Cyber Incident Response Analyst

EXPERT RECRUITING SOLUTIONS, LLC
Austin, TX, United States
7 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Cyber Security Linux File Systems Issue Tracking Systems Data Intelligence Internet Security Intrusion Detection Systems Linux System Administration Log Analysis Network Monitoring Security Information and Event Management
+6 more
In-Plane Switching (IPS) Malware Falcon Platform Cybercrime Microsoft Sentinel SentinelOne Expertise

Job description

·Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery. ·Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis. ·Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies. ·Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE Telecommunication&CK. ·Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools. ·Produce incident reports, timelines, and executive summaries for statewide stakeholders. ·Support multi-agency response operations, including SLTT partners and critical infrastructure entities. ·Provide recommendations for detection improvements, hardening, and long-term mitigation. ·Participate in post-incident reviews, lessons learned, and playbook updates. ·Maintain readiness for 24x7 response through on-call rotation or surge support.

Requirements

Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity. Years Required/Preferred Experience 5 Required Advanced host based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity. 5 Required Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines. 5 Required Experience producing high quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows. 4 Required Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet level and log level data from but not limited to Corelight, NetWitness, and CRIBL pipelines. 3 Required Incident Commander experience 1 Required Experience supporting SLTT or critical infrastructure environments, including multi tenant IR operations and cross agency coordination. 5 Preferred Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE Telecommunication&CK. 5 Preferred Hands on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems. 4 Preferred Security Certifications Preferred (CISSP, CIH, Sec+)

Skills: Analysis Skills, Case Management, Documentation, File Systems, Forensic Science, Hunting, IR (Infrared), Incident Management, Incident Response, Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Leadership, Linux Operating System, Malware Analysis, Memory Hardware, Microsoft Windows Operating System, Network Monitoring, On Call, Reporting Skills, Security Information and Event Management (SIEM), Telecommunications, Telemetry

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

Videos

See all

Related articles

See all