> Markdown version of [/jobs/ext/3595077-cyber-security-analyst-incident-response-remote](https://www.wearedevelopers.com/jobs/ext/3595077-cyber-security-analyst-incident-response-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - Incident Response (Remote) - **Company:** First Citizens - **Location:** Scottsdale, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $140,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Regular Expressions, Security Information and Event Management, Google Cloud, Mitre Att&ck, Malware, Cybercrime - **Published:** October 6, 2026 - **Apply:** https://www.juju.com/job/21_01a0dd5c-6f05-76e1-83cf-afe00b046bfc ## About the Role As a Senior Incident Response Analyst, you'll be a member of the bank's Cyber Incident Response team. We are looking for an experienced senior level analyst with proven skillsets to detect and respond to threats in the environment, interact with business stakeholders and work to restore operations. This is a technical role and will support the Threat Hunting, Intelligence, and Monitoring functions with content creation, threat analysis, detection recommendations, and colleague mentoring. Seeking a candidate with strong communication skills to complement their technical skillset providing the ability to distill down complex issues for broader understanding expedited incident management., Minimum Required Education and Experience: Bachelor's Degree and 8 years' experience. OR High School Diploma or GED/Equivalent and 12 years' experience in Information Security. Preferred Qualifications: * Experience with all aspects of Incident response including stakeholder management. * 2+ years of Threat Hunting experience. * Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus. * Experience analyzing/dispositioning and escalating security events (systems, application, network, authentication email events) * Experience translating threat actor techniques to building mitigations across a variety of security technologies. This could take the form of Yara, Sigma or Regular Expressions. * Ability to define security requirements and drive project deliverables. * Ability to keep track of multiple incidents and ensure responses are provided in a timely fashion. * Experience responding to cloud-related incidents in Azure, AWS and Google cloud. * Cloud administrative experience preferred. * Cyber Incident Response experience - 3+ years required in which your primary job was an Incident Response role. ## Description * Incident Analyst/handler -investigate SIEM/SOAR events as necessary; bring experience in malware analysis, network/endpoint security to respond to and contain incidents. * Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and remediation from a technical perspective. Liaise with technical and business stakeholders. * Incident Management - Ensures Information Security incidents are properly detected, documented, investigated, and resolved. * Content Development - Support the creation of countermeasures and mitigations in response to an incident. * Threat Hunting - Support the operational driven inputs (eg. on the heels of an incident or event) into threat hunting and help build countermeasures/mitigations to address commodity and targeted threats. Also build a capability to track evolving threat actor techniques. * Post Incident Review - Provide recommendations to improve communication, processes, procedures, and mitigation options based on high severity incidents.