> Markdown version of [/jobs/ext/2937507-security-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/2937507-security-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Incident Response Analyst - **Company:** Match Inc - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software as a Service, Cloud Computing, Cyber Security, Distributed Systems, Domain Name System (DNS), Identity and Access Management, Python (Programming Language), Log Analysis, Phishing, Security Information and Event Management, Scripting, Cloud Platform System, Malware - **Published:** September 16, 2026 - **Apply:** https://www.jobmonkeyjobs.com/career/28021386/Security-Incident-Response-Analyst-Any-Vancouver-7430 ## About the Role * 5+ years of experience in Incident Response, DFIR, or Security Operations * Experience leading significant security investigations * Strong familiarity with cloud environments (AWS and/or GCP) * Hands-on experience with SIEM, EDR, and log analysis * Solid understanding of identity systems and distributed architectures * Ability to stay composed and structured during high-pressure situations * Clear written and verbal communication skills Nice to Have * Experience in large-scale consumer or SaaS environments * Experience working across global teams * Familiarity with privacy-related incident handling (e.g., GDPR) * Scripting or automation experience (Python, etc.) ## Description security services across all Match Group brands. The Monitoring, Incident Response & SOC team is responsible for real-time threat detection, investigation, and response across the full portfolio - operating 24/7 to ensure security alerts are effectively triaged and responded to, minimizing the impact of potential threats., We're looking for a senior individual contributor to join our Detection & Response team as a Security Incident Response Analyst. In this role, you'll serve as a senior-level investigator responsible for detecting, analyzing, and responding to advanced security threats across on-prem and cloud infrastructure in a multi-vendor environment. You'll lead investigations spanning phishing, malware, insider threats, and other complex security incidents - driving them from initial detection through containment, eradication, and recovery. What You'll Do * Lead end-to-end investigations into phishing, malware, insider threats, and other advanced security incidents * Triage and analyze security alerts, distinguishing true threats from noise, and prioritize response based on risk and business impact. * Perform technical malware analysis, including static and dynamic examination of suspicious files, to determine behavior, capability, and intent. * Conduct host and network-based analysis - analyzing system logs, processes, registry/configuration artifacts, memory, traffic patterns, DNS activity, and connection logs - to reconstruct attacker activity and identify persistence, command-and-control, lateral movement, and data exfiltration. * Investigate cloud-native incidents by analyzing audit logs, IAM and access activity, and network flow data to detect unauthorized access, privilege misuse, and malicious file activities across cloud environments. * Drive incidents through containment, eradication, and recovery, coordinating with cross-functional teams as needed. * Develop and refine detection logic, playbooks, and response procedures to improve the team's ability to identify and act on emerging threats. * Act as an escalation point for the most technically complex cases, mentoring junior analysts. * Document findings and communicate clearly with both technical and non-technical stakeholders, including post-incident reports and executive summaries., * We operate global consumer platforms that handle sensitive user data. When incidents happen, the way we respond matters. * This role plays a key part in containing impact, protecting user trust, and improving our overall response maturity. #LI-CB1 Why Match Group? Our mission is simple - to help people find love and happiness! We love our employees too and understand the importance of all life's milestones. Here are some of the benefits we are proud to offer: * Generous vacation, flex days, professional development days * RRSP matching, and employee stock purchase plan * Professional development budget and unlimited access to Udemy from day one * Match Group mentorship program * Parental leave top up and fertility preservation benefits * Extended health & dental benefits from day one * Corporate ClassPass membership and other wellness benefits ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) ## Related Articles - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)