SOC THREAT DETECTION & INCIDENT RESPONSE ANALYST Job Title: SOC Threat Detection & Incident Response Analyst Location: Remote Position Type: Full-Time / Contract-to-Hire Operational Shift: Monday ...

60 Flashpoint Incident Response Analyst Jobs Hiring Near You
SOC THREAT DETECTION & INCIDENT RESPONSE ANALYST Job Title: SOC Threat Detection & Incident Response Analyst Location: Remote Position Type: Full-Time / Contract-to-Hire Operational Shift: Monday ...
... incident response capabilities. This role requires a strong technical background, participation in on-call rotations, excellent analytical skills, and a proactive approach to cybersecurity. This ...
... incident response capabilities. This role requires a strong technical background, participation in on-call rotations, excellent analytical skills, and a proactive approach to cybersecurity. This ...
Tier II Incident Response Analyst
Bethesda, MD · On-site +1
$85K - $110K/yr
Overview Edgewater Federal Solutions is currently seeking a Tier II Incident Response Analyst to provide support to an Edgewater Federal government contract. **Due to the nature of the contract and ...
Tier II Incident Response Analyst
Bethesda, MD · On-site +1
$85K - $110K/yr
Overview Edgewater Federal Solutions is currently seeking a Tier II Incident Response Analyst to provide support to an Edgewater Federal government contract. **Due to the nature of the contract and ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
Incident Response Analyst I
Austin, TX · On-site
$59K - $94K/yr
Leads incident handling, coordinates cross-functional responses, and performs forensic analysis. * Oversees incident response strategy, threat hunting, red/blue teaming initiatives, and executive ...
Incident Response Analyst I
Austin, TX · On-site
$59K - $94K/yr
Leads incident handling, coordinates cross-functional responses, and performs forensic analysis. * Oversees incident response strategy, threat hunting, red/blue teaming initiatives, and executive ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
The Cyber Incident Response Analyst will work a 4-day work week; 10 hours per shift. Staff will be assigned to either Sun-Wed or Wed-Sat. The schedule is fixed and does not rotate. We have openings ...
Sr. Incident Response Analyst
Austin, TX · Remote
$146K - $235K/yr
Collaborate effectively with other security teams, IT, and business units during incident response * Contribute to post-incident reports and analysis Job Designation Hybrid: Employee divides their ...
Sr. Incident Response Analyst
Austin, TX · Remote
$146K - $235K/yr
Collaborate effectively with other security teams, IT, and business units during incident response * Contribute to post-incident reports and analysis Job Designation Hybrid: Employee divides their ...
Amentum is seeking SOC / Incident Response Analyst to support our U.S. Department of Energy contract. Positions will be based in the Washington, D.C area. Work Schedule: 5 days, 8hrs Essential ...
Amentum is seeking SOC / Incident Response Analyst to support our U.S. Department of Energy contract. Positions will be based in the Washington, D.C area. Work Schedule: 5 days, 8hrs Essential ...
... or vulnerability analysis 6+ years of experience in information security, especially in an incident response role Understanding of network security devices, protocols, routing, and services ...
... or vulnerability analysis 6+ years of experience in information security, especially in an incident response role Understanding of network security devices, protocols, routing, and services ...
Cybersecurity Incident Response Analyst
$102K - $123K/yr
Coordinate with both technical and business stakeholders during the incident response process. * Perform host based,cloud based,network based, memory, or log analysis and/or forensics in support ...
Cybersecurity Incident Response Analyst
$102K - $123K/yr
Coordinate with both technical and business stakeholders during the incident response process. * Perform host based,cloud based,network based, memory, or log analysis and/or forensics in support ...
Tier II Incident Response Analyst
Bethesda, MD · On-site +1
$85K - $110K/yr
Overview Edgewater Federal Solutions is currently seeking a Tier II Incident Response Analyst to provide support to an Edgewater Federal government contract. **Due to the nature of the contract and ...
Tier II Incident Response Analyst
Bethesda, MD · On-site +1
$85K - $110K/yr
Overview Edgewater Federal Solutions is currently seeking a Tier II Incident Response Analyst to provide support to an Edgewater Federal government contract. **Due to the nature of the contract and ...
Principal Incident Response Analyst
Sorento, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
Sorento, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
Argenta, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
Argenta, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
Apple River, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
Apple River, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
Principal Incident Response Analyst
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
Principal Incident Response Analyst
Hull, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
Hull, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Incident Response Analyst I
Austin, TX · On-site
$59K - $94K/yr
Leads incident handling, coordinates cross-functional responses, and performs forensic analysis. * Oversees incident response strategy, threat hunting, red/blue teaming initiatives, and executive ...
Incident Response Analyst I
Austin, TX · On-site
$59K - $94K/yr
Leads incident handling, coordinates cross-functional responses, and performs forensic analysis. * Oversees incident response strategy, threat hunting, red/blue teaming initiatives, and executive ...
Principal Incident Response Analyst
Dieterich, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Principal Incident Response Analyst
Dieterich, IL · On-site +1
$121K - $224K/yr
Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security ... Advanced - Demonstrated analytical skills * Advanced - Demonstrated project management skills
New
Senior J-9 Hac Incident Response Analyst Location: Fort Meade, MD 20755 Clearance Level: Active Secret Clearance Job Type: Full-Time Must be U.S. Citizen PD Inc International is seeking an ...
Quick apply
Senior J-9 Hac Incident Response Analyst Location: Fort Meade, MD 20755 Clearance Level: Active Secret Clearance Job Type: Full-Time Must be U.S. Citizen PD Inc International is seeking an ...
Technical Incident Response Analyst - Hybrid (IL)
Elk Grove Village, IL · On-site
$85K - $115K/yr
The Technical Incident Response Analyst is responsible for monitoring, analyzing, and responding to cybersecurity alerts and incidents across enterprise infrastructure and security platforms. This ...
Technical Incident Response Analyst - Hybrid (IL)
Elk Grove Village, IL · On-site
$85K - $115K/yr
The Technical Incident Response Analyst is responsible for monitoring, analyzing, and responding to cybersecurity alerts and incidents across enterprise infrastructure and security platforms. This ...
Flashpoint Jobs Information
What other companies are hiring for Incident Response Analyst jobs?
Other
Posted 8 days ago
Job description
- Detection & SIEM Tools: Wazuh SIEM Dashboard & Correlation Engine, CrowdStrike Falcon (Falcon Console, FDR / Streaming API Telemetry).
- Cloud Security Telemetry: Amazon GuardDuty, AWS Security Hub, AWS WAF, AWS CloudTrail, VPC Flow Logs, Route 53 Resolver logs.
- Application & Data Tiers: Amazon RDS SQL Server audit logs, Windows Event Logs / IIS web logs, Dell Boomi middleware logs, GoAnywhere MFT transfer logs, Salesforce CRM connector logs.
- Posture & Vulnerability Feeds: Wazuh SCA (Security Configuration Assessment), AWS Systems Manager (SSM) vulnerability findings, Containerized Prowler daily compliance reports.
- Operational Frameworks: SOC 2 Type II controls, NIST CSF, and NIST 800-53.
- Active SOC Monitoring & Triage: Monitor cloud, endpoint, network, and application security alerts Monday through Friday (7:00 AM – 6:30 PM PST), adhering to strict SLAs (≤ 15 minutes for Critical severity; ≤ 1 hour for High severity).
- Multi-Stage Threat Correlation: Correlate disparate signals across CrowdStrike Falcon endpoint detections, AWS GuardDuty anomalies, CloudTrail management events, IIS web server logs, and RDS SQL Server audit records to identify complete attack chains.
- Threat Hunting: Conduct hypothesis-driven and intelligence-driven threat hunts focusing on cloud credential hijacking, IAM privilege escalation, impossible-travel anomalies, MFA bypass, and unauthorized data staging/exfiltration.
- Integration Edge & File Transfer Monitoring: Perform targeted monitoring of GoAnywhere MFT, Dell Boomi, and external data exchanges (PG&E feeds) for anomalous file transfers, off-hours execution, or unauthorized outbound connections.
- Incident Response & Containment: Execute response playbooks aligned with enterprise CEOP and CIRP frameworks. Perform host isolation recommendations, credential revocation coordination, and initial evidence preservation.
- Vulnerability & Posture Prioritization: Review daily vulnerability scan outputs from Wazuh SCA/SSM and posture findings from Prowler; prioritize findings by business impact and exploitability, and track remediation with engineering teams.
- Reporting & Governance: Assist in preparing monthly security posture reviews, threat intelligence summaries, and quarterly executive risk dashboards.
- Experience: 3+ years of hands-on experience in a Security Operations Center (SOC), Threat Analysis, or Incident Response role.
- Tooling Proficiency: Direct experience analyzing alerts and querying logs within CrowdStrike Falcon, Wazuh (or ELK/OpenSearch/Splunk SIEM), and AWS Security Hub / GuardDuty.
- Cloud & Identity Threat Knowledge: Practical experience analyzing AWS CloudTrail logs, detecting IAM abuse patterns, credential spraying, and web application attack vectors (OWASP Top 10, AWS WAF rules).
- Log Analysis Skills: Strong ability to inspect and analyze raw logs from Windows Event Viewer, IIS web servers, database audit logs (SQL Server), and API/MFT transactional logs.
- Incident Response Execution: Understanding of formal incident response methodologies (containment, eradication, recovery) and playbook execution.
- U.S. Data Residency Requirement: Must reside and work exclusively within the United States.
- CompTIA CySA+, Security+, or GIAC Certified Incident Handler (GCIH)
- GIAC Certified Enterprise Defender (GCED) or GIAC Cloud Forensics (GCFA)
- Certified Information Systems Security Professional (CISSP) or CISM
- AWS Certified Cloud Practitioner or AWS Certified Solutions Architect Associate
- Prior experience in utility, public power, or critical infrastructure operations.