← Back to jobs

Cybersecurity Incident Response Analyst

Skills

awsazurecloudcybersecuritydnsedrfirewallgcpincident investigationlinuxnetwork securitynetworkingnistoracleroot cause analysissiemstakeholder managementtcp ipunix

Description

Cybersecurity Incident Response Analyst

Job Description

Southern Company is seeking a highly experienced Cybersecurity Incident Response Analyst. In this role, you will be the escalation point for cybersecurity incidents and lead response efforts from initial triage through containment, eradication, and remediation. You will assess potential business impacts (including reputational and financial risk), partner with other IT security teams during investigations, and stay current on the evolving threat landscape to improve detection and response capabilities. When not actively responding to incidents, you will proactively update procedures, investigate suspicious cyber events, and make recommendations to improve overall cybersecurity and hygiene.

Responsibilities

  • Take technical ownership of cybersecurity incidents end to end including triage, containment, eradication, and recovery

  • Drive collaboration across stakeholders and technical teams throughout the incident lifecycle, including investigation, containment, mitigation, and remediation; clearly articulate investigative requirements, secure necessary evidence, and identify when additional resources or specialized support are required.

  • Communicate incident status, impact, and next steps to management and key stakeholders

  • Document investigative actions, evidence, and findings

  • Lead post-incident root cause analysis and lessons learned

  • Serve as an escalation point for security monitoring teams by conducting detailed analysis of escalated alerts and security events; leverage telemetry, forensic evidence, and stakeholder input to determine incident severity, scope, and required response actions.

  • Perform endpoint and network forensics using forensically sound acquisition and evidence handling procedures

  • Conduct self-initiated investigations to identify potential breaches or undiscovered threats

  • Track and communicate emerging threats, IOCs, and attacker TTPs from your investigations; recommend and help implement detective/protective improvements

  • Apply lessons learned from incident investigations to improve detection coverage, refine alerting logic, and strengthen SIEM use cases in collaboration with detection engineering and security operations teams.

  • Write technical articles and share knowledge to improve team effectiveness and repeatability

  • Build and maintain strong working relationships across cybersecurity, infrastructure support teams, and business unit operations centers

Qualifications

  • B.S. in Engineering, Computer Science, Cybersecurity, or equivalent

  • 7+ years of cyber security experience, at least 5 in a security operations center investigating endpoint and network security events

  • Advanced proficiency with SIEM, EDR, NDR, SOAR, and other cybersecurity tools

  • Advanced knowledge, experience, and proficiency with several of the following:

    • Operating systems fundaments in Windows and Unix/Linux

    • Networking fundamentals such as TCP/IP, DNS, HTTPS, routing, firewalls

    • Scripting languages

    • Windows/Unix command-line utilities

    • Cloud investigations in AWS, Azure, Google Cloud, and Oracle Cloud

  • Experience drafting and maintaining incident response procedures

  • Experience leading and/or contributing to incident response efforts during major cybersecurity incidents, including cross-functional collaboration and stakeholder communication.

  • Demonstrated ability to build partnerships across security, IT, engineering, operations, and business teams to achieve shared outcomes during incident response activities.

  • Strong collaboration, communication, and stakeholder-management skills with a team-first approach to solving complex problems.

  • Proven ability to influence without authority and drive consensus during high-pressure incidents.

  • Knowledge of common cybersecurity frameworks (e.g., NIST CSF, MITRE ATT&CK, SANS Security Controls)

  • Ability to effectively communicate cybersecurity risks, technical findings, and business impacts across all organizational levels, from technical staff to executive leadership.

  • Demonstrated ownership of incident investigations from discovery through recovery

  • Experience mentoring and training other cyber security professionals

  • Willing and able to obtain a US government security clearance to support threat investigations

  • Desire to develop competency in OT cybersecurity and incident response in industrial environments

Desired Certifications

  • GIAC Certified Incident Handler (GCIH)

  • GIAC Certified Intrusion Analyst (GCIA)

  • GIAC Certified Forensics Examiner (GCFE)

  • Offensive Security Certified Professional (OSCP)

This position falls under the company’s Insider Threat Program and will have access to, and control over sensitive data, systems or assets. Enhanced personnel screening, which includes a background review, drug screen and psychological assessment, will be required if you are selected for this position

Get similar jobs in United States by email

We'll email you when new jobs similar to this one appear.

Similar jobs

Explore more Cybersecurity Incident Response Analyst jobs in United States.

Finding similar jobs…