
Senior Incident Response Analyst
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Investigate, triage, analyze, contain, eradicate, and assist with recovery efforts for cybersecurity incidents in both enterprise and cloud settings.
• Conduct thorough analysis of security events produced by SIEM, EDR/XDR, IDS/IPS, cloud-native security solutions, and endpoint technologies.
• Work in collaboration with Security Operations and Splunk Detection Engineering teams to enhance detection content, fine-tune alerts, minimize false positives, and improve detection efficacy.
• Engage in proactive threat hunting utilizing threat intelligence, behavioral analytics, and MITRE ATT&CK methodologies.
• Perform root cause analysis and suggest corrective and preventive measures.
• Document findings from investigations, create incident timelines, summarize lessons learned, and produce technical reports.
• Aid in the development and upkeep of Incident Response playbooks, SOPs, and workflows.
• Assist with the collection of digital evidence and basic forensic tasks, ensuring the preservation of the chain of custody.
• Participate in security evaluations, architecture reviews, tabletop exercises, phishing simulations, and readiness assessments.
• Support security reviews for IT systems, applications, and cloud services.
• Contribute to the formulation of cybersecurity policies, standards, and operational procedures.
• Collaborate with teams in Cloud Security, Vulnerability Management, Infrastructure, and Application areas.
• Monitor incident metrics and assist in operational reporting.
• Keep abreast of emerging threats and best practices within the industry.
• Perform other job-related tasks as assigned.
• Over 5 years of experience in cybersecurity, with a minimum of 3 years focused on Incident Response, Security Operations, Threat Hunting, or Detection Engineering.
• Practical experience in investigating incidents related to Windows, Linux, cloud, identity, and network environments.
• Familiarity with SIEM platforms such as Splunk ES, Microsoft Sentinel, QRadar, or comparable technologies.
• Experience with EDR/XDR platforms like Microsoft Defender, CrowdStrike, SentinelOne, or similar solutions.
• Knowledge of cloud security tools such as AWS GuardDuty, Security Hub, and Azure Defender.
• Strong grasp of MITRE ATT&CK and the incident response lifecycle.
• Proficient in log analysis, malware triage, threat hunting, and root cause analysis.
• Excellent written and verbal communication abilities.
• Capability to excel in a fast-paced operational setting.
• Preferred experience with Splunk Enterprise Security correlation searches and detection tuning.
• Familiarity with Splunk SOAR or similar orchestration platforms is preferred.
• Prior experience in supporting phishing investigations and tabletop exercises is preferred.
• Knowledge of frameworks such as FISMA, FedRAMP, NIST RMF, NIST 800-61, and NIST CSF is preferred.
• Scripting experience in Python or PowerShell is preferred.
• Preferred certifications include GCIH, GCIA, GCFA, CISSP, Security+, CySA+, or CEH.
• Must be qualified to obtain and maintain a Public Trust.
• Relevant past job titles may include, but are not limited to: Incident Response Analyst, Cybersecurity Analyst, Security Operations Center (SOC) Analyst, Threat Hunter, Detection Engineer, and Cyber Incident Responder.
• Must successfully complete pre-employment qualifications for Cherokee Federal.
• Medical
• Dental
• Vision
• 401K
• Other potential benefits as provided. Please note that benefits are subject to change with or without prior notice.
Frasers Group
Genius Agency
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.