> Markdown version of [/jobs/ext/1984805-csirt-analyst](https://www.wearedevelopers.com/jobs/ext/1984805-csirt-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CSIRT Analyst - **Company:** Computer Task Group, Inc - **Location:** Buffalo, NY, United States - **Experience:** Experienced - **Salary:** $125,200.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Computer Forensics, Digital Forensics, Identity and Access Management, Internet Security, Intrusion Detection and Prevention, Microsoft Office, Parsing, Red Team (Cyber Security), Security Information and Event Management, Cyber Threat Analysis, Cybercrime, Blue Team (Cyber Security) - **Published:** August 8, 2026 - **Apply:** https://www.careerbuilder.com/job-details/csirt-analyst-buffalo-ny--a472b4c0-06e0-498f-a9f4-dc92f62292ba ## About the Role * At least 3-5 years of experience in a similar position. * Significant hands-on experience in disk, memory and log acquisition in a forensically sound manner, parsing and deep forensic analysis of extracted artifacts and professional post-incident report writing * A bachelor or master degree or equivalent through experience. * A hands-on and proactive mindset with a 'can do' mentality. * Experience and/or interest in working with the following MDR tools: EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace, ...), xDR (CrowdStrike Identity Protection, MS Defender for Office/Clouds Apps/Identity/...). * Knowledge of Security Monitoring with SIEM technologies.A passion about the following security capabilities: Security Monitoring, Digital Forensics, Incident Response, Threat Intelligence, Threat Hunting., Analysis Skills, Business Solutions, Cloud Applications, Computer Forensics, Computer Security, Federal Laws and Regulations, Forensic Science, Hunting, Incident Response, Intelligence Gathering, Internet Security, Memory Hardware, Microsoft Office, On Call, Procedure Development, Reporting Skills, Security Information and Event Management (SIEM), Security Monitoring, State Laws and Regulations ## Description Do you have a passion for Cyber Security, especially advanced Managed Detection & Response (MDR)? Does Incident Response, Digital Forensics, Threat Hunting, Threat Intelligence and everything related to Cyber Security feel like second nature to you? Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that are under attack? If you answered yes to all of these questions, you might be the perfect fit for our CSIRT Analyst role! * You handle security alerts/incidents that have been escalated by the SOC Analysts (Tier 2) * You will handle security alerts and incidents together with your team * You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs) * You will perform compromise assessments to identify potential compromises and their scope * You collect Threat Intelligence (IOCs and TTPs) * You will contribute to Detection Engineering in SIEM, xDR. * Together with the Red Team you will do Purple Teaming exercises to test and improve defenses * You contribute to the creation of playbooks in SOAR * You will co-write processes and procedures related to DFIR, Threat Intelligence, Threat Hunting. * You will be part of our Incident Response on call service. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)