> Markdown version of [/jobs/ext/2013701-cyber-incident-response-analyst-ii](https://www.wearedevelopers.com/jobs/ext/2013701-cyber-incident-response-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Response Analyst II - **Company:** AmTrust Financial Services, Inc. - **Location:** Cleveland, OH, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Query Languages, Digital Forensics, Monitoring of Systems, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Windows PowerShell, Kusto Query Language, Security Information and Event Management, Scripting, Malware, Cyber Threat Analysis, Information Technology, Cybercrime - **Published:** August 10, 2026 - **Apply:** https://careers-amtrustgroup.icims.com/jobs/20759/cyber-incident-response-analyst-ii/job?mode=apply&apply=yes&in_iframe=1&hashed=-336092593 ## About the Role * Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field. Equivalent practical experience may be considered in lieu of a degree. * 3-5+ years of experience in cyber security incident response, digital forensics, security operations, threat hunting, or related cyber security disciplines. * Experience investigating and responding to security incidents in enterprise environments. * Strong understanding of threat actor tactics, techniques, and procedures, cyber attack methodologies, and incident response frameworks. * Experience working with security monitoring technologies, including SIEM, EDR/XDR, email security, identity security, and cloud security platforms. * Ability to manage multiple investigations while maintaining attention to detail and documentation quality. * Strong analytical, problem solving, written, and verbal communication skills. * Ability to effectively communicate technical findings and risk-based recommendations to both technical and non-technical audiences. * Proven ability to work independently, manage competing priorities, and perform effectively in fast-paced, high-pressure environments. Preferred: * Industry certifications such as Security+, CySA+, SecurityX (formerly CASP+) GCIH, GCFA, GCIA, GNFA, CISSP, or other relevant cybersecurity certifications. * Experience investigating incidents across hybrid environments. * Experience conducting malware analysis, memory analysis, and digital forensic investigations. * Knowledge of scripting, automation, and query languages such as PowerShell, Python, KQL, SPL, or similar languages. * Experience operating in highly regulated industries and familiarity with applicable cybersecurity regulatory requirements. ## Description The Cyber Security Incident Response II is responsible for detecting, analyzing, investigating, and responding to cybersecurity threats and incidents across the enterprise. This role performs advanced threat detection, incident triage, forensic analysis, containment, and recovery activities coordinated across internal and external stakeholders. The ideal candidate possesses a strong foundation in cyber security incident response, digital forensics, detection capabilities, and stakeholder engagement. This position requires the ability to independently manage complex cybersecurity incidents, collaborate effectively with business and technical teams, influence decision-making through risk-based recommendations, and perform successfully in time-sensitive and high-pressure environments. This role partners with third-party service providers, vendors, infrastructure teams, and security engineering and architecture teams to strengthen the organization's security posture and improve incident response capabilities. The candidate will maintain a strong understanding of AmTrust's mission, vision, and values while upholding the highest standards of professionalism and service., * Investigate security alerts, suspicious activity, and cybersecurity incidents to determine scope, impact, root cause, and remediation actions. * Lead the analysis and response efforts for medium- to high-complexity security incidents, ensuring timely containment, eradication, recovery, and documentation. * Perform digital forensics, log analysis, artifact collection and preservation, and host and network investigations using enterprise security monitoring and endpoint detection tools. * Analyze indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and threat intelligence to support investigations. * Utilize SIEM, EDR, threat intelligence, cloud security, and case management platforms to investigate and respond to security incidents. * Develop and maintain detection logic, correlation rules, analytics, and response playbooks to improve detection and response capabilities. * Document investigation findings, incident timelines, root cause analysis, and lessons learned in accordance with established procedures. * Collaborate with IT, Security, Legal, Risk, HR, and Compliance teams as required during incident investigations. * Participate in tabletop exercises, incident response simulations, and post-incident reviews to validate and improve response readiness. * Recommend improvements to security controls, detection content, monitoring coverage, and response processes based on investigative findings. * Participate in on-call and after-hours incident response support as required. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany)