Incident Response Analyst
HybridIrving, Texas, United States
Job Summary
Conduct root cause analysis of security breaches, determine attack vectors, and lead containment using TrendAI Vision OneTM. Analyze malware and threat components to develop detection rules, generate threat intelligence, and hunt for advanced indicators across customer networks. Create executive-ready incident reports, deliver briefings to stakeholders, and recommend security improvements. Contribute to automation initiatives that compress response times and refine AI-driven workflows. Investigate sophisticated breaches, coordinate with internal teams and customer stakeholders, and translate complex forensic findings into actionable intelligence. Work 24/7 rotating shifts including nights, weekends, and holidays.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field
- 3+ years in security operations
- demonstrated expertise in Incident response and forensics
- demonstrated expertise in Malware analysis and threat investigation
- demonstrated expertise in SOC operations or security monitoring
- Advanced Windows and Linux forensics (registry, event logs, artifacts, filesystem analysis)
- Familiarity with how AI and automation are reshaping incident response workflows, from alert triage to forensic analysis
- SIFT Workstation
- WinPMEM
- dd/dclfdd
- Autopsy
- Volatility Framework
- FTK Imager
- Wireshark
- Bro/SiLK
- Netflow
- tcpdump
- SIEM platforms
- syslog analysis
- event correlation procedures
- Static and dynamic analysis techniques
- Understand threat actor TTPs and MITRE ATT&CK framework alignment
- contribute to organizational threat intelligence
- Leverage threat intelligence platforms
- Working knowledge of the Vision One platform or equivalent threat intelligence/XDR platforms
- Ability to work 24/7 rotating shifts, including nights, weekends, and holidays
- Willing to travel when required
- Candidates must be authorized to work in the U.S. without the need for employment-based visa sponsorship, both currently and moving forward
Desired Qualifications
- GCIH (GIAC Certified Incident Handler)
- GCFA / GCFE (GIAC Certified Forensic Analyst / Examiner)
- CISSP or OSCP
- Strong written and verbal communication, ability to translate complex forensic findings for technical and executive audiences
- Self-directed learner with aptitude for rapidly mastering new tools and threat landscapes
- Comfortable working under pressure; thrives in fast-paced, high-stakes environments
- Strong analytical and problem-solving skills with ability to work effectively in a global team environment
- Comfortable speaking to customer via e-mail, chat and phone
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.