Merck & Co, Inc

Lead Incident Response Analyst - Detection and Response

Merck & Co, Inc$117K — $184K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent work experience
  • 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection
  • Proven ability to lead complex investigations in cloud environments and modern endpoint tooling
  • Experience building detection and response programs with leadership
  • Strong understanding of attacker techniques and log analysis methods
  • Practical knowledge of digital forensics and incident containment
  • Ability to analyze cloud security logs and implement containment measures.

Responsibilities

  • Conduct incident response for escalated alerts, including scoping and containment across cloud and endpoint environments
  • Perform forensic reviews of affected systems, focusing on log correlation and event reconstruction
  • Provide incident findings and recommended remediation steps to both technical and non-technical stakeholders
  • Lead the initial response for high-impact cybersecurity events
  • Mentor and lead team members, overseeing day-to-day operations
  • Coordinate incident transfer between geographical teams and shifts
  • Update playbooks to improve processes and information sharing across teams.

Benefits

  • Medical, dental, and vision healthcare for employees and their families
  • Retirement benefits including 401(k)
  • Paid holidays and vacation days
  • Compassionate and sick days
  • Comprehensive insurance benefits.
Full Job Description
Job Description

Summary:

The Lead Incident Response Analyst is responsible for the day-to-day operations of the team that enables the CFC to respond to an emerging security incident with a coordinated response in the first 0-24hours. The team consist of Incident Response Analysts in the US Tech Center. This position directly supports a 24x7x365 support staff and candidates should be opened to supporting incident response functions outside of core hours. This position will require flexibility to work Incidents to containment and collaborate across global technology centers for long-term investigations.

Key Responsibilities:

Position Responsibilities
  • Incident Response & InvestigationConduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency-only on-call availability is required for high-severity incidents.
  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and Various security tooling.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non-technical stakeholders.
  • Coordinate appropriate response activities across teams or directly with partners.


Managerial Responsibilities
  • Lead the initial response for the Cyber Fusion Center for high impact cybersecurity events.
  • Develop, mentor, and lead the teams and individual members.
  • Oversee the day-to-day operations of the team.
  • Coordinate incident transfer between geographical locations and shifts.
  • Provide data analysis of incidents base on prevalent correlations and data.
  • Evaluate events, escalations, and incidents to determine remediation and resolution actions.
  • Update playbooks to improve processes and information sharing across teams.


Minimum Qualifications
  • Bachelors in Computer Science, Cybersecurity or equivalent work experience
  • 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload-level events) and taking containment measures in cloud environments.
  • Excellent written and verbal communication skills, including the ability to produce concise, high-clarity investigative findings.


Preferred Qualifications
  • Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.
  • Prior experience conducting in depth log analysis and correlating events across an enterprise.
  • Exposure to SIEM/SOAR platforms from an investigative perspective.
  • Incident response or forensics-related certifications (e.g., GCIH, GCFA, GNFA, GCFE).


Required Skills:
Adaptability, Adaptability, Analytical Thinking, Cybersecurity, Cyber Threat Analysis, Cyber Threat Hunting, Cyber Threat Intelligence, Data Loss Prevention (DLP), Detail-Oriented, Digital Forensics, Endpoint Management, Event Monitoring, Event Support, Forensic Analysis, Governance Management, Incident/Breach Triage and Containment, Incident Analysis, Incident Management, Incident Response, Incident Response Management, Insider Threat Mitigation, Log Analysis, Malware Analysis, Network Forensics, Offensive Cyber Operations {+ 17 more}

Preferred Skills:

Current Employees apply HERE

Current Contingent Workers apply HERE

The salary range for this role is
$117,000.00 - $184,200.00

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee's position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs.

The successful candidate will be eligible for annual bonus and long-term incentive, if applicable.

We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits.

You can apply for this role through https://jobs.merck.com/us/en (or via the Workday Jobs Hub if you are a current employee). The application deadline for this position is stated on this posting.

Employee Status:
Regular

Relocation:
No relocation

VISA Sponsorship:
No

Travel Requirements:
10%

Flexible Work Arrangements:
Remote

Shift:
1st - Day

Valid Driving License:
No

Hazardous Material(s):
N/A

Job Posting End Date:
09/17/2026
*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.

About Merck & Co, Inc

Schering-Plough Corporation is a major U.S.-based manufacturer of pharmaceuticals. It operates in three segments: Prescription Pharmaceuticals, Animal Health, and Consumer Health Care. Schering-Plough develops products targeting on allergy, cancer, hepatitis, cardiovascular, central nervous system, respiratory system, and more.  It was founded in 1851 by Ernst Christian Friedrich Schering as Schering AG in Germany. Schering-Plough manufactured several pharmaceutical drugs, the most well-known of which were the allergy drugs Claritin and Clarinex, an anti-cholesterol drug Vytorin, and a brain tumor drug Temodar. It also developed drugs targeting on central nervous system and the respiratory system. Schering Plough also owned and operated the major foot care brand name Dr. Scholl's and the skin care line Coppertone. These also became a part of the new company. Schering-Plough was a full member of the European Federation of Pharmaceutical Industries and Associations (EFPIA), a membership which is also maintained by the new Merck.

Merck & Co, Inc Careers

Join the visionary team at Merck & Co, Inc, a global leader in healthcare dedicated to advancing the world of medicine. As part of our professional community, you'll find dynamic job opportunities that foster innovation and leadership across various fields. Merck & Co, Inc is not just a company; it's a place where you can make a difference.

Work You’ll Do

At Merck & Co, Inc, we are committed to improving global health through groundbreaking research and innovative healthcare solutions. Our team is at the forefront of developing new therapies and vaccines that significantly impact public health worldwide. By joining us, you will collaborate with some of the brightest minds in the industry, using your skills to contribute to projects that save and improve lives around the globe.

Explore Career Paths

Whether you're seeking an internship, a graduate opportunity, or a professional position, Merck & Co, Inc offers a range of career paths in environments that promote rapid professional growth and development. Explore job opportunities in research, digital transformation, manufacturing, and more, all while benefiting from a culture that supports diversity and inclusion.

Innovate and Lead

Merck & Co, Inc is an ideal environment for those who lead with curiosity and the drive to innovate. Our leadership is committed to fostering a culture where inventive thinking and collaboration are encouraged, making it a perfect place for professionals who seek to make an impact through their work.

Develop Your Skills

With Merck & Co, Inc, you are not just getting a job; you're gaining access to unparalleled career development opportunities. Enhance your skills through diverse training programs, workshops, and continuous learning courses designed to help you grow at every stage of your career.

Benefits and Culture

We understand that our employees are our greatest asset, which is why we offer competitive benefits designed to support the health and well-being of you and your family. From comprehensive health care coverage and retirement plans to flexible working conditions and wellness programs, our benefits package is designed to meet the diverse needs of our team members.

Join Our Team

Ready to advance your career at Merck & Co, Inc? Search open positions that match your skills and interests. We are continuously hiring and looking for passionate, creative, and solution-driven team players. Prepare your resume, sharpen your interview skills, and become part of a company that's dedicated to making a difference.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Engage with us through our careers blog and by participating in networking events and employment fairs. Subscribe to receive personalized job alerts and the latest news tailored to your preferences. Discover the exciting and rewarding opportunities that await at Merck & Co, Inc. Join us in our mission to improve health and wellness around the world.
Learn more about Merck & Co, Inc
Size
68,000 employees
Market Cap
$282.6 billion
Industry
Net Income
$7 billion
Founded
1668
5 Year Trend
+4.1%
Revenue
$47.9 billion
NASDAQ

Similar Jobs

More Jobs at Merck & Co, Inc

More Information Technology Jobs

Find similar Lead Incident Response Analyst - Detection and Response jobs: