Job Closed

This listing is no longer active.

TEKsystems logo
TEKsystems

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia.

Incident Response Analyst

Location

United States

Posted

77 days ago

Salary

$75 - $81 / hour

Seniority

Mid Level

Job Description

Incident Response Analyst

TEKsystems

Role Description We are seeking a highly motivated and experienced Incident Response Lead to serve as the NGDC SOC’s technical authority during active cybersecurity incidents across hybrid cloud and on-prem environments. You will direct responders, coordinate with enterprise stakeholders, and drive rapid containment and eradication of threats targeting the NGDC and FTII platforms. This role is ideal for a seasoned IR professional with strong investigative leadership, decisive problem-solving under pressure, and a passion for elevating SOC maturity. This is a forward facing position. The incumbent will support the SOC manager on the delivery of a daily brief to the FSA CISO. Candidate must master clear and concise verbal communications. Qualifications - 10-12 years of hands-on cybersecurity experience within a SOC, including 6+ years in incident response or DFIR roles - Demonstrated ability to lead major incidents affecting cloud infrastructure (AWS) - Strong command of: - Digital forensics methodologies (host, network, and cloud) - Log and SIEM analysis (e.g., Splunk) - EDR platforms (e.g., Trellix) - Network analytics and packet capture fundamentals - Deep familiarity with MITRE ATT&CK, NIST SP 800-61, and cyber kill chain frameworks - Excellent communication and situational leadership skills — able to brief executives under pressure - U.S. Citizenship, must obtain Public Trust 6C. Requirements - Relevant certifications, such as: - GCIA, GCFA, GCFE, GNFA, GCIH, GDAT - Other vendors: Cybersecurity IR or forensic-focused certifications - Experience mentoring responders and maturing SOC/IR capabilities - Experience with MITRE ATT&CK, Threat Intelligence, Threat Hunting, Enterprise Logging, Cloud IR Benefits - Medical, dental & vision - Critical Illness, Accident, and Hospital - 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available - Life Insurance (Voluntary Life & AD&D for the employee and dependents) - Short and long-term disability - Health Spending Account (HSA) - Transportation benefits - Employee Assistance Program - Time Off/Leave (PTO, Vacation or Sick Leave) Company Description We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company. The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

Related Job Pages

More Incident Response Analyst Jobs

Banner Health logo

Senior Major Incident Coordinator

Banner Health

Making health care easier, so life can be better.

Full TimeRemoteTeam 10,001+Since 1999H1B Sponsor

Role Description As a Senior Major Incident Coordinator, you will be the operational engine behind our major incident response: - Monitoring for impact - Keeping timelines and documentation crisp and accurate - Ensuring process adherence - Helping teams stay aligned under pressure When incidents are not active, you’ll support operational readiness—so when the next high-severity event hits, we respond faster and smarter. You’ll work under the guidance of the Major Incident Commanders. This role requires variable shifts plus responding to 24x7 critical alerts via mobile device or other connected platform. This can be a remote position if you live in the following states ONLY: AL, AK, AR, FL, GA, ID, IN, IA, KS, KY, LA, MD, MI, MN, MS, MO, NH, NM, NY, NC, ND, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WI, AZ, CA, CO, NE, NV, WY. No other states will be considered. Qualifications - Experience and education as normally obtained through an Associate’s degree and 1 year of relevant experience in IT operations, service desk, NOC, or incident management. - Demonstrated ability to independently coordinate major incidents. - Strong written and verbal communication skills, including stakeholder-facing updates. - Ability and willingness to work variable shifts and respond to 24x7 critical alerts via mobile device or other connected platforms for service disruptions. Requirements - Works assigned shift and participates in on-call rotation to independently coordinate major incident bridge calls and collaboration channels. - Reviews, validates, and maintains incident records, timelines, and activity logs. - Publishes approved outage notifications and status updates using standard templates. - Monitors dashboards and system alerts across designated platforms. - Partners with Problem Management to monitor RCA completion quality. - Monitors and reports on high-priority incident response SLAs and KPIs. - Reviews playbooks, contact lists, and templates for accuracy. - Maintains up-to-date knowledge of enterprise technology platforms, security policies, major incident processes, core stakeholders, and downtime procedures. Benefits - Health and financial security options. - Variety of benefit plans to help you and your family.

United States
$34 - $56 / hour

Principal Advanced Threat Response Analyst

HPE

Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world.

Role Description At Hewlett Packard Enterprise (HPE), we are seeking a highly experienced and technically proficient Principal Advanced Threat Response Analyst to join our global security organization. The ideal candidate will have over a decade of hands-on experience in incident response, threat hunting, threat intelligence, digital forensics, malware analysis, and incident management, with proven expertise in leading investigations into Advanced Persistent Threats (APT) and other complex, multi-stage intrusions, including widescale Ransomware attacks. This role requires a blend of technical mastery, investigative acumen, and leadership capability. The candidate will drive proactive and reactive threat hunting efforts, lead critical incident response engagements, and develop both short-term containment and long-term remediation strategies to strengthen the organization’s cyber defense and improve overall security posture. This role is fully remote USA. Key Responsibilities - Lead complex threat investigations involving APTs, ransomware, insider threats, and nation-state activity across enterprise and cloud environments. - Drive proactive threat hunting programs focused on emerging TTPs, behavioral analytics, and detection gaps within EDR, SIEM, and network telemetry data. - Develop and execute purple team exercises, simulating advanced adversarial tradecraft to assess detection and response capabilities. - Collaborate with red teams and offensive security engineers to understand attacker tools, techniques, and procedures (TTPs) at a deep technical level and translate that understanding into effective detections. - Perform incident command during major security events — leading multidisciplinary response teams, engaging executive stakeholders, and delivering after-action reports and strategic recommendations. - Develop custom detections, playbooks, and automation in Splunk, Sentinel, or other platforms to improve time-to-detect and time-to-contain metrics. - Mentor and coach junior analysts, hunters, and incident responders — fostering an environment of continuous learning and operational excellence. - Contribute to threat intelligence initiatives, enriching internal intelligence feeds with context from ongoing investigations and external research. - Collaborate with engineering and architecture teams to harden security controls across endpoint, network, and cloud layers. - Conduct tabletop exercises and technical simulations to validate response readiness and identify process or technology gaps. Qualifications - 10+ years of experience in cybersecurity roles focused on incident response, threat hunting, digital forensics, threat intelligence, or SOC operations. - Proven record of leading end-to-end investigations of advanced threat campaigns (APT) or other complex multi-vector attacks. - Strong understanding of MITRE ATT&CK framework, adversary emulation, and kill chain analysis. - Demonstrated expertise in both enterprise IT and cloud security (AWS, Azure, GCP) — from defensive and offensive perspectives. - Working knowledge of red team / offensive security operations and the ability to deconstruct offensive tools (e.g., Cobalt Strike, Empire, Metasploit, Sliver, Mimikatz, other open-source OffSec tools) to detect their presence and behaviors. - Deep knowledge of SIEMs (Splunk, Sentinel, ELK), EDR platforms (CrowdStrike, Carbon Black, Defender ATP), and forensics tools. - Strong scripting or automation experience (Python, PowerShell, Bash) for hunting, enrichment, or data manipulation. - Ability to design and facilitate purple team exercises and incident response tabletop simulations replicating advanced adversary techniques. - Excellent communication and leadership skills; ability to brief executives, collaborate across functions, and guide junior team members. Certifications - Advanced SANS certifications such as GCFA, GREM, GCIA, GNFA, GCTI, GSEC, or GCIH. - Offensive certifications such as OSCP, OSEP, OSED, or CRTO. - Recognition from hands-on platforms (e.g., Hack The Box, Cyber Defenders, TryHackMe) demonstrating technical proficiency. - Cloud security certifications (AWS Security Specialty, Azure Security Engineer, GCP Professional Cloud Security Engineer) are a plus. Benefits - Health & Wellbeing: We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial, and emotional wellbeing. - Personal & Professional Development: We invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division. - Unconditional Inclusion: We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs.

United States
$120.5K - $276.5K / year
Job Closed
Honeywell Aerospace logo

Incident Response Leader

Honeywell Aerospace

Honeywell Aerospace products and services are used on virtually every commercial, defense, and space aircraft. We build aircraft engines, cockpit and cabin electronics, wireless connectivity systems, mechanical components. Our hardware and software solutions help create more fuel-efficient aircraft, more direct and on-time flights and safer skies. Safer, More Fuel-Efficient Flying and Innovations for the Future of Aviation.

Full TimeRemoteTeam 10,001

Cybersecurity Incident Response Team (CIRT) Are you passionate about leading global Cybersecurity innovation and change? Do you thrive in environments that encourage critical thinking, creativity, and challenging the status quo? We’re looking for an Incident Response Leader capable of commanding critical incidents, engaging with senior leadership, developing junior team members, and leading our organization’s initiatives. You will report directly to our Sr. Director of Cyber Security, and work out of our Phoenix, AZ location or REMOTE.

United States
$162K - $233K / year

Registered Nurse - Ambulance Response

NSW Government

The New South Wales (NSW) Government serves as the governing body for Australia’s most populous state, dedicated to delivering programs and services that enha

Title: Registered Nurse - Ambulance Response - Perm PT Location: Sydney - West, NSW, Australia (Fairfield Community Health Centre) Job Description: Employment Type: Permanent Part Time, 16 hours per week Remuneration: $37.48 - $52.62 per hour + 12% Superannuation + Salary Packaging Contact: Belinda Boylson - CoPILOT Team Leader on 0417 287 891 | Belinda.Boylson@health.nsw.gov.au With your skills and experience, you can contribute to the millions of ways we're enriching health, and develop your career as part of the largest health organisation in Australia. Achieve Something Great COPILOT is a fast‑growing, innovative service transforming the way older people access acute care in the community. Our multidisciplinary team delivers rapid, high‑quality geriatric assessment across medical, nursing, and allied health disciplines directly to people in their homes, helping them stay well, avoid unnecessary hospital transfers, and achieve better health outcomes.As an Ambulance Response Registered Nurse, you will play a key role in delivering this impactful model of care. In this role, you will: - Provide high‑quality clinical care to clients aged 16 years and over, supporting both them and their families/carers to optimise health and wellbeing in the community. - Work closely with COPILOT Clinical Nurse Consultants to deliver evidence‑based acute care in clients' homes or residential aged care facilities. - Contribute to reducing avoidable hospital presentations by delivering timely, person‑centred interventions where they are needed most. - Be part of a dynamic, supportive team committed to innovation, collaboration, and exceptional patient outcomes. Are You the Right Fit? The Ambulance Response Registered Nurse delivers high quality, evidence based clinical care to clients aged 16 years and over in the community. In this role, you will work collaboratively with NSW Ambulance, COPILOT Clinical Nurse Consultants, medical officers, and allied health professionals to provide timely and effective care where it is needed most. To thrive in this position, you will bring: - Experience in community or aged care settings, with a strong understanding of the needs of clients receiving care in their home environment. - Confidence working within a multidisciplinary team and contributing to coordinated, person centred care. - Highly developed skills in autonomous practice and advanced clinical decision making. - Excellent communication and time management abilities, enabling you to respond effectively in dynamic and fast paced situations. Selection Criteria To help us assess your suitability for the role, please tell us as much as you can about yourself in response to the questions below. - Do you have current Authority to Practice as a Registered Nurse with Australian Health Practitioners Regulation Agency (AHPRA)? - Demonstrated recent experience as a Registered Nurse in an environment appropriate to the role, with a background in aged care and community health settings preferred. - What are the advantages of providing acute aged care in the community or RACF environment? - Describe a time where you have had to navigate care of a complex patient in the community and manage difficult conversations with a family/carer/NOK and what was the outcome? - Demonstrate your understanding of working within scope of practice and the work, health and safety requirements of working in a community based role. - Do you have a current Australian C-Class driver's license (including P1 or P2)? if you hold a C class license (P1 or P2 included) from a state other than NSW must obtain a NSW C class (P1 or P2 included) license within three months of appointment. Learner's licenses are not permitted. If you'd like more details, we're here to help. - Position Information - Applicants will be assessed against the criteria in the Position Description. - How to Apply - Read our application guide and tips for improving your application. - Diversity, Culture & Inclusion - We are proud to be an equal opportunity employer dedicated to accessibility and a supportive recruitment experience. If you require adjustments or assistance during the application process, please contact SWSLHDJobs@health.nsw.gov.au - We value the diverse backgrounds, experiences, and perspectives of our workforce and are committed to fostering a respectful and welcoming environment. We strongly encourage applications from Aboriginal and/or Torres Strait Islander peoples, people with disability, neurodivergent individuals, those from Refugee, multicultural and multifaith backgrounds, and members of the LGBTQI+ community. - Aboriginal Workforce - For Aboriginal candidates who would like to talk to our Aboriginal Workforce Team, please contact SWSLHD-AboriginalWorkforce@health.nsw.gov.au. Support is also available through the Stepping Up website. More Than Just a Job - Why Work With Us? - Financial Perks - 12% superannuation - Salary packaging and novated leasing via Smart Salary - Annual leave with 17.5% leave loading (for full-time and part-time staff) - One extra day off each month for full-time employees - Work-Life Balance - Flexible work options, including hybrid and varied hours (depending on the role) - Paid maternity and parental leave - Generous leave options like long service and carers leave - Grow Your Career - Access to learning opportunities through our dedicated Education and Organisational Development team, who support staff with training, workshops, and career development programs. - Health & Wellbeing - Discounted gym membership through Fitness Passport - Free and confidential support for staff and their families via our Staff Wellbeing and Support Service (EAP) - Wellbeing programs that promote mental health, resilience, and balance Additional Information - Temporary visa holders - May be considered if no suitable citizen or permanent resident is found. - Vaccination Requirements - All staff must meet NSW Health's vaccination and screening requirements before starting. - Child Safe Employment - South Western Sydney Local Health District is dedicated to fostering a child-safe environment that respects and upholds the rights of children and young people, aligned with NSW Health's commitment to implementing the Child Safe Standards. We aim to ensure that children and young people feel safe, supported, and included in their care. All current and prospective staff are expected to prioritise the safety, welfare, and well-being of children and young people, actively working to protect them from harm and abuse.

Australia
$37 - $52 / hour