Senior Incident Response Analyst (R-19347)
Summary
Lead advanced threat detection and incident response, investigating high-severity security alerts using SIEM, EDR, and cloud tools while mentoring junior analysts.
We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This role is responsible for handling complex security incidents, guiding junior analysts, improving detection capabilities, and strengthening our overall security posture.
The Senior Incident Response Analyst brings deep technical expertise, strong analytical thinking, and a proactive mindset toward defending the enterprise.
Key Responsibilities:
- Lead high‑fidelity alert investigations, performing deep technical analysis to rapidly identify, contain, and remediate threats.
- Own complex incident investigations, driving technically precise conclusions and elevating the organization’s detection and response maturity.
- Champion process development, identifying gaps, designing scalable workflows, and implementing improvements that strengthen the Incident Response program.
- Create and refine technical playbooks, documentation, and response guides, ensuring clarity, consistency, and operational excellence.
- Mentor and uplift junior analysts, providing guidance, coaching, and training to build a high-performing team.
- Serve as the escalation point for critical and ambiguous cases, applying advanced threat analysis and sound judgment under pressure.
- Collaborate with engineering, IT, Legal, HR, and business partners to resolve incidents holistically and drive enterprise-wide security improvements.
- Apply strong analytical and technical expertise to continuously enhance SOC processes, workflows, and response capabilities.
- Contribute to the evolution of our detection landscape, partnering with detection engineering to improve log ingestion, alert logic, and signal quality.
- Assess and mitigate AI‑related security risks, including model misuse, prompt injection, data leakage, and emerging automation attack vectors.
- Participate in an on‑call rotation, serving as a trusted responder for high‑severity incidents.
Skills Needed:
-
At least 1 SANS/GIAC Certification (GCIH, GREM, GCFA preferred)
-
Strong Hands-on experience with
-
SIEM Platforms (Splunk, Microsoft sentinel, etc)
-
EDR Tools (CrowdStrike, Carbon Black)
-
Cloud environments (Azure, AWS, GCP, AliCloud)
-
Network log analysis (Netflows and PCAP files)
-
Deep understanding of:
-
Mitre ATT&CK framework
-
Malware behavior and exploitation techniques
-
Windows, Linux, and macOS internals
-
Script analysis (Javascript, VBscript, powershell, python)
-
Malicious binary analysis (Windows, MacOS, Linux)
-
Clear communication rooted in technical competence
-
Confidence discussing findings with peers and senior management
Education:
As published by lever
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, GitHub URL, Portfolio URL, Twitter URL, Other website
- Are you a current or previous employee of Dun & Bradstreet? choose one
- Do you have a family member or relative who is currently employed by Dun & Bradstreet? choose one
- If you have a family member or relative currently employed by Dun & Bradstreet, please list their name(s): optional
- Did a current Dun & Bradstreet employee influence you to apply or refer you to the company/role? choose one
- If you were referred by a Dun & Bradstreet employee, please list their name: optional
- Are you 18 or older? choose one
- Are you eligible to work in the USA? choose one
- Will you require any type of sponsorship now or in the future? choose one
- Legal First Name, if an offer is extended:
- Legal Last Name, if an offer is extended:
- Street address, City, and Zip code, if an offer is extended:
- If hired, from which US state or territory would you work? choose one · optional
- I am willing and able to work a hybrid schedule at the office location listed in this job posting. choose one
- This hybrid role requires being in the office on a regular basis. What is your ideal number of days onsite? choose one
- Are you a current or former employee of KPMG? choose one
- If you have been employed by KPMG, please share your functional area(s) and approximate dates of employment. optional
- Most recent formal education: choose one
- Optional: If you have relevant certification(s) and/or licensure(s), you may list them here. optional
- Please provide your salary expectations: