Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
T
TEKsystems
Senior Incident and Response Engineer
Career Insights for Incident Analyst / Responder
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An Incident Analyst or Responder investigates an IT-related incident: an unplanned interruption to a service, a reduction in the quality of a service, or an event that has not yet impacted the service to the customer. Works to restore a normal service operation as quickly as possible and to minimize the impact on business operations.
$127,233 / year median in California
+13% projected growth
Job Description
Job Summary The Senior Incident Response professional leads complex, high‑impact cybersecurity incident investigations and acts as the technical and operational authority during major incidents. This role owns incident execution end‑to‑end while driving response maturity through tooling, playbooks, and cross‑functional leadership. Key Responsibilities Lead and coordinate response for high‑severity and enterprise‑wide security incidents, including containment, eradication, and recovery. Serve as the senior technical decision‑maker during active incidents, advising on risk, tradeoffs, and escalation paths. Perform advanced investigations to determine root cause, attacker behavior, scope of compromise, and business impact. Coordinate response activities across Security Operations, IT, Cloud, Legal, Privacy, Communications, and executive stakeholders. Execute and continuously improve incident response plans, playbooks, and escalation procedures. Oversee evidence collection and preservation to support legal, compliance, and regulatory requirements. Lead post‑incident reviews and root cause analysis, translating findings into actionable improvements. Mentor and act as escalation point for junior IR analysts and on‑call responders. Partner with detection engineering and security engineering teams to improve alert fidelity, response automation, and tooling effectiveness. Common Technologies & Tooling Detection, Monitoring & SIEM SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic / OpenSearch) Endpoint Detection & Response (EDR/XDR) platforms Security monitoring and alerting systems integrated with SOC workflows Endpoint & Identity Investigation Endpoint telemetry and advanced hunting tools Identity and authentication logging (e.g., sign‑in logs, audit logs) Privileged access and identity governance platforms Cloud & SaaS Security Cloud security logging and monitoring (AWS, Azure, GCP environments) SaaS audit logs and security controls (email, collaboration, identity platforms) Cloud security posture and workload protection tools Network & Email Security Network traffic analysis and firewall logs Secure email gateways and phishing investigation tools DNS, proxy, and web gateway telemetry Incident Response & Case Management Incident tracking and case management platforms (e.g., ServiceNow, SOAR tools) Automated response and orchestration workflows Major incident management and escalation tooling Forensics & Analysis Digital forensics and evidence collection tools Malware analysis and IOC enrichment platforms Log analysis, timeline reconstruction, and correlation tooling Automation & Scripting Scripting for investigation and response automation (PowerShell, Python) API‑driven integrations across security platforms Custom tooling to streamline repetitive IR tasks Collaboration & Reporting Secure collaboration tools for incident coordination Executive and technical reporting dashboards Documentation and knowledge management platforms