Cyber Incident Response Analyst

Posted yesterday

rit solutionsAustin (TX)

SENIORITY

Senior

Apply

About the role

Cyber Incident Response Analyst
Location: Austin OR San Antonio, TX - Hybrid Candidates must reside within Austin OR San Antonio, TX.
Responsibilities: Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery. Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis. Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies. Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE Telecommunication&CK.Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools. Produce incident reports, timelines, and executive summaries for statewide stakeholders. Support multi-agency response operations, including SLTT partners and critical infrastructure entities. Provide recommendations for detection improvements, hardening, and long-term mitigation. Participate in post-incident reviews, lessons learned, and playbook updates. Maintain readiness for 24x7 response through on-call rotation or surge support.
Qualifications
Minimum Requirements: Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity. Years - Required/Preferred - Experience5 - Required - Advanced host‐based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity.5 - Required - Ability to correlate host, network, and intelligence data from CrowdStrike, Sentinel One, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines.5 - Required - Experience producing high‐quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows.4 - Required - Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet‐level and log‐level data from but not limited to Corelight, NetWitness, and CRIBL pipelines.3 - Required - Incident Commander experience1 - Required - Experience supporting SLTT or critical infrastructure environments, including multi‐tenant IR operations and cross‐agency coordination.5 - Preferred - Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE Telecommunication&CK.5 - Preferred - Hands‐on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems.4 - Preferred - Security Certifications Preferred (CISSP, CIH, Sec+)

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this