> Markdown version of [/jobs/ext/2459181-principal-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/2459181-principal-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Incident Response Analyst - **Company:** Honeywell Aerospace - **Location:** Petersburg, VA, United States - **Experience:** Experienced - **Salary:** $162,000.0 - $203,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Linux, Digital Forensics, Python (Programming Language), Log Analysis, Windows PowerShell, Reverse Engineering, Security Information and Event Management, Office365, Malware, Kubernetes, Docker, Security Orchestration, Automation & Response - **Published:** August 1, 2026 - **Apply:** https://dejobs.org/x/x/2EA8B2454CC84C3986547F25812931BE/job/ ## About the Role Due to compliance with U.S. export control laws and regulations, candidate must be a U.S. Person, which is defined as, a U.S. citizen, a U.S. permanent resident, or have protected status in the U.S. under asylum or refugee status or have the ability to obtain an export authorization. YOU MUST HAVE Technical: Minimum of 3 plus years * At least 5 years: Incident Commanding / Response * At least 5 plus years in any of the following: o Network and Host Forensics o Operating Systems (Windows, Linux, macOS) o Automation (e.g., Python, Shell, PowerShell) o Log Analysis o Malware Analysis o Presentations to Executive Leadership o Technical Training / Mentoring o Bachelor's Degree * Professional (2 Plus Years): o Presentations to Executive Leadership o Technical Training/Mentoring * Education: o Bachelor's Degree WE VALUE * Experience with SIEM, SOAR, and EDR Solutions * Cloud & Container Security (Azure, AWS, O365, Docker, Kubernetes) * Reverse Engineering Malware * Strong Critical Thinker & Problem Solver ## Description As a Principal Incident Response Analyst at Honeywell Aerospace, you will be instrumental in conducting detailed analysis and providing insights on cybersecurity data. Your role will focus on Digital Forensics and Incident Response (DFIR) as an Incident Commander and lead incidents, where you'll engage in triage activities to identify potential threats and vulnerabilities within our systems. You will ensure the implementation of effective security measures to protect critical assets and information across various industries. Cybersecurity Incident Response Team (CIRT) Are you passionate about leading global Cybersecurity innovation and change? Do you thrive in environments that encourage critical thinking, creativity, and challenging the status quo?, We are looking for a Technical Analyst experienced in DFIR and triage processes, capable of conducting thorough incident investigations, working closely with senior leadership, supporting the development of junior team members, and contributing to the organization's cybersecurity strategies and initiatives, You will report directly to our Sr. Director of Cyber Security, and work out of our Phoenix, AZ location or Remote., * Mentor junior cyber security analysts * Build and maintain processes and procedures. * Drive complex cybersecurity incidents to successful conclusion. * Collaborate with global team members. * Lead large-scale technical projects. * Develop Root Cause and Corrective Action Reports. * Serve as part of a Global On-Call Rotation. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus)