> Markdown version of [/jobs/ext/3267095-security-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/3267095-security-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Incident Response Analyst - **Company:** RemainCo Personnel Holdings, LLC - **Location:** Raleigh, NC, United States - **Experience:** Experienced - **Salary:** $95,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Data Security, Query Languages, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Domain Name System (DNS), Multi-Factor Authentication, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Log Analysis, OAuth, Windows PowerShell, Azure Active Directory, Anti-Phishing, Kusto Query Language, Security Information and Event Management, EndPointSecurity, Scripting, Data Classification, Office365, Mitre Att&ck, Firewalls (Computer Science), Microsoft Sentinel, Api Design, Splunk - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=101a133bf63134f8 ## About the Role * 5+ years in security operations or incident response, with at least 2 years leading investigations independently on high-severity incidents. * Deep, practical expertise in: + SIEM / detection engineering - query languages (KQL, SPL, or equivalent), correlation logic, detection tuning, log source onboarding (e.g., Microsoft Sentinel, Rapid7 InsightIDR, Splunk). + Identity and access - Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, offboarding controls. + Email security - BEC and phishing investigation, header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateway and API-based email security tools. + Endpoint - EDR investigation and response (Defender for Endpoint, CrowdStrike, or similar), persistence and lateral movement techniques. + Network security - firewall, proxy, VPN, and DNS log analysis; understanding of segmentation, C2 patterns, and data exfiltration indicators. * Fluency with MITRE ATT&CK and the ability to map observed activity to it. * Strong written communication: you can write an executive status update and a technical timeline in the same hour, and both are clear. * Judgment: you know when to contain immediately, when to watch, and when to escalate, and you can explain why. * Experience investigating incidents involving PHI/PII or other regulated data, including scoping data exposure and supporting breach risk assessments. Preferred * Healthcare industry experience and working knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy laws. * Cloud incident response experience (Azure, M365, AWS, or GCP) including SaaS/OAuth-based compromises. * Scripting for investigation and automation (PowerShell, Python, KQL). * Experience with SOAR platforms and automating response actions. * Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200. * Experience handling incidents involving third parties, vendors, or divested/carved-out business units with shared infrastructure. ## Description * Lead high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry; build and defend a timeline and root cause, not just a list of alerts. * Make and execute containment decisions: session revocation, credential resets, token invalidation, host isolation, mailbox rule removal, conditional access changes, and network blocks - weighing business impact against risk. * Run eradication and recovery, verify the adversary is actually out, and confirm persistence mechanisms (OAuth grants, inbox rules, MFA device registrations, scheduled tasks, service principals) are removed. * Perform log analysis and light forensics (memory, disk, M365/Entra audit logs, proxy/firewall/VPN logs) and preserve evidence to a standard that survives legal and regulatory review. PHI/PII and data security incidents * Lead investigations involving protected health information (PHI) and personally identifiable information (PII): unauthorized access, misdirected or exposed data, insider misuse, lost or compromised devices, and third-party or vendor exposures. * Determine what data was involved, who had access, for how long, and whether it was actually viewed or exfiltrated - and document that determination to a standard that supports HIPAA breach risk assessments and regulatory response. * Work directly with Privacy, Compliance, and Legal to feed incident facts into breach determination and notification decisions, and coordinate takedown or remediation of exposed data (public sites, file-sharing platforms, misconfigured storage, email). * Contribute to data protection controls (DLP, access reviews, data classification, secure file-transfer) based on what incidents reveal. Communication * Own incident communications: concise, accurate status updates to the CISO and security leadership, plain-language briefings to business owners, and clear handoffs to IT, Legal, Privacy, and HR. * Write incident reports and post-incident reviews that a non-technical executive can read and that an engineer can act on. * Coordinate with external parties as needed: MDR/MSSP, forensic retainers, cyber insurance, vendors, and third-party partners involved in an incident. Detection and improvement * Tune and build SIEM detections and response playbooks from what you learn in incidents; measure and reduce false positives, dwell time, and time to contain. * Threat hunt proactively using current intelligence, and convert findings into detections or hardening recommendations. * Identify control gaps (offboarding, SSO/MFA coverage, mail-flow protections, privileged access) and drive them to closure with the owning teams. Team leverage * Serve as escalation point and mentor for L1/L2 analysts; review their investigations and raise the quality bar. * Maintain and improve runbooks, severity definitions, and escalation criteria. * Participate in the on-call rotation and lead tabletop exercises. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)