
Incident Response Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Arizona, +1 more state.
• Assess, investigate, and respond to security alerts within enterprise and product environments.
• Identify threats, gather evidence, and drive response actions utilizing Splunk and security platforms.
• Collaborate with Detection Engineering to refine detections, minimize false positives, and address coverage gaps.
• Develop and sustain SOC automation, including scripts, playbooks, and enrichment workflows.
• Utilize AI-assisted and agentic tools for investigations under human oversight.
• Conduct threat hunting and lead incident review processes.
• Contribute to inter-team investigations and enhance overall SOC quality.
• Manage security incidents from initial alert through to a documented resolution.
• Work from Wednesday to Saturday, 10:00am–8:00pm Pacific time.
• Participate in an on-call rotation one week every two months, from 11:00pm to 8:00am Eastern Standard Time.
• Bachelor’s Degree.
• Over 4 years of experience in security operations, incident response, or a related technical discipline.
• Proficient understanding of incident response, alert triage, threat hunting, evidence management, escalation workflows, and attacker tactics.
• Hands-on experience with triaging and investigating alerts using SIEM, EDR, cloud, or network security tools.
• Familiarity with Git/GitLab workflows, including branching, merge requests, code reviews, and CI/CD processes.
• Experience in developing automation scripts and updating playbooks, pipeline configurations, or modular tooling.
• Background in AI-assisted development, AI-driven security tools, or agentic workflows.
• Ability to critically assess AI/tool outputs prior to taking action.
• Knowledge of MITRE ATT&CK, threat hunting methodologies, malware triage, phishing analysis, vulnerability exploitation, attacker infrastructure analysis, or SOC performance metrics.
• Strong written and verbal communication skills.
• Experience with Splunk Enterprise Security, Splunk SPL, SOAR platforms, or large-scale security telemetry environments.
• Experience in building, maintaining, or reviewing SOC automation, enrichment workflows, SOAR playbooks, detection-as-code, reusable modules, or agentic investigation workflows.
• Familiarity with GitLab CI/CD or comparable pipeline systems.
• Knowledge of cloud technologies, containers, Kubernetes, CI/CD runners, artifact registries, package management, or software supply chain security.
• Scripting or automation experience in Python, Bash, Go, or JavaScript.
• Must be a U.S. Person (U.S. citizen).
• Must be able to perform work that is restricted to a U.S. citizen on U.S. soil.
• Medical, dental, and vision insurance.
• 401(k) plan with Cisco matching contributions.
• Paid parental leave.
• Coverage for short- and long-term disability.
• Basic life insurance.
• Cisco restricted stock unit grants may be available.
• 10 paid holidays each full calendar year.
• 1 floating holiday for non-exempt employees.
• 1 paid day off to celebrate the employee’s birthday.
• Paid holiday shutdown at the end of the year.
• 4 paid days off dedicated to personal wellness.
• 16 days of paid vacation per full calendar year for non-exempt employees.
• Flexible vacation time off program with no defined limit for eligible exempt employees.
• 80 hours of sick leave provided upon hire and each January 1st thereafter.
• Up to 80 hours of unused sick leave may be carried forward.
• Additional paid time off for critical or emergency family matters.
• Optional 10 paid days per full calendar year for volunteering.
• Annual bonuses may be available for non-sales roles.
• Sales employees may qualify for performance-based incentive pay.
• Opportunities for professional growth and development.
• Collaboration within a global network and team.
COREnglish
COREnglish
United Franchise Group
Symbotic
Get handpicked remote jobs straight to your inbox weekly.