> Markdown version of [/jobs/ext/596928-cybersecurity-incident-response-analyst-ii](https://www.wearedevelopers.com/jobs/ext/596928-cybersecurity-incident-response-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Incident Response Analyst II - **Company:** Avnet, Inc. - **Location:** Chandler, AZ, United States - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Query Languages, Security Information and Event Management, Cloud Platform System, Mitre Att&ck, Falcon Platform, Cybercrime, Security Orchestration, Automation & Response - **Published:** June 20, 2026 - **Apply:** https://www.juju.com/job/00000000g9iz0j ## About the Role + **Investigation Depth:** Demonstrates the ability to perform full investigations, including scoping, timeline reconstruction, root cause identification, and impact assessment. + **Tool Proficiency:** Experience operating within EDR and SIEM platforms and using multiple telemetry sources to conduct investigations. + **CrowdStrike Experience:** Hands-on experience with the CrowdStrike Falcon platform (EDR, NG-SIEM, Fusion, or related modules) and familiarity with Falcon Query Language or LogScale is strongly preferred. + **Threat Hunting Capability:** Experience performing proactive threat hunting and identifying activity outside of alert-driven workflows. + **Multi-Source Correlation:** Ability to correlate activity across endpoint, identity, network, and cloud systems without relying on a single tool. + **Framework Awareness:** Familiarity with MITRE ATT&CK and structured incident response practices aligned to frameworks such as NIST 800-61 Rev. 3. + **Process Improvement Mindset:** Experience improving detections, playbooks, or response workflows based on investigation findings and recurring patterns. + **Incident Ownership:** Demonstrates the ability to take ownership during incidents and contribute to coordination or leadership of response activities. + **Communication:** Strong written and verbal communication skills, including the ability to clearly explain what is happening, what it means, and what needs to happen next during active incidents. + **Collaboration:** Ability to work effectively with SOC, engineering, infrastructure, and security teams to investigate and remediate threats. Work Experience: + Typically 1 to 3 years with bachelor's or equivalent. Education and Certification(s): + Bachelor's degree or equivalent experience from which comparable knowledge and job skills can be obtained. + Relevant certifications preferred but not required ## Description We are seeking a hands-on Cyber Incident Response Analyst to join a steadily maturing incident response program. In this role, you will be part of a global team operating in a follow-the-sun model across regions, supporting incident response through coordinated handoffs. The team operates on the CrowdStrike platform across EDR, NG-SIEM, SOAR, case management, and Charlotte AI, working closely with an externally managed SOC to support escalated investigations. As we continue integrating AI capabilities into the platform, lower-level triage work is handled automatically, allowing analysts to focus on deeper investigation, threat hunting, reporting, and improving how incidents are detected and handled. Principal Responsibilities: + **Incident Investigation:** Investigates and responds to escalated cybersecurity incidents, including validation, scoping, containment, and recovery, while determining root cause, scope, and business impact. + **Threat Analysis and Correlation:** Analyzes activity across endpoint, network, cloud, and identity systems and correlates data across EDR, SIEM, and other telemetry sources to understand attacker behavior. + **SOC Escalation Support:** Serves as an escalation point for SOC analysts by guiding investigations, improving triage quality, and helping ensure consistency in analysis. + **Threat Hunting:** Performs proactive threat hunting using structured queries, threat intelligence, and observed activity to identify suspicious behavior beyond alert-driven detection. + **Detection and Response Improvement:** Identifies detection gaps and contributes to improving detections, use cases, workflows, and overall response quality. + **Documentation and Reporting:** Maintains incident response playbooks, procedures, and investigation documentation, and develops clear incident reports and executive summaries for both technical and non-technical audiences. + **Incident Coordination:** Takes ownership of investigative workstreams during complex incidents and, when needed, assumes the role of incident commander until relieved by senior staff. + **Post-Incident Review:** Participates in post-incident reviews and contributes to applying lessons learned to improve future detection and response. + **Other duties as assigned** ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)