> Markdown version of [/jobs/ext/2941580-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/2941580-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Analyst - **Company:** Corteva - **Location:** Johnston, IA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Authentication Protocols, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Information Leak Prevention, Digital Forensics, Monitoring of Systems, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Network Architecture, Windows PowerShell, Security Information and Event Management, Data Logging, Scripting, Google Cloud, Enterprise Software Applications, Cloud Platform System, Mitre Att&ck, SentinelOne Expertise - **Published:** September 16, 2026 - **Apply:** https://dejobs.org/x/x/31B3C5848EE7420FBC8DF2276F4D741D/job/ ## About the Role * 6+ years of experience in cybersecurity or Bachelor in an IT/Cybersecurity field with 3 years of related experience within security operations, incident response, digital forensics, threat detection, or a related field. * Relevant certifications such as GCIH, GCFA, GCIH, GCIA, Security+, CySA+, CISSP, or equivalent experience. * Hands-on experience investigating and responding to security incidents. * Strong understanding of common attack techniques, tactics, and procedures; familiarity with MITRE ATT&CK and common threat actor behaviors. * Understanding of identity providers, authentication protocols, and privileged access management; experience working with SIEM, EDR/XDR, identity, network, cloud, or security monitoring technologies. * Strong analytical and investigative skills with an ability to connect seemingly unrelated pieces of evidence; understanding of user and entity behavior analytics (UEBA). * Experience analyzing logs and security telemetry to determine the scope and impact of an incident; experience with scripting or automation using Python, PowerShell, or similar languages. * Ability to prioritize multiple investigations and operate effectively during high-severity incidents. * A methodical approach to evidence collection, documentation, and investigation. * Experience with investigations in one or more of the areas of data loss prevention, data filtration, compromised account, identity, and cloud security is preferred. * Experience with EDR/XDR platforms (CrowdStrike, Microsoft Defender, SentinelOne) and cloud platforms (AWS, Azure, GCP) preferred. * Strong written and verbal communication skills. * Results driven; ability to successfully navigate challenging opportunities to meet objectives and deadlines. * Strong attention to detail and ability to quickly adapt to changing needs. * Ability to solve complex problems with minimal guidance. * Effective collaborator; encourages novel approaches to solving problems. ## Description As an Incident Response Analyst , you will play a key role in Vylor's detection and response capabilities. You will investigate security alerts and incidents, perform threat analysis, coordinate containment and remediation activities, and help strengthen our overall security posture. The Incident Response Analyst is a trusted investigator and responder within the Vylor security team who helps the organization quickly distinguish real threats from noise and turn lessons learned into stronger security controls and detections. The ideal candidate is naturally curious, analytical, and comfortable operating in a fast-paced environment where every investigation may present a new challenge. Experience with Insider Threat detection, response, and investigations is highly valued. Candidates with a background identifying and investigating malicious or negligent insider activity, unusual user behavior, data exfiltration, compromised accounts, or inappropriate access to sensitive information are strongly encouraged to apply. Primary Responsibilities - How will you help us Grow! * Monitor, triage, investigate, and respond to cybersecurity incidents and security alerts. * Conduct investigations across endpoints, identity systems, cloud environments, network infrastructure, SaaS applications, and other enterprise systems. * Perform incident scoping, root-cause analysis, and impact assessments. * Identify indicators of compromise (IOCs), attacker techniques, and suspicious patterns of activity. * Lead or support containment, eradication, and recovery activities. * Analyze logs, endpoint telemetry, authentication activity, network traffic, and other forensic evidence. * Investigate potentially malicious, compromised, or anomalous user activity. * Support insider threat investigations, including suspected data exfiltration, unauthorized access, policy violations, credential misuse, and other suspicious employee or contractor activity. * Collaborate with IT, Engineering, HR, Legal, Compliance, and other stakeholders when incidents require cross-functional response. * Document investigations, findings, timelines, evidence, and remediation actions clearly and accurately. * Develop and improve incident response playbooks, procedures, and investigative processes. * Identify opportunities to improve security detections, alerting, logging, and response automation. * Participate in incident response exercises and post-incident reviews. * Stay current on emerging threats, attacker techniques, vulnerabilities, and security trends. * Lead or support other cyber threat and incident activities, as assigned. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)