> Markdown version of [/jobs/ext/1852812-cyber-incident-responder](https://www.wearedevelopers.com/jobs/ext/1852812-cyber-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Responder - **Company:** PG&E Corporation - **Location:** Concord, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $122,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Digital Forensics, Supervisory Control and Data Acquisition (SCADA), Network Packet, Python (Programming Language), Windows PowerShell, Reverse Engineering, Security Information and Event Management, Scripting, Malware, Information Technology, Cisco - **Published:** July 11, 2026 - **Apply:** https://jobs.pge.com/job/concord/senior-cyber-incident-responder/29673/97632327584 ## About the Role * Integrity * Reliability * Problem Solving * Team Work * Safety Mindset * Flexibility, * Adaptable * Collaborative * Creative * Curious * Results-driven * Thoughtful, The Senior Cyber Incident Responder will be curious and knowledgeable regarding cyber security standards and technologies, able to work independently or with appropriate stakeholders as needed. You will provide the opportunity to focus on threat identification, proactive threat hunting, incident response, and cyber threat intelligence fusion. You will be part of a highly collaborative, dynamic, responsive, and agile team providing incident response and cyber defense services to IT & OT infrastructure., Minimum: * High School or GED-General Educational Development-GED Diploma * 4 years' experience in IT-Information Technology security, including working in Security Operations Centers Desired: * Bachelor's Degree in Computer Science or job-related discipline or equivalent experience * Previous experience supporting cyber defense analysis of Operational Technology (OT) Networks, including Integrated Controls Systems (ICS), SCADA, and Process Control Networks (PCN). * Formal IT Security/Network Certification, such as WCNA, CompTIA Security +, Cisco CCNA, GIAC GCIH, GMON, GCFA, GCFE, GREM, GICSP, GRID, or other relevant certifications * Utility Industry experience * Experience with compliance standards: NERC-CIP, SOX, TSA * Previous experience working with various SIEM, EDR, and digital forensic technologies * Experience with scripting in Python, PowerShell * Malware reverse engineering skills ## Description The Security Intelligence and Operations Center (SIOC) is responsible for ensuring that PG&E proactively identifies and assesses threats to its user and operational network and data, monitors its network for malicious activity, investigates intrusions and other relevant events, and has a sophisticated and detailed understanding of the evolving threat landscape., * Maintain knowledge of adversary activities, including intrusion tactics, attack techniques and operational procedures. * Investigate and respond to potential cybersecurity incidents * Analysis of security event logs from a variety of sources * Forensic analysis of potential evidence * Static and dynamic malware analysis * Network packet capture analysis * Lead incident response efforts, coordinating resources as needed * Documentation of analysis, including summarization for executive review * Perform proactive threat hunting * Work cross-functionally to recommend, facilitate, and test security control improvements * Create and refine security operations workflows for new and existing tools * Provide guidance to junior analysts * Share on-call responsibility outside of business hours, onsite and remote ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps)