Senior Incident Response Analyst

Rutgers University
New Brunswick, NJ, United States
2 days ago
Apply on jobs.rutgers.edu
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Software Applications Software System Penetration Testing Botnet Software as a Service Cyber Security Linux Digital Forensics Domain Name System (DNS) Perl (Programming Language) Intrusion Detection and Prevention Intrusion Detection Systems
+21 more
Python (Programming Language) NetFlow Routing Packet Analyzer Network Protocols Windows PowerShell Regular Expressions Phishing Security Software Security Information and Event Management Syslog Scripting Computer Networking Systems Mitre Att&ck Malware Cyber Threat Analysis Firewalls (Computer Science) Computer Equipment People Soft Cybercrime Vulnerability Analysis

Job description

Among the key duties of this position are the following:

  • Performs daily operations of the incident detection and response program, which includes finding evidence of threats or suspicious behavior and leveraging data to improve controls and processes.
  • Monitors information security incidents throughout Rutgers’ computing environment.
  • Serves as an escalation point for Incident Response Analysts.
  • Provides expert-level analytic, investigative and forensic support of complex security incidents to detect and remediate security threats on networks, workstations, servers, and other connected devices.
  • Provides expert level advice and services to business units throughout the University while participating in all phases of Rutgers’ Integrated Incident Response Program (Prepare, Detect & Analyze, Contain, Eradicate, Recovery, Report, Remediate)., Working Hours Standard Hours 37.50 Daily Work Shift Work Arrangement Consistent with the current application of Rutgers Policy 60.3.22 or the applicable provisions of relevant collective negotiations agreements, this position may be eligible for a hybrid work arrangement. Flexible work arrangements are not permanent, subject to change or discontinuation, and contingent on the employee receiving approval in the FlexWork@RU Application System. Union Description Admin Assembly (MPSC) Payroll Designation PeopleSoft Seniority Unit Terms of Appointment Staff - 12 month Position Pension Eligibility ABP

Requirements

  • Bachelor’s degree or equivalent education and experience plus five years relevant experience in specialty area
  • 5+ years of information security experience; vulnerability scanning, penetration testing and/or security operations
  • 5+ years of experience working in an enterprise technical environment, preferably in a customer-service based organization

Certifications/Licenses Required Knowledge, Skills, and Abilities

  • Knowledge in a wide array of cybersecurity tools and their capabilities as they pertain to the detection and mitigation of Cyber Threats (SIEM, EDR, NGFW, DLP, IPS/IDS, etc.)
  • Knowledge of industry standard cybersecurity frameworks (Mitre ATT&CK, NIST Incident Response, etc.)
  • Understanding of complex enterprise networks to include routing, switching, firewalls and common networking protocols (HTTP, DNS, SMB, etc.)
  • Experience with Regex and at least one common scripting language (PERL, Python, PowerShell)
  • Experience with an enterprise SIEM platform
  • Excellent verbal and written communication skills
  • Ability to communicate technical problems succinctly and accurately
  • Ability to handle multiple, shifting priorities and a large volume of technical problem resolution
  • Ability to apply and document new technical knowledge and procedures
  • Ability to work well with peers and junior staff in a team oriented, cooperative spirit, * Degree in a related field such as Information Security.
  • 3+ years of experience in incident response, threat hunting, SOC operations, digital forensics, or detection engineering.
  • Relevant certifications such as GCFA, GCIH (or other SANS certifications), CISSP, CySA+
  • Experience as a key member of a cybersecurity team (SOC, Incident Response, Threat Intel, Malware Analysis, Live Forensics, IDS/IPS Analysis)
  • Experience investigating identity-centric attacks, cloud compromise, phishing, business email compromise, and SaaS-based incidents.
  • Knowledge of TTPs related to cyber-crime, malware, botnets, social engineering, APTs and other threats.
  • Experience developing, tuning, and maintaining detection content including SIEM correlation rules, behavioral analytics, dashboards, and automation workflows.
  • Expertise in network and host-based analysis and investigation

Equipment Utilized

  • Vulnerability analysis/Penetration testing
  • Packet capture and Netflow
  • Firewalls/IPS/IDS/EDR
  • Syslog/SIEM/Dashboards & Alerting/SOAR
  • Threat hunting/Malware Analysis
  • Windows/Linux/macOS

Physical Demands and Work Environment

  • Must be able to lift up to 50 pounds for the purpose of moving computer equipment.

Benefits & conditions

Grade 07 Salary Details Minimum Salary 108147.000 Mid Range Salary 136809.000 Maximum Salary 165471.000, Rutgers provides a comprehensive benefits package to eligible employees. The specific benefits vary based on the position and may include:

  • Medical, prescription drug, and dental coverage
  • Paid vacation, holidays, and various leave programs
  • Competitive retirement benefits, including defined contribution plans and voluntary tax-deferred savings options
  • Employee and dependent educational benefits (when applicable)
  • Life insurance coverage
  • Employee discount programs

About the company

Rutgers, The State University of New Jersey, is a leading national research university and the State of New Jersey’s preeminent, comprehensive public institution of higher education. As one of the largest employers in the State of New Jersey, Rutgers University is committed not only to the students and the State that we serve, but also to the faculty and staff who work on our campuses.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.rutgers.edu
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:32 min

Dependency risks in widespread NPM supply chain attacks

Chris Heilmann +2 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:30 min

Discovering and instrumenting services using systemd process enumeration

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

Videos

See all

Related articles

See all