Senior Cyber Incident Response (IR) Analyst – USA
Role summary
We are looking for a Senior Cyber Incident Response (IR) Analyst with strong hands‑on experience to lead and manage complex security incidents and support the maturity of the global incident response capability.
The analyst will work independently on follow‑the‑sun coverage (business days) and collaborate closely with the SOC distributed across the USA, Philippines, Romania, and Spain, as well as Global IT and business partners around the world. The role acts as a senior technical authority and escalation point within Incident Response.
Key responsibilities
- Lead cyber incidents end‑to‑end across all severities, performing incident assessment, triage, investigation, containment, eradication, recovery support, and closure documentation, in line with approved playbooks and NIST‑aligned incident response standards.
- Act as escalation point for high‑severity and complex incidents, driving investigation strategy, containment decisions, and coordination with SOC, Global IT, and business stakeholders.
- Perform deep technical analysis of security incidents, including endpoint, identity, email, network, and cloud‑based attacks.
- Oversee evidence collection and preservation, ensuring forensic integrity and compliance with procedures and standards.
- Coordinate and lead response activities across regions, including structured handover to the Philippines IR/SOC team, ensuring continuity in a follow‑the‑sun operating model.
- Provide clear, concise, and audit‑ready incident documentation, including timelines, executive summaries, and post‑incident reports.
- Contribute to the continuous improvement of incident response processes, playbooks, and procedures, incorporating lessons learned from incidents, exercises, and post‑incident reviews.
· Endorse and manage incident tickets from EMEA and perform structured handover of active incidents to the Philippines IR/SOC team, ensuring continuity in a follow‑the‑sun operating model.
· Contribute to the continuous improvement of incident response processes, playbooks, and procedures, incorporating lessons learned.
· Work effectively within a global, distributed team, ensuring smooth handover, clear communication, and continuous operations across time zones.
·
Required experience
- 5+ years of experience in Incident Response, SOC, Security Operations, or a related cybersecurity role.
- Proven experience leading high‑severity security incidents end‑to‑end.
- Strong hands‑on experience across the full incident response lifecycle: assessment, triage, investigation, containment, eradication, recovery, and post‑incident review.
- Advanced understanding of endpoint, identity, email, network, and cloud security incidents.
- Solid working knowledge of incident response frameworks and standards (e.g. NIST).
- Demonstrated ability to operate independently, make risk‑based decisions, and act as a senior escalation point.
- Experience working in global, distributed, follow‑the‑sun environments.
Nice to have
- 5+ years of experience in Incident Response, SOC, Security Operations, or a related cybersecurity role.
- Experience leading incident response in large, enterprise environments.
- Strong exposure to enterprise detection and response platforms (e.g. Microsoft Security Suite such as MDE, MDI, MDO, Entra ID Protection, and/or equivalent tools from other vendors).
- Experience with cloud and identity incident response (M365, Entra ID / Azure AD, AWS, or equivalent).
- Industry certifications such as GCIH, GCIA, GCED, CISSP, or equivalent.
Soft skills
- Excellent written and verbal communication skills in English, including executive‑level briefings.
- Strong analytical and decision‑making skills under pressure.
- Leadership mindset with the ability to guide, coordinate, and mentor others during incidents.
- Calm, structured, and resilient in high‑impact or crisis situations.
- Collaborative, pragmatic, and focused on continuous improvement.
Pay: $63.00 - $75.00 per hour
Work Location: Hybrid remote in Raleigh, NC 27629