Incident Response Analyst

🔥 1 minute ago

🇺🇸 United States – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🚨 Incident Response Analyst

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Thrive

Thrive

1001 - 5000 employees

Founded 2000

🔒 Cybersecurity

💼 Consulting

Cybersecurity • Consulting

Thrive is a B2B technology services firm that provides managed IT, cloud, and cybersecurity solutions for mid-market and enterprise clients. Its offerings include managed detection and response (MDR), EDR/NDR, vulnerability management, autonomous penetration testing, patching, managed firewalls, dark web monitoring, email/DNS security, security awareness training, incident response and remediation, and specialized security for Microsoft 365 and Azure. Thrive also delivers managed cloud services, disaster recovery, colocation, ServiceNow-based ITSM (TransformIT), managed network services, vCISO/vCIO advisory, and compliance support for standards such as HIPAA, GLBA, CMMC, GDPR and others. The company targets industries including financial services, healthcare, government, education, life sciences, and professional services, positioning itself as a consultancy and managed services provider that combines security, cloud, and digital transformation capabilities.

📋 Description

• Process investigation requests from SOC Analysts monitoring security events through SIEM across network and host-based IDS/IPS, network infrastructure logs, system logs, applications, and databases • Investigate intrusion attempts, distinguish false positives from true intrusions, and perform in-depth exploit analysis • Lead incident response and threat hunting for confirmed High Priority security incidents through resolution • Use threat intelligence to identify and investigate potential security threats • Develop incident response and incident management playbooks covering threat triage, investigation, and resolution • Review and update playbooks for currency and effectiveness • Collaborate with cross-functional teams to align playbooks with security strategy and goals • Participate in tabletop exercises and drills to test and validate playbooks • Monitor and evaluate incidents to identify playbook improvement opportunities • Track current security threats and trends to keep playbooks relevant • Investigate current vulnerabilities, advisories, incidents, and TTPs and collaborate with Security Engineering on recommended use cases • Proactively monitor, hunt, and respond to known and emerging threats • Execute Thrive’s information security strategy internally and externally for 400+ clients • Analyze data from SOC, SIEM, and EDR platforms and determine whether further analysis is needed • Follow Thrive security standards and best practices and recommend enhancements • Stay current on security events and techniques to protect clients

🎯 Requirements

• Advanced knowledge of SIEM (Security Information and Event Management) • Advanced knowledge of TCP/IP, computer networking, routing, and switching • Advanced knowledge of IDS/IPS, penetration and vulnerability testing • Advanced knowledge of firewall and intrusion detection/prevention protocols • Advanced knowledge of Windows, UNIX, and Linux operating systems • Advanced knowledge of network protocols and packet analysis tools • Advanced knowledge of EDR, anti-virus, and anti-malware • Advanced knowledge of content filtering • Advanced knowledge of email and web gateways • Advanced knowledge of malware, network, or system analysis • Professional experience in a system administration role supporting multiple platforms and applications • Comprehension of best security practices • Ability to collaborate and communicate security issues to clients, peers, and management • Strong analytical and problem-solving skills • Adaptability and resilience in rapidly evolving situations • Ability to participate in an on-call rotation, occasionally working nights and weekends • Technical proficiency in networking, operating systems, and security technologies • Familiarity with SIEM, IDS/IPS, EDR, and forensic analysis tools • Understanding of incident response procedures and methodologies • Understanding of MITRE ATT&CK and the Cyber Kill Chain frameworks • Familiarity with TCP/IP and application-layer protocols, including HTTP, SMTP, and DNS • Experience responding to and investigating cloud, system, or network intrusions • Expertise in forensics, malware analysis, and network intrusion response • Preferred: knowledge of common Windows and Linux/Unix system calls and APIs • Preferred: knowledge of programming languages • Preferred: knowledge of internal file structures for malware-associated formats such as OLE, RTF, PDF, and EXE • Preferred: knowledge or experience in Detection Engineering

Apply Now

Similar Jobs

🕒 Yesterday

Toyota Tsusho Europe

1001 - 5000

🚘 Automotive

💼 Consulting

🏭 Manufacturing

Incident Response Analyst defending Toyota’s global automotive technology ecosystem. Conducting digital forensics, threat hunting, malware analysis, and critical incident response.

🇺🇸 United States – Remote

⏰ Full Time

🟠 Senior

🚨 Incident Response Analyst

🕒 September 8

OpenLoop

201 - 500

💼 Consulting

⚖️ Legal

📦 Logistics

Senior Incident Response Analyst protecting OpenLoop’s telehealth systems and patient-care operations. Owning forensic investigations, incident containment, and response automation.

🇺🇸 United States – Remote

💰 $15M Series A - OpenLoop Health on 2023-03

⏰ Full Time

🟠 Senior

🚨 Incident Response Analyst

🕒 July 15

Allstate

10,000+ employees

💼 Consulting

📦 Logistics

🛡️ Insurance

Senior Incident Handler at Allstate leading critical incident response and investigations. Driving modern security operations with a focus on automation and AI.

🇺🇸 United States – Remote

💵 $120k - $193.7k / year

💰 Post-IPO Equity on 2014-01

⏰ Full Time

🟠 Senior

🚨 Incident Response Analyst

🦅 H1B Visa Sponsor

infoinfo