Incident Response Analyst

Columbia Advisory Group

$80K — $120K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of hands-on incident response experience
  • Deep expertise in Windows endpoint investigation
  • Proficient in Active Directory, Entra ID, and Microsoft 365 security
  • Experience with ransomware, BEC, and data exfiltration incidents
  • Strong familiarity with EDR tools, particularly CrowdStrike
  • Skilled in analyzing various security telemetry
  • Excellent documentation and communication skills

Responsibilities

  • Support active cybersecurity incidents from investigation to recovery
  • Respond to and manage incidents like ransomware and credential theft
  • Scope incidents and identify affected users and systems
  • Reconstruct attack timelines and identify attacker activities
  • Provide clear containment and remediation recommendations
  • Document investigative findings and case management processes
  • Collaborate with senior teams during high-pressure situations

Benefits

  • Fully remote work arrangement
  • Flexible hours
  • Dynamic work on current cybersecurity incidents
  • Opportunity to work with senior DFIR personnel
  • Exposure to a wide range of cybersecurity challenges
  • Career advancement opportunities within the organization
Full Job Description
Incident Response Analyst

Location: Remote - U.S.

Work Arrangement: Remote

Type: Full-time

Role Focus

Hands-on incident response position supporting active cybersecurity incidents from initial investigation through containment, scoping, eradication, and recovery. This role will work directly on ransomware, business email compromise, credential theft, cloud compromise, lateral movement, data exfiltration, and other active security incidents. Remote position, must currently live in the U.S. and not require sponsorship or a 3rd party at any time.

Target Candidate
  • Professional hands-on incident response experience
  • Strong Windows endpoint investigation experience
  • Strong understanding of Active Directory, Entra ID, Microsoft 365, authentication, and identity-related attacks
  • Experience responding to ransomware, BEC, compromised accounts, persistence, credential access, lateral movement, and data exfiltration
  • Strong EDR experience; CrowdStrike experience strongly preferred
  • Experience analyzing endpoint, authentication, identity, network, email, and cloud telemetry
  • Ability to scope incidents and identify affected users, systems, accounts, and infrastructure
  • Experience identifying attacker activity and reconstructing attack timelines
  • Comfortable making containment and remediation recommendations during active incidents
  • Ability to operate effectively during high-pressure and rapidly evolving incidents
  • Strong investigative documentation and case management discipline
  • Ability to communicate findings clearly to senior technical personnel, engagement leadership, clients, and other stakeholders
  • Digital forensics experience is beneficial, but this position should be incident-response-first
  • Currently reside in the U.S. and be eligible to work for any U.S. employer without ever requiring sponsorship or a 3rd party
  • Able to pass a background check


Level: Analyst / Senior Analyst depending on experience

Preference: Experienced responder capable of independently owning significant portions of an active incident while coordinating effectively with senior DFIR personnel.

Compensation: $80,000-$120,000 and benefits package

Similar Jobs

More Jobs at Columbia Advisory Group

  • Senior Network and Systems Engineer (locals only)
    $80K — $90K *
    East Syracuse, NY 13057 (Onondaga County)
    Information Technology
    In-Person
  • IT Project Manager
    $95K — $115K *
    Houston, TX 77084 (Harris County)
    Information Technology
    In-Person
  • vCIO
    $150K — $180K *
    California City, CA 93505 (Kern County)
    Enterprise Technology
    In-Person
  • SOC Analyst - Albany, NY
    $80K — $95K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Incident Response Analyst jobs: