Incident Responder

SchoolsFirst FCU
Sacramento, United States of America
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Languages
English
Experience level
Junior
Compensation
$ 132K

Job location

Sacramento, United States of America

Tech stack

Microsoft Active Directory
CompTIA Security+
Computer Networks
Python
Powershell
Standard Sql
Security Information and Event Management
TCP/IP
Scripting (Bash/Python/Go/Ruby)
Computer Network Operations
Information Technology
Performance Monitor
Splunk
Appdynamics
ServiceNow

Job description

Responsible for responding to all major systems and service incidents during business hours and extended business hours in support of IT Incident Management program. Creates and maintains unified monitoring of Infrastructure, Application and Business & IT services to proactively detect, predict and prevent service, application and security problems.

  • Monitors security and network operations in a 24x7 environment and escalates exceptions based on established procedures.
  • Participates in on-call rotation supporting production systems.
  • Performs initial triage, correlation, and documentation of security, availability, and service incidents.
  • Investigates alerts using standard tools and predefined queries; escalates incidents requiring advanced analysis or coordination.
  • Executes established incident response and availability playbooks for repeatable events.
  • Maintains accurate incident records and provides status updates to stakeholders during the incident lifecycle.
  • Utilizes and maintains monitoring dashboards and alert views (e.g., ServiceNow, Splunk, Orion, Tenable, AppDynamics, Sentinel).
  • Uses prebuilt dashboards and analytics to identify potential issues (service degradation, security events, insider risk indicators).
  • Follows established monitoring rules and procedures to support proactive fault detection and reduce alert noise.
  • Coordinates with internal teams and vendors for resolution of assigned incidents.
  • Tracks SLA adherence and ensures data quality for reporting and KPI tracking.
  • Maintains working knowledge of tools, processes, and incident response best practices.

Additional Job Functions

  • Performs other duties as assigned
  • Complies with regulatory compliance and assigned training requirements including but not limited to BSA regulations corresponding to their specific job duties. Failure to do so may result in disciplinary and other employment related actions

Requirements

Do you have experience in Vendor coordination?, Do you have a High school diploma or GED?, We're always looking for diverse, talented, service-oriented people to join our exceptional team., * High School Diploma or GED required

  • Bachelor's Degree in a related field or equivalent years of experience required

  • 1-3 years of prior relevant experience required

  • CompTIA Security+ required

  • ITIL Foundation required

  • CompTIA CySA+ preferred

  • Splunk Power User preferred

  • Certified CyberDefender preferred

Knowledge, Skills, and Abilities

  • Demonstrated ability to solve structured problems with guidance; developing capability for unstructured scenarios.
  • Excellent written and verbal communication with ability to document incidents clearly.
  • Basic knowledge of TCP/IP and operating systems.
  • Foundational understanding of enterprise security and monitoring concepts.
  • Familiarity with reading basic Kusto Query Language (KQL) and Search Processing Language (SPL).
  • Foundational understanding of industry security frameworks (e.g., ISO 27001, NIST 800-53)
  • Working knowledge of:
  • Microsoft Active Directory, Exchange, SQL
  • Enterprise network operations
  • SIEM platforms and alerting frameworks
  • Scripting basics (PowerShell / Python)
  • Change Management and system hardening practices
  • SOC operations processes and tooling

Additional Knowledge, Skills, and Abilities

  • Understands basic alert types and indicators across endpoint, network, and cloud sources. Participates in tabletop exercises as a responder executing predefined playbooks, validating alert triage and escalation processes, and documenting actions to support testing of detection and response procedures. Follows predefined detection logic and recognizes common false positives. Understands the incident response lifecycle and follows defined playbooks. Escalates incidents based on predefined severity and impact criteria. Reviews logs and alerts to support basic investigations and documentation. Identifies obvious indicators of compromise using available tools. Understands basic integration between tools (SIEM, EDR, ticketing). Understands basic business impact of incidents (service disruption, user impact). Escalates issues affecting critical systems or users. Provides clear and accurate incident updates to internal teams. Documents incidents in a structured and understandable format. Identifies basic issues in alerts, processes, or documentation. Provides feedback to improve playbooks and monitoring. Understands basic concepts of security controls and alert generation. Recognizes how alerts are triggered within tools.

Benefits & conditions

3.83.8 out of 5 stars Sacramento, CA Hybrid work $42.41 - $63.62 an hour - Full-time, The pay range for this position is listed below. Our pay ranges are built to allow for candidates with various levels of skill and experience to be considered, as well as for room for growth and tenure achieved in a role over time. Typical new hire salary offers fall within the minimum to midpoint of a pay range for many candidates. Any offer extended to a candidate will be based upon their unique set of knowledge, skills, education, and experience as well as internal equity.

Pay Range: $42.41 - $63.62

Scheduled Weekly Hours:

40

Apply for this position