> Markdown version of [/jobs/ext/276964-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/276964-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Analyst - **Company:** Trend Micro Inc. - **Location:** Irving, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Cyber Security, Computer Networks, Linux, Event Logging, Forensics Tools (Digital Forensics Software), Log Analysis, NetFlow, Network Forensics, Security Information and Event Management, Wireshark, Multi-Agent Systems, Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Vulnerability Analysis - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=42dc610e6272ba40 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field * 3+ years in security operations with demonstrated expertise in: * Incident response and forensics; * Malware analysis and threat investigation; * SOC operations or security monitoring. Technical Competencies * AI in Practice: Familiarity with how AI and automation are reshaping incident response workflows, from alert triage to forensic analysis. Curiosity about where it's going matters as much as where you are today. * OS & Network Forensics: Advanced Windows and Linux forensics (registry, event logs, artifacts, filesystem analysis). * Forensics Tools: SIFT Workstation, WinPMEM, dd/dclfdd, Autopsy, Volatility Framework, FTK Imagerm Wireshark, Bro/SiLK, Netflow, tcpdump - or similar OS/Network Tools. * Log Analysis & Correlation: SIEM platforms, syslog analysis, event correlation procedures * Malware analysis: Static and dynamic analysis techniques. * Threat Intelligence: Understand threat actor TTPs and MITRE ATT&CK framework alignment; contribute to organizational threat intelligence. Leverage threat intelligence platforms. * TrendAI familiarity: Working knowledge of the Vision One platform or equivalent threat intelligence/XDR platforms. Professional Certifications Preferred * GCIH (GIAC Certified Incident Handler). * GCFA / GCFE (GIAC Certified Forensic Analyst / Examiner). * CISSP or OSCP., * Strong written and verbal communication, ability to translate complex forensic findings for technical and executive audiences. * Self-directed learner with aptitude for rapidly mastering new tools and threat landscapes. * Comfortable working under pressure; thrives in fast-paced, high-stakes environments. * Ability to work 24/7 rotating shifts, including nights, weekends, and holidays. * Willing to travel when required. * Strong analytical and problem-solving skills with ability to work effectively in a global team environment. * Comfortable speaking to customer via e-mail, chat and phone. ## Description In this role, you're not just responding to breaches. You're the person customers rely on when it matters most. You'll build trusted relationships with enterprise customers, translate complex threat data into intelligence that drives decisions, and lead organisations through their most critical security moments with clarity and control. Working alongside AI systems that accelerate your investigative capabilities, you'll compress detection times from hours to minutes and deliver insights that turn incidents into lasting security improvements. Every forensic analysis you conduct, every malware sample you dissect, and every recommendation you make leaves customers measurably harder to compromise than before you arrived. As an Incident Response Analyst, you'll investigate sophisticated security breaches, lead containment under pressure and become the person enterprise customers trust when everything is on the line. You'll be the critical link between TrendAI Vision One and customer recovery, operating across global threat operations where seconds matter, relationships are everything and AI amplifies what you're already capable of. You will also play an active role in shaping how AI transforms incident response. That means contributing to automation initiatives, stress-testing AI-driven workflows and helping define how our analysts and AI systems work together to respond faster, investigate deeper and protect more effectively at scale. The analysts who join us now are not just using the tools. They are helping build them. Core Responsibilities * Forensic Investigation: Conduct root cause analysis of security breaches; determine attack vectors, scope and business impact with precision and accountability. * Incident Response: Lead containment and threat eradication using TrendAI Vision One , coordinating across internal teams and customer stakeholders from first alert to resolution. * Threat Analysis & Detection: Analyze malware and threat components; develop and refine detection rules; generate threat intelligence and IoCs. * Customer Reporting: Create executive-ready incident reports; deliver briefings to stakeholders; recommend security improvements. * Proactive Threat Operations: Hunt for advanced threat indicators across customer networks; improve detection logic and fidelity. * AI Orchestration: Contribute to automation and AI initiatives that compress response times, reduce analyst burden, and sharpen the overall quality of MDR delivery. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)