Senior Incident Response Analyst (R-19347)
| Estimated Pay info | Based on similar jobs in your market$31 per hour |
|---|---|
| Hours | Full-time |
| Location | United, West Virginia |
About this job
Job Description
We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This role is responsible for handling complex security incidents, guiding junior analysts, improving detection capabilities, and strengthening our overall security posture.
The Senior Incident Response Analyst brings deep technical expertise, strong analytical thinking, and a proactive mindset toward defending the enterprise.
- Lead high‑fidelity alert investigations, performing deep technical analysis to rapidly identify, contain, and remediate threats.
- Own complex incident investigations, driving technically precise conclusions and elevating the organization’s detection and response maturity.
- Champion process development, identifying gaps, designing scalable workflows, and implementing improvements that strengthen the Incident Response program.
- Create and refine technical playbooks, documentation, and response guides, ensuring clarity, consistency, and operational excellence.
- Mentor and uplift junior analysts, providing guidance, coaching, and training to build a high-performing team.
- Serve as the escalation point for critical and ambiguous cases, applying advanced threat analysis and sound judgment under pressure.
- Collaborate with engineering, IT, Legal, HR, and business partners to resolve incidents holistically and drive enterprise-wide security improvements.
- Apply strong analytical and technical expertise to continuously enhance SOC processes, workflows, and response capabilities.
- Contribute to the evolution of our detection landscape, partnering with detection engineering to improve log ingestion, alert logic, and signal quality.
- Assess and mitigate AI‑related security risks, including model misuse, prompt injection, data leakage, and emerging automation attack vectors.
- Participate in an on‑call rotation, serving as a trusted responder for high‑severity incidents.
At least 1 SANS/GIAC Certification (GCIH, GREM, GCFA preferred)
Strong Hands-on experience with
SIEM Platforms (Splunk, Microsoft sentinel, etc)
EDR Tools (CrowdStrike, Carbon Black)
Cloud environments (Azure, AWS, GCP, AliCloud)
Network log analysis (Netflows and PCAP files)
Deep understanding of:
Mitre ATT&CK framework
Malware behavior and exploitation techniques
Windows, Linux, and macOS internals
Script analysis (Javascript, VBscript, powershell, python)
Malicious binary analysis (Windows, MacOS, Linux)
Clear communication rooted in technical competence
Confidence discussing findings with peers and senior management
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please visit https://bit.ly/3LMn4CQ.