Sr. Incident Response Analyst, Information Security
Lam ResearchAbout the role
The Group You’ll Be A Part Of
The Global Information Systems Group is dedicated to the success of Lam through providing best-in-class and innovative information system solutions and services. Together, we support users globally with data, information, and systems to achieve their business objectives.
The Impact You’ll Make
Lam Research seeks a Sr. Incident Response Analyst to lead technical responses to cybersecurity incidents and drive proactive security monitoring to protect Information Technology (IT) and Operational Technology (OT) infrastructure. This role ensures timely threat identification, containment, and remediation, guiding incidents through the full incident response lifecycle (detection to post-incident analysis). The Analyst will collaborate globally with regional teams, mentor junior responders, and enhance Lam’s security posture through process optimization and automation. The role reports to the Sr. Manager of Incident Response and requires expertise in incident management, threat detection tools, and cross-functional coordination.
What You’ll Do
- Lead Incident Response: Manage complex incidents end-to-end through the lifecycle, from initial detection to post-incident review, ensuring alignment with organizational cybersecurity goals.
- Tier 1 Mentorship: Provide escalation support for Tier 1 CSOC analysts, guiding containment strategies, investigation techniques, and resolution oversight.
- Threat Intelligence: Research emerging threats, vulnerabilities, and exploit trends; apply findings to improve detection and response strategies.
- Process Improvement: Lead automation initiatives, refine standard operating procedures (SOPs), and optimize workflows to reduce manual effort and improve efficiency.
- Global Collaboration: Serve as a liaison between the CSOC and Incident Response Team, ensuring seamless cross-functional communication and information sharing.
- CSOC Support: Contribute to on-call shift rotations and maintain continuous threat monitoring in fast-paced environments.
- Post-Incident Analysis: Lead reviews to document lessons learned, recommend process enhancements, and strengthen overall security resilience.
Who We’re Looking For
Required Qualifications:
- Experience:
- 5+ years in Information Security, with 2+ years in a Security Operations Center (SOC).
- Proven success leading incident response for complex cyber incidents across the full lifecycle.
- Hands-on experience with SIEM platforms (e.g., Azure Sentinel, Splunk, QRadar) and security tools (e.g., Microsoft Defender, Cloud App Security).
- Technical Expertise:
- Proficiency in networking, firewalls, OS security (Windows/Linux), cloud computing, and information security best practices.
- Strong understanding of endpoint security, DFIR, threat hunting, and intrusion detection/prevention.
- Experience with Kusto Query Language (KQL), scripting (Python, PowerShell, Bash), and automation.
- Skills:
- Excellent verbal/written communication to translate technical details for diverse audiences.
- Analytical problem-solving skills with creativity in investigative work.
Preferred Qualifications
- Experience:
- Global enterprise-scale (Fortune 500) or semiconductor manufacturing/high-tech industry exposure.
- Familiarity with OT environments, penetration testing, malware analysis, or reverse engineering.
- Technical Knowledge:
- Advanced proficiency with Microsoft security tools (Defender for Endpoint, Azure Sentinel).
- Cloud expertise (AWS, Azure, or GCP) and familiarity with ATT&CK frameworks or Cyber Kill Chain.
- Certifications:
- At least one of: Security+, CISSP, SANS GCIH or GMON, CEH, OSCP, or Azure Security Engineer.
- Tools:
- Experience with memory forensics tools (e.g.,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s