Technical Incident Response Analyst
Elk Grove Village, IL, United States
USD 98K-130K (estimate) Mid-level Full Time
Tasks
- Analyze authentication endpoint network and application activity
- Assign or resolve Microsoft Defender alerts
- Collaborate with Infrastructure and Application teams
- Communicate incident status
- Contain threats using incident response playbooks
- Correlate data across security platforms
- Document incident activity
- Escalate unauthorized changes
- Investigate phishing emails
- Investigate security incidents
- Monitor cybersecurity alerts
- Participate in SOC working group sessions
- Perform log reviews using templates
- Prepare incident reporting for audit and regulatory reviews
- Reconcile firewall rule changes
- Remediate security incidents
- Review SIEM and Kibana dashboards
- Review external SOC tickets for closure
- Review firewall logs and intrusion alerts
- Track incidents end to end closure
- Update alerts and incident response playbooks
- Validate change authorization and compliance
- Validate evidence with screenshots and reports
Perks/Benefits
- N/A
Skills/Tech-stack
365 Security | Anti-Malware | Endpoint protection | Firewall | HIDS | IDS | Incident Response | Intrusion Detection | Intrusion Detection System | Intrusion Prevention | Intrusion Prevention System | Kibana | Linux | Log Analysis | Microsoft 365 | Microsoft 365 Security | Microsoft Defender | NIDS | Phishing analysis | SIEM | Security monitoring | TCPIP
Education
N/A
Regions
Countries
States
Related jobs
-
IT Security Analyst USD 60K-75KAccess Management | DLP | Email Security | Endpoint Security | Google WorkspaceMentorship | TrainingEntry-level Full TimeAnaheim, CA, United States9h ago
-
Senior SIEM Engineer USD 130K-145KAlert Tuning | Automation | Compliance reporting | Correlation rules | DashboardingCleared positionSenior-level Full TimeWashington, DC, United States9h ago
-
Mid. Cyber Incident Coordinator USD 133K-160KComputer Networking | Computer fundamentals | Cybersecurity | Detection engineering | Incident ResponseOn-site workSenior-level Full TimeARLINGTON, VA, United States9h ago
-
Security Engineer - Mid USD 66K-82KAccess Control | Cybersecurity | Network Security | Risk Management | Security ArchitectureEntry-level Full TimeMaxwell Airforce Base, AL, United States9h ago
-
Comptroller - Enterprise Security Analyst I USD 75K-79KAntivirus | Application Security | Cybersecurity | DLP | Digital forensicsFlexible work schedule | Insurance | On-the-job training | Retirement plan | Teambuilding exercisesMid-level Full TimeTexas-Austin12h ago
-
Mid-level Full TimeHuntsville, Alabama, United States13h ago
-
Archer | Automation | Correlation rules | CrowdStrike | Event CorrelationSenior-level Full TimeArlington/Rosslyn, Virginia, United States13h ago
-
Lead Security Engineer II, Splunk Security Content Visualization Expert (Secret Clearance) USD 102K-188KAlerts | Correlation | Dashboards | Data models | Indicators of compromiseSenior-level Full TimeArlington/Rosslyn, Virginia, United States13h ago
-
Security Engineer III, Cyber Threat Hunter USD 107K-188KAmazon Web Services | Analytic Rules | Cloud Security | Cloud security monitoring | Detection and ResponseSenior-level Full TimeArlington/Rosslyn, Virginia, United States; Baltimore, Maryland, …13h ago
-
Senior Security Researcher USD 119K-261KAdversary Emulation | Anomaly Detection | C++ | Cloud Security | Command and controlSenior-level Full TimeRedmond, WA, US; Reston, VA, US18h ago
-
Security Engineer, Detection and Response USD 230K-260KAWS | Adversary Emulation | Azure | Blue Team | Cloud SecurityEquity | Flexible work options | Health benefits | On-call rotationSenior-level Full TimeSan Francisco, California22h ago
-
Manager, Enterprise Security Engineering USD 166K-220KAWS | AWS CDK | Azure | CI/CD | Cloud SecurityMid-level Full TimeWashington, District of Columbia, United States1d ago
-
Lead Cyber Defense Center Analyst USD 90K-157KAD | AV | Access Management | Active Directory | AntivirusEmployee assistance program | Family care support | Flexible work/life support | Insurance coverage | On-call rotationSenior-level Full TimeQuincy, Massachusetts, United States1d ago
-
Cybersecurity Analyst, Mid USD 62K-141K800-53 | AWS | AandA | Assessment and Authorization | Cloud SecurityDependent care | Disability insurance | Financial benefits | Health insurance | Life insuranceMid-level Full TimeUSA, DC, Washington (400 7th St …1d ago
-
Cybersecurity Engineer and Risk Analyst USD 61K-141KApplication Firewall | Assessment and Authorization | Big Data | Big data analytics | Cloud ComputingMid-level Full TimeUSA, CA, San Diego (4301 Pacific …1d ago
-
Cybersecurity Analyst, Mid USD 62K-141K800-53 | AWS | Authorization and Assessment | Azure | Cloud SecurityDependent care | Paid leave | Professional development | Tuition assistance | Work-life programsMid-level Full TimeUSA, DC, Washington (400 7th St …1d ago
-
Security Engineer, Senior USD 99K-225K800-53 | AWS | Azure | Bash | CI/CDDependent care | Paid leave | Professional development | Tuition assistance | Work-life programsSenior-level Full TimeUSA, DC, Washington (400 7th St …1d ago
-
Specialist, Security Operations Center USD 70K-118KAlarm investigation | Incident Analysis | Incident Response | Open Source | Open-source intelligenceEntry-level Full TimePA - West Chester, 1354 Boot …1d ago
-
Senior-level Full TimeNashville, TN, United States1d ago
-
Product Security Engineer, Staff USD 149K-224KAndroid security | Binary Analysis | Binary Ninja | Bluetooth | CDMASenior-level Full TimeSan Diego, California, United States of …1d ago
-
Cybersecurity Incident Response Analyst USD 85K-115KCloud Security | Digital forensics | Dynamic malware analysis | Firewalls | Incident ResponseOn-call rotationMid-level Full TimeLos Angeles, CA, United States1d ago
-
Cybersecurity Incident Response Analyst USD 85K-115KCloud Security | Dynamic malware analysis | Firewall | Forensics | Incident ResponseOn-call supportMid-level Full TimeLos Angeles, CA, United States1d ago
-
Information Systems Security Officer (ISSO) I USD 90K-122KAudit Logging | Authorization management | Configuration Management | Incident Handling | Information Security Management401k match | Dental insurance | Flex work week | Health insurance options | Life insuranceEntry-level Full TimeUSA VA Arlington - Customer Proprietary …1d ago
-
COMSEC | Common Criteria | Data Backup | Exchange Server | Information Security Management401k match | Dental insurance | Disability insurance | Health insurance | Life insuranceMid-level Full TimeUSA CO Colorado Springs - - …1d ago
-
Senior Incident Response Analyst USD 131K-237KBash | Case management | Cyber Kill Chain | Cybersecurity | DHCPSenior-level Full Time9614 Arlington VA Non-specific Customer Site, …1d ago