Jobs and Careers
RS

Cyber Incident Response Analyst, Senior

RSM
USA-IL-Virtual, United States, United StatesRemotefull_timeVerifiedPosted 15 Sept 2025
💰 $190,300/yr($111,200/yr$190,300/yr)

About the role

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.

Cyber Incident Response Senior Analyst

The Cyber Incident Response Senior Analyst will take the lead in responding to cyber incidents, conducting in-depth investigations, and implementing measures to prevent future occurrences. This role demands a comprehensive understanding of cybersecurity threats, strong technical expertise, exceptional problem-solving abilities, and the capacity to perform well under pressure. The ideal candidate will possess strong analytical skills, excellent communication abilities, and a passion for automation and orchestration. In addition, you will mentor junior team members, help develop incident response processes and documentation and drive continuous improvement in incident response practices. May require on-call rotation and after-hours support during critical incidents.

ESSENTIAL DUTIES:

  • Incident Response & Investigation: Lead investigations into security incidents, analyzing evidence to identify the source, impact, and scope of threats. Develop and execute strategies for containment, eradication, and recovery. Prioritize incidents based on their potential impact and assist with decision-making during critical situations. Produce detailed post-incident reports, including recommendations for prevention and lessons learned.
     
  • Threat Intelligence & Analysis: Monitor and analyze real-time threat intelligence feeds, identifying patterns and proactively detecting emerging threats and vulnerabilities. Use threat intelligence to enhance detection capabilities and strengthen defensive measures.
     
  • Cross-Department Collaboration: Work closely with IT, legal, and other departments to address cybersecurity concerns. Provide technical guidance and support during incident recovery and prevention. Collaborate across teams to implement solutions that prevent future incidents.
     
  • Incident Response Planning & Documentation: Assist in developing, reviewing, and continuously improving incident response policies, playbooks, and procedures. Ensure all incidents are documented in line with industry best practices and legal requirements.
     
  • Mentoring & Leadership: Provide guidance, training, and mentorship to junior analysts and team members. Promote a collaborative and knowledge-sharing environment within the team.
     
  • Other duties as assigned.

QUALIFICATIONS:

Required:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Relevant certifications such as CISSP, CISM, GCIH, CEH, GCFA, or GCIH.

Preferred:

  • Master's degree in Information Security or a related field.

TECHNICAL/SOFT SKILLS

Required:

  • Problem Solving: Strong critical and analytical thinking, especially in high-pressure situations.
  • Collaboration: Team player with a collaborative mindset, eager to share knowledge and learn from others.
  • Attention to Detail: Thorough in documenting incidents and tracking resolutions.
  • Adaptability: Ability to adjust strategies in response to a rapidly evolving threat landscape.
  • Forensic Expertise: Proficient in forensic tools and techniques such as Axiom Cyber, FTK, or similar.
  • Security Technologies: Solid understanding of SIEM, firewalls, IDS/IPS, endpoint detection and response (EDR), and forensic analysis tools.

Preferred:

  • In-depth knowledge of industry standards and frameworks (e.g., NIST, MITRE ATT&CK, SANS).
  • Strong understanding of network protocols and operating systems (Windows, Linux). Experience with cloud security and incident response in cloud environments.
  • Experience with advanced persistent threats (APT) and large-scale cyberattack investigations.
  • Familiarity with security automation and orchestration tools.
  • Knowledge of scripting languages such as Python or PowerShell.
  • Experience with SIEM tools such as Sentinel, Splunk, ArcSight, or QRadar.
  • Business Intelligence and Analytics
  • Python or other methods to automate and orchestrate
  • Applied neural network solutions

EXPERIENCE<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

RSM

View company profile →