories for Remote Critical Incident Response jobs are:

Infographic showing various Remote Critical Incident Response job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 11% Part Time, and 5% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Senior Cyber Security Analyst (Incident Response)

First Citizens Bank

Carolina, RI • Remote

$140K - $188K/yr

Full-time

Posted 7 days ago


First Citizens Bank rating

7.4

Company rating: 7.4 out of 10

Based on 106 frontline employees who took The Breakroom Quiz

107th of 171 rated banks


Job description

Overview

This is a remote role that may be hired in several markets across the United States.

As a Senior Incident Response Analyst, you'll be a member of the bank's Cyber Incident Response team. We are looking for an experienced senior level analyst with proven skillsets to detect and respond to threats in the environment, interact with business stakeholders and work to restore operations. This is a technical role and will support the Threat Hunting, Intelligence, and Monitoring functions with content creation, threat analysis, detection recommendations, and colleague mentoring. Seeking a candidate with strong communication skills to complement their technical skillset providing the ability to distill down complex issues for broader understanding expedited incident management. 


Responsibilities
  • Incident Analyst/handler –investigate SIEM/SOAR events as necessary; bring experience in malware analysis, network/endpoint security to respond to and contain incidents. 
  • Incident Responder/Incident Lead – Lead Incidents, coordinating the investigation, mitigation, and remediation from a technical perspective. Liaise with technical and business stakeholders. 
  • Incident Management – Ensures Information Security incidents are properly detected, documented, investigated, and resolved. 
  • Content Development - Support the creation of countermeasures and mitigations in response to an incident. 
  • Threat Hunting - Support the operational driven inputs (eg. on the heels of an incident or event) into threat hunting and help build countermeasures/mitigations to address commodity and targeted threats. Also build a capability to track evolving threat actor techniques. 
  • Post Incident Review – Provide recommendations to improve communication, processes, procedures, and mitigation options based on high severity incidents. 

Qualifications

Bachelor's Degree and 8 years of experience in Information security OR High School Diploma or GED and 12 years of experience in Information security

  • Experience with all aspects of Incident response including stakeholder management. 
  • 2+ years of Threat Hunting experience.
  • Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus. 
  • Experience analyzing/dispositioning and escalating security events (systems, application, network, authentication email events) 
  • Experience translating threat actor techniques to building mitigations across a variety of security technologies. This could take the form of Yara, Sigma or Regular Expressions. 
  • Ability to define security requirements and drive project deliverables. 
  • Ability to keep track of multiple incidents and ensure responses are provided in a timely fashion. 
  • Experience responding to cloud-related incidents in Azure, AWS and Google cloud.
  • Cloud administrative experience preferred.
  • Cyber Incident Response experience – 3+ years required in which your primary job was an Incident Response role.
  • This role requires participation in the afterhours on call rotation. Rotations will cycle on a weekly basis.

The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

This job posting is expected to remain active for 45 days from the initial posting date listed above.  If it is necessary to extend this deadline, the posting will remain active as appropriate.  Job postings may come down early due to business need or a high volume of applicants

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Qualifications:

Bachelor's Degree and 8 years of experience in Information security OR High School Diploma or GED and 12 years of experience in Information security

  • Experience with all aspects of Incident response including stakeholder management. 
  • 2+ years of Threat Hunting experience.
  • Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus. 
  • Experience analyzing/dispositioning and escalating security events (systems, application, network, authentication email events) 
  • Experience translating threat actor techniques to building mitigations across a variety of security technologies. This could take the form of Yara, Sigma or Regular Expressions. 
  • Ability to define security requirements and drive project deliverables. 
  • Ability to keep track of multiple incidents and ensure responses are provided in a timely fashion. 
  • Experience responding to cloud-related incidents in Azure, AWS and Google cloud.
  • Cloud administrative experience preferred.
  • Cyber Incident Response experience – 3+ years required in which your primary job was an Incident Response role.
  • This role requires participation in the afterhours on call rotation. Rotations will cycle on a weekly basis.

The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

This job posting is expected to remain active for 45 days from the initial posting date listed above.  If it is necessary to extend this deadline, the posting will remain active as appropriate.  Job postings may come down early due to business need or a high volume of applicants

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Education:UNAVAILABLEEmployment Type: FULL_TIME

What First Citizens Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom