Company
Cybersecurity
SeniorIncidentResponseSpecialist,CyberSecurity
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Incident Response Specialist, Cyber Security. Skills: Incident Response, Cyber Security, SIEM platform. Monitor security alerts. Investigate security alerts”
What You'll Achieve.
Ensure timely response; Maintain cyber resilience; Align with MTTD goals; Align with MTTR goals
Industry & Context.
Root cause analysis; Troubleshooting
What They're Looking For.
Must Have
Perform deep-dive investigations, Conduct threat hunting, Support incident response reporting, Manage continuous logs availability
Nice to Have
MITRE ATT&CK mapping, Automation opportunities
What You'll Do.
Monitor security alerts
Investigate security alerts
Analyze security incidents
Contain security incidents
Escalate security incidents
Suggest new detections
Create incident documentation
Maintain incident documentation
Create incident reports
Maintain incident reports
Create lessons learned
Maintain lessons learned
Support playbook execution
Perform root cause analysis
Provide use case insights
Escalate confirmed incidents
Participate in reviews
Validate security events
Identify legitimate threats
Investigate malware incidents
Investigate phishing incidents
Investigate insider threats
Investigate cloud breaches
Assist in rule creation
Assist in rule tuning
Improve detection quality
Contribute to automation
Participate in training
Participate in simulations
Participate in exercises
Manage log availability
How You'll Work.
Team & Collaboration
Collaborate with IT; Collaborate with network; Collaborate with application teams; Collaborate with MSSP; Collaborate with CSIRT; Collaborate with IT infrastructure
Full Job Description
Role Mission The Senior Analyst - Cyber Security Incident Response is responsible for monitoring, detecting, and analyzing cybersecurity incidents through the Security Operations Centre (SOC) platform. The role supports the end-to-end incident lifecycle — including triage, investigation, containment, and closure — ensuring timely response to security events and maintaining cyber resilience. This role acts as the Level 2 (L2) Incident Responder, bridging SOC analysts and Incident Response management by performing deep technical analysis and coordinating with internal teams for resolution. Accountabilities: - Perform end-to-end incident triage and investigation of security alerts escalated from L1 SOC analysts. - Ensure timely incident analysis, containment, and escalation aligned with MTTD and MTTR goals. - Support the SIEM platform (Elastic Stack) by fine-tuning existing rules and suggesting new detections. - Conduct log analysis and correlation across multiple data sources (network, endpoint, and cloud). - Create and maintain incident documentation, reports, and lessons learned. - Support incident response playbook execution during containment and recovery phases. - Collaborate with IT, network, and application teams for incident remediation and root cause analysis. - Provide insights for use case improvements and participate in use case validation and testing. - Escalate confirmed incidents to CSIRT / Assistant Manager - Incident Response for further action. - Participate in post-incident reviews, contributing to process and detection improvements. - Monitor alerts generated from the SOC/SIEM and perform initial to intermediate-level investigations. - Review and validate security events from multiple log sources and identify legitimate threats. - Perform deep-dive investigations for incidents involving malware, phishing, insider threats, and cloud breaches. - Assist in detection rule creation and tuning under the guidance of senior incident responders. - Use frame
Applying for this Senior Incident Response Specialist, Cyber Security role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.