> Markdown version of [/jobs/ext/2625454-ibm-s-cyber-security-incident-response-team](https://www.wearedevelopers.com/jobs/ext/2625454-ibm-s-cyber-security-incident-response-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IBM's Cyber Security Incident Response Team - **Company:** IBM - **Location:** Austin, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Proxy Servers, Macintosh Computers, IBM System I, Microsoft Azure, Cyber Security, Computer Forensics, Linux, Digital Forensics, Network Topologies, IBM Cloud Computing, IBM Systems Network Architecture, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Open Source Technology, Windows PowerShell, Security Information and Event Management, EndPointSecurity, Forensic Toolkit, Scripting, Cloud Platform System, Software Security, Malware, Firewalls (Computer Science), Azure Security Center, Encase - **Published:** August 15, 2026 - **Apply:** https://www.dice.com/job-detail/e75037e6-68d1-4780-a8fd-dba2871f8af6 ## About the Role Associate's Degree/College Diploma Preferred education Bachelor's Degree Required technical and professional expertise - 3-5 years of experience in Incident Response, SOC and/or Digital Forensics in a global corporate environment - Key Technical Skills * Strong digital forensics expertise across endpoints, systems, and network artifacts; experience with industry-standard tools (e.g., EnCase, FTK, Autopsy) * Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness * Strong investigative and analytical skills, including correlation of logs, endpoint, and network data to determine root cause and reconstruct timelines * Experience operating within incident response workflows and using EDR, SIEM, and detection platforms in active incident environments * Understanding of attacker TTPs, with exposure to malware analysis or memory forensics preferred * Analysis using EDR tooling such as Crowdstrike or Microsoft Defender for Endpoint (MDE) * Basic scripting/automation skills (e.g., Python, PowerShell) are a plus - Strong understanding of Windows, Mac, and Linux operating systems - Solid working knowledge of networking topology, technology and tools, such as firewalls, proxies, IDS/IPS, EDR Event analysis and correlation Excellent technical writing and presentation skills - The ability to work independently and effectively, as well as in a group setting required. Preferred technical and professional experience - Demonstrated computer forensic investigations experience - Demonstrated knowledge of commercial and open-source forensic tools, such as X-Ways, Axiom, Autopsy, ELK, SIFT, Plaso, etc - Familiarity with enterprise cybersecurity tooling (EDR, SIEM, forensic platforms) Scripting & Automation (Nice to Have) - Certifications such as: GCFA, CHFI, GCIH (or equivalent experience, nice to have) - Demonstrated knowledge of analysis with EDR tooling, such as Crowdstrike or Microsoft Defender for Endpoint (MDE) - Knowledge of incident response and analysis in cloud environments, such as IBM Cloud, AWS, or Azure - Ability to successfully lead and facilitate information gathering meetings - Experience managing small and large scale cyber security incidents, Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background. Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do. Are you ready to be an IBMer?, IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship. ## Description The Office of the CISO has the responsibility to safeguard not only IBM systems but those of clients we support around the globe. The IBM CISO office is comprised of teams that cover all aspects of security - from Vulnerabilty Management, Threat Detection, Security Operations, Product Security, Mail Security, System Inventory, Endpoint Detection, as well as Computer Security Incidence Response. CSIRT is responsible for maintaining and managing the IBM internal global incident response process for cybersecurity and data privacy cases across IBM. We are looking for individuals who bring both technical depth and professional discipline-those who can dig into the evidence, uncover the story behind an incident, and communicate it clearly to drive action. Your role and responsibilities IBM's Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region. In this role, you will work at the intersection of incident response, digital forensics, and threat analysis, partnering closely with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation. This is a hands-on analytical role requiring the ability to translate complex technical findings into actionable insights, enabling both operational response and executive decision-making. The successful candidate will demonstrate strong technical depth, investigative rigor, and the ability to operate effectively in high-pressure environments. Key Responsibilities: -Conduct forensic investigations on endpoint, network, and cloud environments -Collect, preserve, and analyze digital evidence in accordance with established standards -Support incident response activities, including triage, containment, eradication, and recovery -Correlate forensic evidence with threat intelligence and detection signals -Ability to analyze disk images, logs, and recovered data -Reconstruct attack timelines and identify root cause and impact -Document findings and produce clear, defensible reports for technical and non-technical stakeholders -Collaborate across CSIRT, SOC, Legal, and Compliance teams as needed -Contribute to post-incident reviews and continuous improvement of response capabilities ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Welcome to Switzerland](https://www.wearedevelopers.com/magazine/4-welcome-to-switzerland) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)