Lead Incident Response Analyst - Detection and Response

Merck Sharp & Dohme LLC
Montpelier, VT, United States
3 days ago
Apply on www.financialjobbank.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$117,000.0 - $184,200.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Data Analysis Audit Trail Microsoft Azure Cyber Security Information Leak Prevention Digital Forensics Identity and Access Management Intrusion Detection and Prevention Log Analysis Network Forensics Security Information and Event Management
+6 more
Mitre Att&ck Malware Cyber Threat Analysis Information Technology Cloudwatch Cyber Warfare

Job description

The Lead Incident Response Analyst is responsible for the day-to-day operations of the team that enables the CFC to respond to an emerging security incident with a coordinated response in the first 0-24hours. The team consist of Incident Response Analysts in the US Tech Center. This position directly supports a 24x7x365 support staff and candidates should be opened to supporting incident response functions outside of core hours. This position will require flexibility to work Incidents to containment and collaborate across global technology centers for long-term investigations., * Incident Response & InvestigationConduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency-only on-call availability is required for high-severity incidents.

  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and Various security tooling.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non-technical stakeholders.
  • Coordinate appropriate response activities across teams or directly with partners.

Managerial Responsibilities

  • Lead the initial response for the Cyber Fusion Center for high impact cybersecurity events.
  • Develop, mentor, and lead the teams and individual members.
  • Oversee the day-to-day operations of the team.
  • Coordinate incident transfer between geographical locations and shifts.
  • Provide data analysis of incidents base on prevalent correlations and data.
  • Evaluate events, escalations, and incidents to determine remediation and resolution actions.
  • Update playbooks to improve processes and information sharing across teams.

Requirements

  • Bachelors in Computer Science, Cybersecurity or equivalent work experience
  • 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload-level events) and taking containment measures in cloud environments.
  • Excellent written and verbal communication skills, including the ability to produce concise, high-clarity investigative findings., * Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.
  • Prior experience conducting in depth log analysis and correlating events across an enterprise.
  • Exposure to SIEM/SOAR platforms from an investigative perspective.
  • Incident response or forensics-related certifications (e.g., GCIH, GCFA, GNFA, GCFE)., Adaptability, Adaptability, Analytical Thinking, Cybersecurity, Cyber Threat Analysis, Cyber Threat Hunting, Cyber Threat Intelligence, Data Loss Prevention (DLP), Detail-Oriented, Digital Forensics, Endpoint Management, Event Monitoring, Event Support, Forensic Analysis, Governance Management, Incident/Breach Triage and Containment, Incident Analysis, Incident Management, Incident Response, Incident Response Management, Insider Threat Mitigation, Log Analysis, Malware Analysis, Network Forensics, Offensive Cyber Operations {+ 17 more}

Benefits & conditions

We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts (https://www.msdprivacy.com/us/en/CCPA-notice/)

The salary range for this role is

$117,000.00 - $184,200.00

About the company

Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.financialjobbank.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

3:13 min

Navigating the GenAI observability dashboard in Amazon CloudWatch

Yasemin Aktürk Yasemin Aktürk · Europe 2026 Virtual

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

Videos

See all

Related articles

See all