← All jobs · More in this country

CSIRT Analyst

CTG

Buffalo, NY

Mid · Full-time · $120,000.00/yr - $145,000.00/yr

The Role

This position sits within a CSIRT team, handling escalated security incidents and conducting digital forensics and incident response investigations. Day-to-day responsibilities span threat hunting, compromise assessments, threat intelligence collection, detection engineering in SIEM and XDR platforms, purple teaming exercises, playbook development in SOAR, and participation in an on-call incident response rota.

Skills & Experience

Candidates need three to five years of relevant experience, with strong hands-on skills in disk, memory, and log acquisition, artifact analysis, and post-incident reporting. Familiarity with EDR tools such as CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne, as well as NDR platforms including Vectra and Darktrace, is expected. A relevant degree or equivalent practical experience is required.

Who It Suits

This role suits a proactive, defence-minded analyst who is equally comfortable leading forensic investigations and collaborating across red and blue teams. Someone who thrives in a fast-paced MDR environment, enjoys building processes and documentation, and takes genuine satisfaction in protecting organisations actively under attack will feel at home here.

Typical advertised salary for Incident Response roles in United States: $125,000–$179,000 (median $149,000 — from 108 recent listings analysed by Forensic Focus).

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-08-03