SAP NS2 Sr. Incident Response Analyst -Tier 2
SAPAbout the role
We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
Company Description
SAP is the global market leader for business software and related services, and SAP National Security Services Inc. ® (SAP NS2®) is an independent U.S. subsidiary, offering SAP solutions with specialized levels of security and support to meet the requirements of U.S. national security and critical infrastructure customers.
Must be a U.S. citizen; this position requires access to customer data. SAP NS2 does not offer Visa sponsorships for this role. All internals must have manager’s approval to transfer.
Please note: This is a hybrid position requiring you to be onsite at our Herndon, VA office 3x week
Job Summary
SAP NS2 is seeking an experienced Senior Incident Response Analyst (Tier 2) to support day-to-day security operations and lead complex investigations across endpoint, network, identity, and cloud environments. This role is focused on hands-on incident investigation and response, acting as a key escalation point from Tier 1 and a bridge to Tier 3. The ideal candidate has strong experience in triaging alerts, conducting deep investigations, and driving incidents through full lifecycle response.
Key Responsibilities:
- Lead investigations and responses for security incidents across EDR, SIEM, cloud, and identity platforms.
- Perform advanced triage of escalated alerts to determine scope, impact, and severity.
- Execute containment, eradication, and recovery actions for confirmed incidents.
- Analyze endpoint, log, and cloud telemetry to identify malicious activity and attacker behavior.
- Investigate threats such as account compromise, malware execution, and unauthorized access.
- Support monitoring and response for cloud and identity-based threats.
- Serve as an escalation point for Tier 1 analyst investigations and escalations, providing feedback, mentoring, and guidance to improve analysis quality, documentation, and incident handling.
- Document findings, timelines, and outcomes within case management systems.
- Contributes to the improvement of incident response processes and detection capabilities.
General Qualifications:
- 4–7+ years of experience in Security Operations / Incident Response
- Strong experience with:
- Alert triage and investigation workflows
- Endpoint and log-based investigations
- EDR, SIEM, and cloud security platforms in a SOC or incident response environment
- Solid understanding of:
- Windows systems and common forensic artifacts
- Network traffic and common protocols
- Identity and authentication mechanisms
- Experience investigating cloud-based security events
- Knowledge of common attacker tactics and techniques
- Ability to analyze large datasets and identify malicious patterns
- Basic scripting or automation skills (e.g., PowerShell, Python)
- Strong analytical thinking and ability to work through complex investigations
- Strong communication skills, including writing clear incident summaries
Preferred Qualifications:
- Knowledge of compliance frameworks such as NIST, ISO 27001, or SOC 2
- Security certifications such as GCIA, GCIH, GCFE, CISSP, or similar.
- Experience working in or with highly regulated environments.
- Ability to integrate AI into your process driven workflow(s).
- Background in threat hunting and developing proactive detections in a SOC or incident response environment.
- Familiarity with SAP software and platforms.
- Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related technical discipline (or equivalent practical experience).
Bring out your best
SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ER
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
SEXUAL ASSAULT PREVENTION RESPONSE VICTIM ADVOCATE (SAPR VA)
Army National Guard Units
$100,164/yr
Senior Partner Solution Architect, SAP
Amazon Web Services Argentina S.R.L. - F61
Senior Partner Solution Architect, SAP
Servicios Amazon Web Services Chile Limitada - E39