Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Information Security Operations Analyst / Incident Response & Forensics Speci image - Rise Careers
Job details

Information Security Operations Analyst / Incident Response & Forensics Speci

 

Information Security Operations Analyst / Incident Response & Forensics Specialist

Madison, Wisconsin, HYBRID REMOTE (Flexible work from home days available)

 

 $110,000 to $140,000 

Experience 5+ Years Required

The Information Security Operations Analyst / Incident Response & Forensics Specialist is a critical, hands-on role responsible for operating and maturing the organization's cybersecurity defense, detection, and response capabilities. This specialist serves as a high-level escalation point, bridging the gap between proactive threat intelligence and reactive incident management.

The primary focus is two-fold: leading the execution of the full incident response lifecycle (detection, containment, eradication, and post-incident analysis) and conducting comprehensive digital forensic investigations for security breaches, eDiscovery requests, and internal investigations (HR/Legal). The role requires deep technical proficiency, a strong analytical mindset, and the ability to operate under pressure while maintaining strict standards for evidence integrity and regulatory compliance.

Key Responsibilities

I. Incident Response & Threat Hunting (The Core Focus)

  • Lead Incident Response: Serve as the primary technical lead in responding to escalated and complex security incidents (e.g., advanced persistent threats, nation-state attacks, significant data breaches, and sophisticated phishing campaigns).
  • 24/7 Coordination: Coordinate and ensure the timely prioritization, triage, and response to cybersecurity alerts and incidents across a 24/7 operations environment.
  • Containment and Eradication: Execute highly technical containment strategies to limit the scope of an attack and lead the root cause analysis and eradication phase to ensure complete removal of adversary presence.
  • Threat Intelligence Integration: Continuously ingest, review, and analyze incoming threat intelligence feeds, applying best practices to inform proactive threat hunting campaigns using the MITRE ATT&CK framework.
  • Post-Incident Analysis: Create detailed, high-quality incident reports and after-action reviews to document findings, articulate technical concepts to non-technical stakeholders (including leadership), and identify opportunities for control enhancement.

II. Digital Forensics & Investigations

  • Forensic Investigations: Conduct advanced, forensically sound data collections, imaging, and analysis of compromised systems, volatile memory, cloud environments, and network data in support of active security incidents.
  • eDiscovery & Legal Support: Execute eDiscovery requests and support complex internal investigations led by Legal and Human Resources, ensuring strict maintenance of the chain of custody and evidence integrity in alignment with regulatory and organizational standards.
  • Tool Expertise: Utilize and maintain state-of-the-art forensic tools, such as Magnet Forensics Axiom Cyber, for deep-dive investigations.

III. Security Operations & Program Management

  • Tool Optimization: Maintain and optimize core security technologies, including SIEM (Splunk)Extended Detection and Response (XDR) solutions (e.g., Microsoft Defender), and vulnerability scanners, specifically focusing on alert tuning and detection engineering.
  • Risk Remediation: Review findings from penetration tests, vulnerability scans, and security control assessments to identify weaknesses and provide pragmatic recommendations for remediation and control gap closure.
  • Governance and Awareness: Contribute to the development and ongoing maintenance of security policies, standards, processes, and Incident Response Plans (IRPs). Develop and deliver targeted, high-impact security awareness content for the organization.

Required Experience and Qualifications

Education & Experience

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent combination of education and/or 5 or more years of progressively responsible professional work experience in security operations, incident response, or digital forensics.
  • Experience in a highly regulated industry is strongly preferred (e.g., Financial Services, Insurance).
  • Experience supporting law enforcement or external regulatory body investigations is preferred.

Technical Expertise

  • Deep, hands-on experience executing the full Incident Response lifecycle (preparation, identification, containment, eradication, recovery, and lessons learned).
  • Demonstrated proficiency with Security Information and Event Management (SIEM) tools like Splunk for advanced log analysis and correlation rule creation.
  • Expertise utilizing Endpoint Detection and Response (EDR) / XDR platforms (e.g., Microsoft Defender) for threat hunting and incident containment.
  • Proven experience with digital forensic tools and methodologies, specifically including Magnet Forensics Axiom Cyber or equivalent platforms.
  • In-depth knowledge of attacker Tactics, Techniques, and Procedures (TTPs) and the MITRE ATT&CK framework.
  • Proficiency with scripting languages (e.g., Python, PowerShell) for automation of investigative tasks and data analysis is a plus.

Professional Skills

  • Exceptional verbal and written communication skills with a proven ability to translate complex technical findings into clear, concise reports for both technical and non-technical executive audiences.
  • Demonstrated analytical and critical thinking skills with the ability to manage high-stress, high-impact security incidents.
  • Proven ability to work collaboratively across diverse teams (IT, Legal, HR, Business Units) and provide consulting and mentorship to junior team members.

Average salary estimate

$125000 / YEARLY (est.)
min
max
$110000K
$140000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Posted 18 hours ago

Experienced reimbursement professional needed to manage payer contract modeling, Epic contract builds, and reimbursement analytics at a top-ranked regional hospital in Buckeye Lake, OH.

Knowhirematch Hybrid No location specified
Posted 16 hours ago

Lead the product line for conformal antennas and RF sensors, driving strategy, technical execution, and product transitions for defense and advanced communications.

Photo of the Rise User
Posted 5 hours ago

Peraton seeks a hands-on Systems Engineer/Administrator in Herndon to deploy and maintain Windows servers and virtualized infrastructure in support of national security missions.

Photo of the Rise User
NBCUniversal Hybrid 904 Sylvan Ave, Englewood Cliffs, NEW JERSEY
Posted 16 hours ago

Lead complex insider threat and content protection investigations for Versant/NBCUniversal, building and operating advanced DLP, forensics, and detection programs.

Posted 5 hours ago

Lead enterprise business analysis efforts at AEP to define strategy, standards, and technology portfolio priorities that deliver scalable, high-quality solutions.

Photo of the Rise User
Posted 5 hours ago

Lead IT operations at a hyper-growth AI company, owning incident response, endpoint and identity reliability, and automation to prevent recurring issues.

HSO Hybrid No location specified
Posted 2 hours ago

HSO is hiring a Modern Workplace Engineer to implement and support Microsoft 365, Intune, and Azure AD solutions while leading migrations, automations, and security for client environments.

Photo of the Rise User

Lead the organization's enterprise architecture practice and deliver an EAMS roadmap that aligns technology strategy with business objectives across a distributed US environment.

Photo of the Rise User

Lead Encore’s distributed Service Desk team to deliver exceptional IT support, asset management, and partner engagement across the organization.

Photo of the Rise User

Buzzi Unicem USA is hiring an experienced Oracle EBS HRMS Application Analyst to manage, configure, and support HR and payroll systems across its U.S. operations.

Photo of the Rise User

Experienced SAP SD/Application Lead needed to provide hands-on AMS support and client management for a major retail engagement in Greensboro, NC.

Photo of the Rise User
TAT Technologies Ltd Hybrid No location specified
Posted 12 hours ago

Lead IT operations and strategy for a growing aerospace manufacturer in Charlotte, ensuring secure, compliant, and scalable enterprise systems while managing a small IT team.

Posted 8 hours ago

A leading insurance technology team in Hartford is looking for a Solution Architect with strong P&C experience to lead architecture and delivery of enterprise insurance solutions.

Photo of the Rise User
Posted 6 hours ago

Experienced EHR Solution Architect needed to lead innovative Epic-based integrations and solution design for a remote, client-focused healthcare technology practice.

Photo of the Rise User

Coalfire seeks New Grad Associates for Division Hex to perform penetration tests and security assessments while developing hands-on cybersecurity skills in a client-facing consulting environment.

MATCH
Calculating your matching score...
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
October 13, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!