> Markdown version of [/jobs/ext/3579115-senior-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/3579115-senior-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Incident Response Analyst - **Company:** Western Governors University - **Location:** Salt Lake City, UT, United States - **Experience:** Expert - **Salary:** $130,900.0 - $196,300.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Bash Shell, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Information Technology, Multiplatform - **Published:** October 4, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87282465/1 ## About the Role If you're passionate about building a better future for individuals, communities, and our country-and you're committed to working hard to play your part in building that future-consider WGU as the next step in your career., * 5+ years in security operations (10+ years earns bonus consideration) * Hands-on SIEM expertise, including content development, not just querying * Experience with CrowdStrike or Carbon Black (EDR), Mimecast, and vulnerability management tools * Working knowledge of the MITRE ATT&CK framework and cloud security principles * Python or Bash scripting for automation and workflow improvement * Strong communicator who can brief leadership and work across non-security teams * Bachelor's degree in IT Security, Computer Science, or related field, or equivalent experience Bonus Points * CISSP, GIAC, CCSP, or AWS Security Specialty * SOAR experience * Cloud-native security tooling Experience in Lieu of Education Equivalent relevant experience may substitute for educational requirements at the hiring manager's discretion. ## Description Our Security Operations Center (SOC) team is responsible for a broad range of security operations, including monitoring, incident response, risk assessment, policy development, audit and compliance, technical operations, and collaboration across departments. This team plays a critical role in safeguarding WGU's systems and data while driving innovation and collaboration across the organization. Security incidents demand more than monitoring. They require fast investigation, sound technical judgment, effective coordination, and the ability to drive remediation through closure. As a Senior Incident Response Analyst, you will help protect WGU's systems and data by leading advanced incident response and threat detection activities across multiple platforms and environments. You'll investigate security events, strengthen detection capabilities, hunt for emerging threats, and partner with engineering and IT teams to improve WGU's overall security posture. What You'll Do * Lead security incident investigations from initial triage through remediation and closure. * Perform advanced threat detection, analysis, and response across multi-platform environments. * Investigate suspicious activity using SIEM, EDR, network, and other security tools. * Develop and tune SIEM alerts, detection rules, and dashboards to improve incident detection and response. * Conduct threat hunting and research emerging threats to identify and address potential risks. * Partner with engineering and IT teams to drive incident remediation, harden configurations, and strengthen security controls. * Support vulnerability management, security audits, compliance initiatives, and risk assessments. ## Related Videos - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [The Dark Corners of Kotlin Multiplatform](https://www.wearedevelopers.com/videos/100143-the-dark-corners-of-kotlin-multiplatform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your AI Agent is just a while loop with an API call. Let me prove it](https://www.wearedevelopers.com/videos/1988-your-ai-agent-is-just-a-while-loop-with-an-api-call-let-me-prove-it) - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)