> Markdown version of [/jobs/ext/3038639-senior-security-analyst-incident-response](https://www.wearedevelopers.com/jobs/ext/3038639-senior-security-analyst-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Analyst - Incident Response - **Company:** ACCRESCENT INVESTMENT GROUPS LLC - **Location:** Cranberry Township, PA, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Data Analysis, Network Analysis, Cyber Security, Linux, Digital Forensics, Intrusion Detection and Prevention, OSI Models, Linux Security Modules, Log Analysis, Network Protocols, Security Information and Event Management, TCP/IP, QRadar, Firewalls (Computer Science), Microsoft Sentinel, Windows Security, Servicenow - **Published:** September 23, 2026 - **Apply:** https://www.wayup.com/i-j-Senior-Security-Analyst-Incident-Response-Accrescent-Group-186809128082183/ ## About the Role We're seeking a Senior Security Analyst - Incident Response with hands-on experience in incident response, SOC operations, or a dedicated IR team. The role will focus on security incident investigation, detection engineering, log and network analysis, digital forensics, and development of response playbooks. The ideal candidate will have strong knowledge of information security concepts, Windows and Linux security, enterprise SIEM platforms, network protocols, and security tools including Microsoft Sentinel and Defender., + Candidates must be authorized to work in the U.S. without current or future sponsorship requirements. ## Description + Investigate and respond to security incidents within a SOC or Incident Response environment. + Perform Windows log analysis to identify suspicious activity and security events. + Create and maintain incident response playbooks. + Conduct digital forensic analysis during security investigations. + Perform data and network analysis to identify threats and indicators of compromise. + Develop and improve security detections and detection engineering processes. + Use enterprise SIEM platforms for security monitoring and investigation. + Analyze security events using Microsoft Sentinel and Microsoft Defender. + Apply knowledge of Windows and Linux operating systems and security. + Analyze network activity using the OSI Model, TCP/IP, and common network protocols. + Utilize ServiceNow for user-level requests and incident management. + Apply general firewall knowledge during security investigations. + Communicate security findings effectively through written and verbal communication. + Follow information security concepts, protocols, tools, industry best practices, and response strategies. Required Skills + Microsoft Sentinel + Microsoft Defender + Detection Engineering + Incident Response + SOC Operations + Windows Log Analysis + Playbook Creation + Digital Forensics + Information Security + Windows Security + Linux Security + OSI Model + TCP/IP + Network Protocols + Enterprise SIEM + QRadar or Sentinel + ServiceNow + Firewall Knowledge + Data Analysis + Network Analysis + Strong Verbal and Written Communication ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)