> Markdown version of [/jobs/ext/1830867-digital-forensic-and-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/1830867-digital-forensic-and-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensic and Incident Response Analyst - **Company:** Merck Sharp & Dohme LLC - **Location:** Frankfort, KY, United States (Remote available) - **Experience:** Experienced - **Salary:** $79,200.0 - $124,700.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Cyber Security, Information Leak Prevention, Digital Forensics, Intrusion Detection Systems, Python (Programming Language), Network Security, Log Analysis, Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Malware, Cyber Threat Analysis, Cybercrime, Ddos, Vulnerability Analysis - **Published:** July 12, 2026 - **Apply:** https://www.juju.com/job/00000000gfvsv2 ## About the Role + High School Diploma required. + Equivalent experience and/or education is accepted in place. Required Experience and Skills: + 3-5 years of experience Incident Response or Cybersecurity (Education and Bootcamps included) + Intimate knowledge of the Cyber Kill Chain, MITRE ATT&CK Framework, or other relevant network defense and intelligence frameworks. + Advanced knowledge of security technologies, such as, SIEM, EDR Tools, Host and Network Security Tools and Vulnerability Management tools. + Excellent written and oral communication skills. + Demonstrated ability to work independently and as part of global teams in a fast-paced global environment. Preferred Experience and Skills: + IT Security Certifications (GCIH, CySA+, SANS) + Familiarity with Agile methodology. + Working knowledge of Software Development Lifecycle Practices. + Experience with Python, networking, IDS/IPS., Adaptability, Analytical Thinking, Cyber Threat Hunting, Cyber Threat Intelligence, Data Loss Prevention (DLP), Detail-Oriented, Digital Forensics, Incident Response Management, Insider Threat Mitigation, Log Analysis, Malware Analysis, Security Information and Event Management (SIEM), Security Monitoring, Security Operations, SLA Management, Team Collaboration, Vulnerability Assessments, Vulnerability Management, Written Communication ## Description Digital Forensic and Incident Response (DFIR) Analyst will be a member of our Cyber Fusion Center Team and support our Incident Response function. This position will provide support to security operations through incident triage, event analysis, documentation updates, incident response and other SOC duties assigned. This position supports a 24x7x365 support staff and candidates should be open to working a rotating schedule with non-core hours. This position will be a hybrid working environment with a mix of remote and onsite work., + Responds to IT security incidents according to the IT security incident response policy. + Provides guidance to first level responders for handling information security incidents. + Actively manage, drives, and provide recommendations on third party remediation efforts. + Provides investigation findings for cyber events (intrusions, malware, DDoS, unauthorized access, insider attacks and loss of proprietary information) to the relevant cyber security assurance functions to help improve information security posture. + Respond to high-priority requests for information/intelligence from senior stakeholders. + Validates and maintains incident response plans and processes to address potential threats. + Build strong relationships with business and technology stakeholders. + Effectively represent the team and communicate with all levels of organization including senior management and business stakeholders. + Identify and develop workflow automation to lower response time and eliminate lengthy procedures during incident investigation. + Perform additional analysis of escalations from Incident Response Analysts and conduct case review + Develop specific expertise, to discern patterns of complex threat actor behavior, and to communicate an understanding of current and developing cyber threats ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)