Junior Cyber Incident Response (IR) Analyst – USA
Role summary
We are looking for a Junior Cyber Incident Response (IR) Analyst with prior hands‑on experience to support daily incident response operations.
The analyst will work independently on follow‑the‑sun coverage (business days) and collaborate closely with the SOC distributed across the USA, Philippines, Romania, and Spain, as well as Global IT and business partners around the world.
Key responsibilities
· Handle low and medium severity cyber incidents end‑to‑end, performing incident assessment, triage, investigation, containment, eradication, support in recovery, and closure documentation, based on approved playbooks and NIST‑aligned incident response standards.
· Support high‑severity incidents, assisting senior IR analysts with investigation activities, evidence collection, and coordination, following established playbooks and escalation procedures; decision‑making remains with senior IR.
· Collect, preserve, and analyze incident evidence, and execute approved containment and eradication actions in line with documented procedures and standards.
· Document incidents accurately and on time, including tickets, investigation notes, timelines, and closure notes, ensuring audit‑ready documentation.
· Endorse and manage incident tickets from EMEA and perform structured handover of active incidents to the Philippines IR/SOC team, ensuring continuity in a follow‑the‑sun operating model.
· Contribute to the continuous improvement of incident response processes, playbooks, and procedures, incorporating lessons learned.
· Work effectively within a global, distributed team, ensuring smooth handover, clear communication, and continuous operations across time zones.
·
Required experience
· 1–3 years of experience in Incident Response, SOC, Security Operations, or a related cybersecurity role.
· Hands‑on exposure to handling security incidents, at least at a junior or supporting level.
· Practical understanding of the incident response lifecycle: assessment, triage, investigation, containment, eradication, recovery support, and closure documentation.
· Experience working with security alerts, logs, and incident tickets, following defined playbooks and procedures.
· Basic knowledge of common incident types, such as malware, phishing, ransomware, and account compromise.
· Familiarity with incident response standards and frameworks (e.g. NIST), at a foundational or working level.
· Comfortable working independently within defined scope and escalating appropriately to senior IR staff.
Nice to have
· 1–3 years of experience handling security incidents in a SOC, Incident Response, or SecOps environment.
· Experience with enterprise security tooling used for detection and response (e.g. Microsoft Security suite or similar platforms from other vendors).
· Exposure to alerts from EDR, identity, email, network, or cloud security tools.
· Basic experience with cloud or identity environments (e.g. M365 / Entra ID or equivalent
· Entry‑level security certifications such as Security+, CySA+, or equivalent.
Soft skills
- Clear written and verbal communication in English.
- Comfortable working in a global, distributed team and following handover processes.
- Able to stay calm, structured, and methodical during incident handling.
- Willing to ask for help and escalate appropriately when needed.
- Proactive, reliable, and eager to learn and develop incident response skills.
Pay: $39.00 - $55.00 per hour
Work Location: Hybrid remote in Raleigh, NC 27629