Cyber Incident Response Analyst
3b staffingAustin (TX)
About the role
Cyber Incident Response Analyst
Location: Austin, TX / San Antonio, TX (Onsite)
Duration:
12 Months Contract Interview: Onsite Cyber Incident Response, Digital Forensics, Windows & Linux Security, SIEM, EDR, IDS/IPS, Threat Hunting, Malware Analysis, Memory & Disk Forensics, MITRE ATT&CK, Crowd Strike, Sentinel One, Microsoft Sentinel, Net Witness, Corelight, Gravwell, Google Sec Ops, Incident Command, Threat Intelligence, Security Operations (SOC).
Job Description:
We are seeking an experienced Cyber Incident Response Analyst to join our cybersecurity team. The ideal candidate will be responsible for investigating and responding to cybersecurity incidents, conducting forensic analysis, and collaborating with internal teams to protect critical systems and infrastructure. This role requires strong analytical skills, hands-on experience with incident response tools, and the ability to communicate technical findings to both technical and non-technical stakeholders.
Responsibilities:
Perform incident response activities, including triage, investigation, containment, eradication, and recovery. Conduct host-based forensic investigations across Windows and Linux environments. Analyze logs, memory, file systems, and malware to determine the scope and impact of security incidents. Monitor and investigate alerts from SIEM, EDR, IDS/IPS, and network monitoring tools. Correlate endpoint, network, and threat intelligence data to identify attack patterns and build incident timelines. Serve as the Incident Commander during major cybersecurity events when required. Analyze attacker tactics, techniques, and procedures (TTPs) and map findings to the MITRE ATT&CK framework. Prepare detailed incident reports, executive summaries, and technical documentation. Collaborate with cross-functional teams to improve detection capabilities and strengthen security controls. Participate in post-incident reviews and contribute to updating incident response playbooks. Provide on-call support for critical security incidents as needed.
Required Qualifications:
5+ years of experience in Cybersecurity Incident Response, Security Operations, or Digital Forensics. Strong experience with Windows and Linux incident response and forensic investigations. Hands-on experience with SIEM, EDR, IDS/IPS, and security monitoring platforms. Experience using tools such as Crowd Strike, Sentinel One, Microsoft Sentinel, Net Witness, Corelight, Gravwell, or Google Sec Ops. Knowledge of malware analysis, memory analysis, and digital forensic techniques. Strong understanding of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies. Experience producing incident reports and documenting technical findings. Excellent analytical, troubleshooting, and communication skills. Ability to work effectively in a fast-paced, collaborative environment.
Preferred Qualifications:
Experience with threat intelligence platforms such as Recorded Future, Grey Noise, Virus Total, Mandiant, or Google Threat Intelligence. Experience with security orchestration and automation tools such as Cyware CSAP.Previous experience supporting government, public sector, or critical infrastructure environments. Industry certifications such as CISSP, GCIH, Security+, GCFA, or GCFE.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
