Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

TEKsystems

Senior Incident and Response Engineer

Career Insights for Incident Analyst / Responder

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on California data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

An Incident Analyst or Responder investigates an IT-related incident: an unplanned interruption to a service, a reduction in the quality of a service, or an event that has not yet impacted the service to the customer. Works to restore a normal service operation as quickly as possible and to minimize the impact on business operations.

$127,233 / year median in California

+13% projected growth

Explore Career

Job Description

Job Summary The Senior Incident Response professional leads complex, high‑impact cybersecurity incident investigations and acts as the technical and operational authority during major incidents. This role owns incident execution end‑to‑end while driving response maturity through tooling, playbooks, and cross‑functional leadership. Key Responsibilities Lead and coordinate response for high‑severity and enterprise‑wide security incidents, including containment, eradication, and recovery. Serve as the senior technical decision‑maker during active incidents, advising on risk, tradeoffs, and escalation paths. Perform advanced investigations to determine root cause, attacker behavior, scope of compromise, and business impact. Coordinate response activities across Security Operations, IT, Cloud, Legal, Privacy, Communications, and executive stakeholders. Execute and continuously improve incident response plans, playbooks, and escalation procedures. Oversee evidence collection and preservation to support legal, compliance, and regulatory requirements. Lead post‑incident reviews and root cause analysis, translating findings into actionable improvements. Mentor and act as escalation point for junior IR analysts and on‑call responders. Partner with detection engineering and security engineering teams to improve alert fidelity, response automation, and tooling effectiveness. Common Technologies & Tooling Detection, Monitoring & SIEM SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic / OpenSearch) Endpoint Detection & Response (EDR/XDR) platforms Security monitoring and alerting systems integrated with SOC workflows Endpoint & Identity Investigation Endpoint telemetry and advanced hunting tools Identity and authentication logging (e.g., sign‑in logs, audit logs) Privileged access and identity governance platforms Cloud & SaaS Security Cloud security logging and monitoring (AWS, Azure, GCP environments) SaaS audit logs and security controls (email, collaboration, identity platforms) Cloud security posture and workload protection tools Network & Email Security Network traffic analysis and firewall logs Secure email gateways and phishing investigation tools DNS, proxy, and web gateway telemetry Incident Response & Case Management Incident tracking and case management platforms (e.g., ServiceNow, SOAR tools) Automated response and orchestration workflows Major incident management and escalation tooling Forensics & Analysis Digital forensics and evidence collection tools Malware analysis and IOC enrichment platforms Log analysis, timeline reconstruction, and correlation tooling Automation & Scripting Scripting for investigation and response automation (PowerShell, Python) API‑driven integrations across security platforms Custom tooling to streamline repetitive IR tasks Collaboration & Reporting Secure collaboration tools for incident coordination Executive and technical reporting dashboards Documentation and knowledge management platforms
Pay:
$65.00 - $70.00 per hour
Work Location:
In person