Incident Response Analyst

Trend Micro Inc.
Irving, TX, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Shift work
Job source

Tech stack

Microsoft Windows Artificial Intelligence Cyber Security Computer Networks Linux Event Logging Forensics Tools (Digital Forensics Software) Log Analysis NetFlow Network Forensics Security Information and Event Management Wireshark
+6 more
Multi-Agent Systems Mitre Att&ck Malware Cyber Threat Analysis Information Technology Vulnerability Analysis

Job description

In this role, you’re not just responding to breaches. You’re the person customers rely on when it matters most. You’ll build trusted relationships with enterprise customers, translate complex threat data into intelligence that drives decisions, and lead organisations through their most critical security moments with clarity and control. Working alongside AI systems that accelerate your investigative capabilities, you’ll compress detection times from hours to minutes and deliver insights that turn incidents into lasting security improvements. Every forensic analysis you conduct, every malware sample you dissect, and every recommendation you make leaves customers measurably harder to compromise than before you arrived.

As an Incident Response Analyst, you’ll investigate sophisticated security breaches, lead containment under pressure and become the person enterprise customers trust when everything is on the line. You’ll be the critical link between TrendAI Vision One and customer recovery, operating across global threat operations where seconds matter, relationships are everything and AI amplifies what you’re already capable of.

You will also play an active role in shaping how AI transforms incident response. That means contributing to automation initiatives, stress-testing AI-driven workflows and helping define how our analysts and AI systems work together to respond faster, investigate deeper and protect more effectively at scale. The analysts who join us now are not just using the tools. They are helping build them.

Core Responsibilities

  • Forensic Investigation: Conduct root cause analysis of security breaches; determine attack vectors, scope and business impact with precision and accountability.
  • Incident Response: Lead containment and threat eradication using TrendAI Vision One , coordinating across internal teams and customer stakeholders from first alert to resolution.
  • Threat Analysis & Detection: Analyze malware and threat components; develop and refine detection rules; generate threat intelligence and IoCs.
  • Customer Reporting: Create executive-ready incident reports; deliver briefings to stakeholders; recommend security improvements.
  • Proactive Threat Operations: Hunt for advanced threat indicators across customer networks; improve detection logic and fidelity.
  • AI Orchestration: Contribute to automation and AI initiatives that compress response times, reduce analyst burden, and sharpen the overall quality of MDR delivery.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or related field
  • 3+ years in security operations with demonstrated expertise in:
  • Incident response and forensics;
  • Malware analysis and threat investigation;
  • SOC operations or security monitoring.

Technical Competencies

  • AI in Practice: Familiarity with how AI and automation are reshaping incident response workflows, from alert triage to forensic analysis. Curiosity about where it’s going matters as much as where you are today.
  • OS & Network Forensics: Advanced Windows and Linux forensics (registry, event logs, artifacts, filesystem analysis).
  • Forensics Tools: SIFT Workstation, WinPMEM, dd/dclfdd, Autopsy, Volatility Framework, FTK Imagerm Wireshark, Bro/SiLK, Netflow, tcpdump - or similar OS/Network Tools.
  • Log Analysis & Correlation: SIEM platforms, syslog analysis, event correlation procedures
  • Malware analysis: Static and dynamic analysis techniques.
  • Threat Intelligence: Understand threat actor TTPs and MITRE ATT&CK framework alignment; contribute to organizational threat intelligence. Leverage threat intelligence platforms.
  • TrendAI familiarity: Working knowledge of the Vision One platform or equivalent threat intelligence/XDR platforms.

Professional Certifications Preferred

  • GCIH (GIAC Certified Incident Handler).
  • GCFA / GCFE (GIAC Certified Forensic Analyst / Examiner).
  • CISSP or OSCP., * Strong written and verbal communication, ability to translate complex forensic findings for technical and executive audiences.
  • Self-directed learner with aptitude for rapidly mastering new tools and threat landscapes.
  • Comfortable working under pressure; thrives in fast-paced, high-stakes environments.
  • Ability to work 24/7 rotating shifts, including nights, weekends, and holidays.
  • Willing to travel when required.
  • Strong analytical and problem-solving skills with ability to work effectively in a global team environment.
  • Comfortable speaking to customer via e-mail, chat and phone.

Benefits & conditions

Pet insurance, Parental leave, Health insurance, 401(k) matching, Paid time off, Adoption assistance, Wellness program, You’re important to us. What matters to you, matters to us too. Trend Micro provides benefit options for you and your family. Here some of the top-rated benefits that employees enjoy today:

  • Comprehensive health benefits and paid time off package
  • Pre-partum, maternity, parental, medical leave and adoption assistance
  • Mental Health Wellness Program & Annual Wellness Incentive
  • 401(k) with company match
  • Pet Insurance
  • Collaborative and innovative culture

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 ¡ LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ WWC 2025

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn ¡ LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil ¡ LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade ¡ LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph ¡ LIVE

Videos

See all

Related articles

See all