FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Incident Response Analyst
Thrive. Process investigation requests from SOC Analysts monitoring security events through SIEM across network and host-based IDS/IPS, network infrastructure logs, system logs, applications, and databases .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates advanced knowledge in SIEM, IDS/IPS, and incident response methodologies, with a strong focus on threat hunting and vulnerability analysis. Proficient in collaborating with cross-functional teams to develop and maintain effective incident response playbooks aligned with security strategies.
Highest-signal resume keywords
Advanced Knowledge of SIEMAdvanced Knowledge of TCP/IPAdvanced Knowledge of IDS/IPSAdvanced Knowledge of EDRExpertise in Forensics and Malware Analysis
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ResponseThreat HuntingVulnerability TestingPacket AnalysisMalware AnalysisNetwork Intrusion ResponseContent FilteringSystem AdministrationSecurity Best PracticesIncident Management
Soft Skills
Strong Analytical SkillsProblem-Solving SkillsCollaborationCommunication
Tools & Technologies
SIEMIDS/IPSEDRFirewallsAnti-VirusAnti-MalwareForensic Analysis ToolsNetwork Protocols
Industry Keywords
Cyber Kill ChainMITRE ATT&CKIncident Response ProceduresSecurity StandardsThreat Intelligence
Tech Stack
Tools & technologiesCloudDNSLinuxSMTPSwitchingTCP/IPUnix
About the role
Key responsibilities & impact- Process investigation requests from SOC Analysts monitoring security events through SIEM across network and host-based IDS/IPS, network infrastructure logs, system logs, applications, and databases
- Investigate intrusion attempts, distinguish false positives from true intrusions, and perform in-depth exploit analysis
- Lead incident response and threat hunting for confirmed High Priority security incidents through resolution
- Use threat intelligence to identify and investigate potential security threats
- Develop incident response and incident management playbooks covering threat triage, investigation, and resolution
- Review and update playbooks for currency and effectiveness
- Collaborate with cross-functional teams to align playbooks with security strategy and goals
- Participate in tabletop exercises and drills to test and validate playbooks
- Monitor and evaluate incidents to identify playbook improvement opportunities
- Track current security threats and trends to keep playbooks relevant
- Investigate current vulnerabilities, advisories, incidents, and TTPs and collaborate with Security Engineering on recommended use cases
- Proactively monitor, hunt, and respond to known and emerging threats
- Execute Thrive’s information security strategy internally and externally for 400+ clients
- Analyze data from SOC, SIEM, and EDR platforms and determine whether further analysis is needed
- Follow Thrive security standards and best practices and recommend enhancements
- Stay current on security events and techniques to protect clients
Requirements
What you’ll need- Advanced knowledge of SIEM (Security Information and Event Management)
- Advanced knowledge of TCP/IP, computer networking, routing, and switching
- Advanced knowledge of IDS/IPS, penetration and vulnerability testing
- Advanced knowledge of firewall and intrusion detection/prevention protocols
- Advanced knowledge of Windows, UNIX, and Linux operating systems
- Advanced knowledge of network protocols and packet analysis tools
- Advanced knowledge of EDR, anti-virus, and anti-malware
- Advanced knowledge of content filtering
- Advanced knowledge of email and web gateways
- Advanced knowledge of malware, network, or system analysis
- Professional experience in a system administration role supporting multiple platforms and applications
- Comprehension of best security practices
- Ability to collaborate and communicate security issues to clients, peers, and management
- Strong analytical and problem-solving skills
- Adaptability and resilience in rapidly evolving situations
- Ability to participate in an on-call rotation, occasionally working nights and weekends
- Technical proficiency in networking, operating systems, and security technologies
- Familiarity with SIEM, IDS/IPS, EDR, and forensic analysis tools
- Understanding of incident response procedures and methodologies
- Understanding of MITRE ATT&CK and the Cyber Kill Chain frameworks
- Familiarity with TCP/IP and application-layer protocols, including HTTP, SMTP, and DNS
- Experience responding to and investigating cloud, system, or network intrusions
- Expertise in forensics, malware analysis, and network intrusion response
- Preferred: knowledge of common Windows and Linux/Unix system calls and APIs
- Preferred: knowledge of programming languages
- Preferred: knowledge of internal file structures for malware-associated formats such as OLE, RTF, PDF, and EXE
- Preferred: knowledge or experience in Detection Engineering
Benefits
Comp & perks- 🌐 Worldwide ❌ Jobs You've Hidden ⭐️ Saved Jobs ✅ Applied Jobs ✉️ Email Alerts 👤 Account Thrive Website LinkedIn All Job Openings 1001 - 5000 employees Founded 2000 🔒 Cybersecurity 💼 Consulting Cybersecurity
- Consulting Thrive is a B2B technology services firm that provides managed IT, cloud, and cybersecurity solutions for mid-market and enterprise clients. Its offerings include managed detection and response (MDR), EDR/NDR, vulnerability management, autonomous penetration testing, patching, managed firewalls, dark web monitoring, email/DNS security, security awareness training, incident response and remediation, and specialized security for Microsoft 365 and Azure. Thrive also delivers managed cloud services, disaster recovery, colocation, ServiceNow-based ITSM (TransformIT), managed network services, vCISO/vCIO advisory, and compliance support for standards such as HIPAA, GLBA, CMMC, GDPR and others. The company targets industries including financial services, healthcare, government, education, life sciences, and professional services, positioning itself as a consultancy and managed services provider that combines security, cloud, and digital transformation capabilities. Incident Response Analyst 🔥 2 minutes ago 🇺🇸 United States – Remote ⏰ Full Time 🟡 Mid-level 🟠 Senior 🚨 Incident Response Analyst 👻 Ghost score 10% Apply Now Customize resume + cover letter Report problem ☆ Save ☑️ Mark as applied ❌ Hide 📋 Description
- Process investigation requests from SOC Analysts monitoring security events through SIEM across network and host-based IDS/IPS, network infrastructure logs, system logs, applications, and databases
- Investigate intrusion attempts, distinguish false positives from true intrusions, and perform in-depth exploit analysis
- Lead incident response and threat hunting for confirmed High Priority security incidents through resolution
- Use threat intelligence to identify and investigate potential security threats
- Develop incident response and incident management playbooks covering threat triage, investigation, and resolution
- Review and update playbooks for currency and effectiveness
- Collaborate with cross-functional teams to align playbooks with security strategy and goals
- Participate in tabletop exercises and drills to test and validate playbooks
- Monitor and evaluate incidents to identify playbook improvement opportunities
- Track current security threats and trends to keep playbooks relevant
- Investigate current vulnerabilities, advisories, incidents, and TTPs and collaborate with Security Engineering on recommended use cases
- Proactively monitor, hunt, and respond to known and emerging threats
- Execute Thrive’s information security strategy internally and externally for 400+ clients
- Analyze data from SOC, SIEM, and EDR platforms and determine whether further analysis is needed
- Follow Thrive security standards and best practices and recommend enhancements
- Stay current on security events and techniques to protect clients 🎯 Requirements
- Advanced knowledge of SIEM (Security Information and Event Management)
- Advanced knowledge of TCP/IP, computer networking, routing, and switching
- Advanced knowledge of IDS/IPS, penetration and vulnerability testing
- Advanced knowledge of firewall and intrusion detection/prevention protocols
- Advanced knowledge of Windows, UNIX, and Linux operating systems
- Advanced knowledge of network protocols and packet analysis tools
- Advanced knowledge of EDR, anti-virus, and anti-malware
- Advanced knowledge of content filtering
- Advanced knowledge of email and web gateways
- Advanced knowledge of malware, network, or system analysis
- Professional experience in a system administration role supporting multiple platforms and applications
- Comprehension of best security practices
- Ability to collaborate and communicate security issues to clients, peers, and management
- Strong analytical and problem-solving skills
- Adaptability and resilience in rapidly evolving situations
- Ability to participate in an on-call rotation, occasionally working nights and weekends
- Technical proficiency in networking, operating systems, and security technologies
- Familiarity with SIEM, IDS/IPS, EDR, and forensic analysis tools
- Understanding of incident response procedures and methodologies
- Understanding of MITRE ATT&CK and the Cyber Kill Chain frameworks
- Familiarity with TCP/IP and application-layer protocols, including HTTP, SMTP, and DNS
- Experience responding to and investigating cloud, system, or network intrusions
- Expertise in forensics, malware analysis, and network intrusion response
- Preferred: knowledge of common Windows and Linux/Unix system calls and APIs
- Preferred: knowledge of programming languages
- Preferred: knowledge of internal file structures for malware-associated formats such as OLE, RTF, PDF, and EXE
- Preferred: knowledge or experience in Detection Engineering Apply Now 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score Similar Jobs Incident Response Analyst – Mid-Senior Level 🕒 Yesterday Toyota Tsusho Europe 1001 - 5000 🚘 Automotive 💼 Consulting 🏭 Manufacturing Website LinkedIn All Job Openings Incident Response Analyst defending Toyota’s global automotive technology ecosystem. Conducting digital forensics, threat hunting, malware analysis, and critical incident response. 🇺🇸 United States – Remote ⏰ Full Time 🟠 Senior 🚨 Incident Response Analyst Senior Incident Response Analyst 🕒 September 8 OpenLoop 201 - 500 💼 Consulting ⚖️ Legal 📦 Logistics Website LinkedIn All Job Openings Senior Incident Response Analyst protecting OpenLoop’s telehealth systems and patient-care operations. Owning forensic investigations, incident containment, and response automation. 🇺🇸 United States – Remote 💰 $15M Series A - OpenLoop Health on 2023-03 ⏰ Full Time 🟠 Senior 🚨 Incident Response Analyst Senior Incident Handler 🕒 July 15 Allstate 10,000+ employees 💼 Consulting 📦 Logistics 🛡️ Insurance Website LinkedIn All Job Openings Senior Incident Handler at Allstate leading critical incident response and investigations. Driving modern security operations with a focus on automation and AI. 🇺🇸 United States – Remote 💵 $120k - $193.7k / year 💰 Post-IPO Equity on 2014-01 ⏰ Full Time 🟠 Senior 🚨 Incident Response Analyst 🦅 H1B Visa Sponsor View More Incident Response Analyst Jobs 🌐 Worldwide Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or support@remoterocketship.com Search Remote jobs Search Jobs by country Search jobs by city Search jobs by job title Search entry-level jobs Search junior-level jobs Search senior-level jobs Search jobs by tech stack Search jobs by contract type Search remote internships Search remote part-time jobs Remote jobs Anywhere in the World Companies Hiring Anywhere in the World Companies Hiring Sales People Anywhere in the World Companies Hiring Software Engineers Anywhere in the World Resources About us Advice Tips for finding remote jobs Interview questions and answers Resume examples Cover letter examples Post a job Affiliates Is Remote Rocketship legit? Privacy policy Terms of service Job board SEO course Remote Job Search MasterClass Resume Review AI Apply Copilot OpenClaw job finder API docs Find jobs using your resume Jobs by Country Remote jobs anywhere in the world (Worldwide remote jobs) Remote jobs United States Remote jobs Australia Remote jobs Brazil Remote jobs Canada Remote jobs France Remote jobs Ireland Remote jobs Germany Remote jobs Netherlands Remote jobs Spain Remote jobs UK Popular Jobs Remote data analyst jobs Remote customer support jobs Remote executive assistant jobs Remote marketing jobs Remote product designer jobs Remote product manager jobs Remote project manager jobs Remote recruiter jobs Remote sales jobs Remote software engineer jobs Jobs by Type Remote full-time jobs Remote part-time jobs Remote contract jobs Remote internship jobs Remote entry-level jobs Remote jobs with no experience required Remote junior jobs (1-3 years of experience) Digital nomad jobs Remote jobs with no degree required Freelance remote jobs Temporary remote jobs Remote jobs hiring now Stay at home mom jobs