> Markdown version of [/jobs/ext/1172841-cyber-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/1172841-cyber-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Response Analyst - **Company:** Akaasa Technologies - **Location:** San Antonio, TX, United States - **Salary:** $75,000.0 - $80,000.0 - **Contract:** Temporary to permanent - **Skills:** Microsoft Windows, Cyber Security, Linux, File Systems, Issue Tracking Systems, Data Intelligence, Intrusion Detection Systems, Network Security, Linux System Administration, Log Analysis, Network Monitoring, Security Information and Event Management, In-Plane Switching (IPS), Mitre Att&ck, Malware, Falcon Platform, Cybercrime, Microsoft Sentinel, SentinelOne Expertise - **Published:** July 3, 2026 - **Apply:** https://www.careerjet.com/jobad/us3015f7375a218e5e473496abce7c29f4 ## About the Role 5 Required Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines. 5 Required Experience producing high quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows. 4 Required Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet level and log level data from but not limited to Corelight, NetWitness, and CRIBL pipelines. 3 Required Incident Commander experience 1 Required Experience supporting SLTT or critical infrastructure environments, including multi tenant IR operations and cross agency coordination. PREFERRED 5 Preferred Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE ATT&CK. 5 Preferred Hands on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems. 4 Preferred Security Certifications Preferred (CISSP, CIH, Sec+) ## Description Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery. Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis. Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies. Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE ATT&CK. Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools. Produce incident reports, timelines, and executive summaries for statewide stakeholders. Support multi-agency response operations, including SLTT partners and critical infrastructure entities. Provide recommendations for detection improvements, hardening, and long-term mitigation. Participate in post-incident reviews, lessons learned, and playbook updates. Maintain readiness for 24x7 response through on-call rotation or surge support. MUST HAVE 5 Required Advanced host based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity., Global Security Systems Service Desk Analyst Location: Remote Salary: $75,000-$80,000 The Global Physical Security Service Desk is responsible for safeguarding personnel, fac… + 1 day ago, Cyber Incident & Threat Analyst Contract Length: 12+ months Location: Austin or San Antonio, Texas (Hybrid) The Cyber Incident & Threat Analyst will be on the front lines of so… + 6 days ago ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)