Job Description: Incident Response AnalystPosition Title Incident Response Analyst
Job Summary We are seeking an experienced Incident Response Analyst to investigate, contain, and remediate cybersecurity incidents across enterprise environments. The ideal candidate will respond to security events, perform forensic investigations, analyze attacker activities, and coordinate response efforts to minimize business impact and improve organizational security resilience.
Key Responsibilities - Monitor, investigate, and respond to cybersecurity incidents including malware infections, phishing attacks, ransomware, data breaches, and unauthorized access.
- Perform incident triage, classification, prioritization, and escalation based on severity and business impact.
- Execute incident response processes following established security frameworks and playbooks.
- Conduct digital forensic analysis on endpoints, servers, network devices, and cloud environments.
- Perform root cause analysis to determine attack vectors, affected systems, and scope of compromise.
- Collect, preserve, and analyze forensic evidence while maintaining chain of custody.
- Analyze security logs, endpoint telemetry, network traffic, and threat intelligence data.
- Identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs).
- Support containment activities such as isolating affected systems, blocking malicious indicators, and removing threats.
- Assist with eradication and recovery activities after security incidents.
- Conduct malware analysis and suspicious file investigations.
- Perform threat hunting activities based on incident findings and intelligence.
- Develop incident reports, executive summaries, and technical documentation.
- Collaborate with SOC analysts, security engineers, IT teams, legal teams, and business stakeholders.
- Improve incident response procedures, playbooks, and security controls based on lessons learned.
Required Technical Skills - Strong understanding of incident response lifecycle:
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons Learned
- Experience with security monitoring and investigation tools:
- SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, ArcSight)
- EDR/XDR platforms (CrowdStrike, Microsoft Defender, SentinelOne)
- Network monitoring tools
- Threat intelligence platforms
- Knowledge of digital forensics concepts:
- Disk forensics
- Memory analysis
- Log analysis
- Timeline analysis
- Evidence handling
- Experience investigating:
- Phishing attacks
- Malware infections
- Credential compromise
- Insider threats
- Ransomware incidents
- Advanced persistent threats (APTs)
- Understanding of MITRE Telecommunication&CK framework and attacker behaviors.
- Knowledge of Windows and Linux security internals.
- Familiarity with scripting languages such as Python, PowerShell, or Bash for automation and analysis.
Preferred Tools & Technologies - Forensics:
- EnCase
- FTK
- Autopsy
- Volatility
- KAPE
- Security Platforms:
- Splunk
- Microsoft Sentinel
- CrowdStrike Falcon
- Microsoft Defender for Endpoint
- Network Analysis:
- Case Management:
Certifications (Preferred) - GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Incident Handler (ECIH)
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- OSCP (Offensive Security Certified Professional)
Education & Experience - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field preferred.
- Experience in incident response, SOC operations, digital forensics, or cybersecurity investigations.
- Experience handling security incidents in enterprise environments.
- Knowledge of security frameworks such as NIST Cybersecurity Framework and MITRE Telecommunication&CK.
Soft Skills - Strong analytical and investigative skills.
- Ability to work effectively under pressure during security incidents.
- Excellent documentation and reporting abilities.
- Strong communication skills with technical and non-technical stakeholders.
- Ability to collaborate across multiple teams.
- Strong attention to detail and problem-solving mindset.
Key Deliverables - Incident investigation reports.
- Root cause analysis documentation.
- Evidence collection and forensic analysis reports.
- Threat intelligence and IOC documentation.
- Incident response recommendations.
- Post-incident improvement plans.
Role Type Full-time / Contract
Department Cybersecurity / Incident Response / Security Operations