Incident Response Analyst

Warrenville, IL, US • Posted 1 day ago • Updated 5 hours ago
Full Time
On-site
$47 - $60 per hour
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Data Loss Prevention
  • Malware Analysis
  • Network
  • Cyber Security
  • Incident Management
  • System On A Chip
  • SIEM
  • Research
  • Nessus
  • Qualys
  • DLP
  • Microsoft
  • ITIL
  • ServiceNow
  • Security Operations
  • Workflow
  • Management
  • Communication
  • Health Care
  • Medical Devices
  • Vulnerability Management
  • Scripting
  • IT Service Management
  • Innovation
  • Collaboration
  • Recruiting
  • Artificial Intelligence
  • Privacy
  • Insurance
  • Finance
  • Professional Development
  • Training
  • Leadership
  • CompTIA
  • Customer Service
  • Career Counseling
  • SAP BASIS
  • Law
  • ADA
  • Apex
  • Oracle Application Express

Summary

Job#: 3047633

Job Description:
Incident Response Analyst

Location: Remote

Pay Rate: $55-60/hr based on experience

Duration: 6+ months contract

Role Overview

An Incident Response Analyst is sought to join a co-sourced cyber operations environment. In this setting, an external managed security service provider handles primary SOC monitoring, and the internal team manages escalated investigations through to remediation. This position will provide operational coverage, investigate security events, coordinate response activities across technical teams, and strengthen vulnerability management and data loss prevention capabilities.

Key Responsibilities
  • Receive escalated alerts and tickets from the SOC, initiate investigations, determine scope and impact, and manage incidents through remediation and closure.
  • Investigate malware, phishing, unexpected network connections, and other security events by reviewing SIEM logs, endpoint telemetry, affected assets, and impacted users.
  • Coordinate with infrastructure, application, clinical technology, privacy, and other internal teams to contain threats and execute corrective actions.
  • Participate in the rotating SOC alert and on-call coverage model.
  • Execute and improve established incident response runbooks and support the continued development of operational procedures.
  • Use packet capture data at network egress points to trace threats and support response actions that require internal access or credentials.
  • Create, tune, and maintain custom detections and response scripts within the co-sourced security model.
  • Support vulnerability management operations by researching newly disclosed CVEs, identifying affected assets, validating exposure, and assisting in the prioritization of remediation.
  • Account for systems that may not appear in standard vulnerability tools, such as medical and other specialized devices, when assessing exposure.
  • Review DLP alerts and policies, investigate potential data exposure events, and coordinate escalation to the privacy team when events may involve PHI or patient impact.
  • Document investigations, response actions, findings, and remediation activities in ServiceNow in alignment with ITIL-based processes.
Required Qualifications
  • Approximately 5-10 years of relevant cybersecurity operations experience, with hands-on incident response and SOC escalation responsibility.
  • Demonstrated ability to independently investigate alerts, build a complete picture from multiple data sources, and coordinate an incident through remediation.
  • Experience reading and interpreting SIEM logs; Sumo Logic experience is preferred.
  • Hands-on experience with CrowdStrike for endpoint investigation, threat response, exposure research, and detection or response scripting.
  • A solid foundation in vulnerability management, including practical experience assessing CVEs, identifying affected assets, interpreting scanner findings, and prioritizing remediation.
  • Experience with vulnerability management platforms such as Tenable Nessus and Qualys; direct Tenable experience is preferred.
  • Experience investigating DLP events and understanding how DLP policies trigger; Microsoft Purview experience is preferred.
  • Working knowledge of ITIL practices and experience using ServiceNow for security operations workflows and ticket management.
  • Clear communication, sound judgment, and the ability to work effectively across technical and business teams during active investigations.
Preferred Qualifications
  • Experience in a healthcare environment or with security events involving PHI, medical devices, or patient-impacting systems.
  • Deep vulnerability management expertise and the ability to improve prioritization practices, recommend better operating approaches, and share knowledge with other team members.
  • Experience working in an operational security function where workload shifts based on active incidents and emerging threats.
  • Experience authoring custom detections and developing scripts that automate or accelerate threat response.


Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at

Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.

Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.

UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: apexsan
  • Position Id: BHJOB2374_3047633
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Arlington Heights, Illinois

Today

Easy Apply

Contract, Third Party

Homewood, Illinois

Today

Full-time

USD 90,000.00 - 115,000.00 per year

Remote or Chicago, Illinois

Today

Contract

USD60 - USD65

Remote or New Jersey

9d ago

Full-time

USD 105,000.00 - 133,000.00 per year

Search all similar jobs