Senior Incident Response Analyst
OpenLoop
United States
The Role
The role sits within a dedicated DFIR function, requiring the analyst to own tier-1 and tier-2 incidents from detection validation through post-incident review. Day-to-day responsibilities include host, memory, network, cloud and identity forensic investigations, EDR and SIEM-driven triage, playbook authoring, on-call rotation participation, and executive-level incident reporting.
Skills & Experience
Candidates need six to eight years of hands-on security experience, the majority in IR and digital forensics. Required tooling includes EDR platforms (CrowdStrike, Defender, SentinelOne), SIEM query authoring, and forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK or X-Ways. Scripting in Python or PowerShell and MITRE ATT&CK fluency are essential. AWS cloud IR and identity-centric investigations are preferred.
Who It Suits
This role suits an experienced, self-directed individual contributor who has led real incidents under ambiguity and can produce both rigorous technical timelines and clear executive summaries. Those with a healthcare or regulated-sector background will find the PHI-handling and legal evidence discipline requirements particularly relevant.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Learn More/Apply





