FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Incident Response Analyst II
WGU Advancement. Serve as a lead analyst for incident response and related security efforts, including digital forensics, continuous monitoring, intrusion detection and prevention, penetration testing, integration, and automation .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in incident response, digital forensics, and security operations, with a strong focus on SIEM analysis, automation, and compliance with industry standards. Proficient in developing security solutions and collaborating with cross-functional teams to enhance security posture.
Highest-signal resume keywords
Incident ResponseSIEM AnalysisMITRE ATT&CK FrameworkScripting Languages (Bash, Python)Security Certifications (CISSP, GIAC, ISACA, CCSP, CCSK)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Digital ForensicsIntrusion Detection SystemsPenetration TestingNetwork Traffic AnalysisSecurity Event AnalysisSecurity Rule DevelopmentIncident HandlingCloud Security PrinciplesData Encryption StrategiesAutomation
Soft Skills
Analytical SkillsProblem-SolvingDecision-MakingWritten CommunicationVerbal Communication
Tools & Technologies
SIEMIDS/IPSEndpoint SecurityFirewallsDLPHIPSEPPClient ProxyAWS ServicesCI/CD Security
Certifications & Qualifications
CISSPGIACISACACCSPCCSKAWS
Industry Keywords
Information SecuritySecurity StandardsComplianceSecurity OperationsSecurity Telemetry
Tech Stack
Tools & technologiesAWSCloudFirewallsPython
About the role
Key responsibilities & impact- Serve as a lead analyst for incident response and related security efforts, including digital forensics, continuous monitoring, intrusion detection and prevention, penetration testing, integration, and automation
- Investigate security events and unusual activity using SIEM, IDS/IPS, endpoint security, DLP, HIPS, EPP, client proxy, firewalls, and other security technologies
- Analyze phishing emails, logs, network traffic, alerts, and other security telemetry using industry-standard tools to identify malicious, suspicious, or anomalous behavior
- Lead or participate in tactical response efforts to investigate and address identified security risks across technical environments
- Develop and refine SIEM security rules and security use cases aligned with the MITRE ATT&CK Framework
- Collaborate with architects, risk professionals, infrastructure teams, and security specialists to build and integrate detective, preventive, and corrective security controls
- Improve incident response and security operations through documentation, automation, lessons learned, Correction of Errors (CoE), and development of more effective security practices
- Assess and analyze tools, systems, and processes in defense of applications, systems, and networks
- Collaborate with Infrastructure and business teams to strengthen defensive capabilities and improve detection and response to security threats
Requirements
What you’ll need- Bachelor's Degree in IT Security, Computer Science, Engineering, or related field
- 3 years of Information Security experience
- Experience analyzing SIEM, network, event, security, and IDS alert logs
- Experience working with MITRE ATT&CK Framework
- Experience with security industry standards and best practices, specifically with interpreting and implementing those standards in a corporate environment
- Scripting language experience (Bash, Python, etc.) with strong working knowledge of automation
- Experience working with compliance and regulatory program requirements
- Experience designing and deploying security solutions
- Knowledge and experience in incident handling, computer forensics, intrusion detection systems, firewalls, antivirus, syslog, and related security technologies
- Strong understanding of SIEM content security rules to detect malicious, suspicious, and/or abnormal events
- Working knowledge of intrusion detection methodologies, network traffic analysis, sensor tuning, and interpreting signatures
- Understanding of AWS services, cloud security principles, CI/CD security, infrastructure-as-code, and data encryption strategies
- Excellent analytical, problem-solving, decision-making, written, and verbal communication skills
- Equivalent relevant experience may substitute for education degree requirements
- Bonus: 8 years of Information Security experience
- Bonus: Experience recommending additional security requirements and safeguards
- Bonus: Experience developing end-user operating manuals and documentation
- Bonus: Familiarity with cloud infrastructure
- Bonus: Relevant security certifications (CISSP, GIAC, ISACA, CCSP, CCSK, AWS, etc.)
- Ability to work a swing shift from 3:00 p.m. to 12:00 a.m., aligned to Eastern or Mountain Time
Benefits
Comp & perks- Eligible for bonuses
- Medical, dental, vision, telehealth and mental healthcare
- Health savings account and flexible spending account
- Basic and voluntary life insurance
- Disability coverage
- Accident, critical illness and hospital indemnity supplemental coverages
- Legal and identity theft coverage
- Retirement savings plan
- Wellbeing program
- Discounted WGU tuition
- Flexible paid time off for rest and relaxation with no need for accrual
- Flexible paid sick time with no need for accrual
- 11 paid holidays
- Other paid leaves, including up to 12 weeks of parental leave