Skip to content

Open nowPosted 19 days ago

Incident Response Analyst (Mid-Senior Level)

Workable (global search)108,016 open roles

Where
Plano, TX, United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIncident Response Analyst (Mid-Senior Level)Workable (global search) · Plano, TX, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 19 days ago

Workable (global search) median: 7 days open

The posting

Founded in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) is a Toyota group company, that develops IT solutions wherever global businesses operate. Transforming into a technology and mobility company, TTS-US with its 8 TTS affiliates worldwide is establishing a secure and resilient Toyota global value chain. The creative capacity to forge such limitless business opportunities is one of the strengths of Toyota Tsusho Systems.

We are seeking a skilled and experienced Incident Response Analyst to join our collaborative cybersecurity incident response team within the Threat Research, Response & Analysis Center (TRRAC). In this role, you will combine technical expertise in digital forensics and incident response with proactive threat intelligence and hunting activities. You will respond to critical security incidents across the ecosystem, conduct comprehensive forensic investigations, and collaborate closely with the 24/7 SOC and other cybersecurity teams. When not actively responding to incidents, you will contribute to threat hunting, cyber threat intelligence, tooling improvements, and the development of SOPs and training materials—helping to elevate the entire team's capabilities.

Essential Functions:

  • Conduct comprehensive incident response activities following the NIST Cybersecurity Framework across all phases: Initial Detection, Analysis & Validation, Containment, Eradication, Recovery, and Post-Incident Activity.
  • Respond to cyber incidents impacting corporate environments, manufacturing plants, third-parties, dealerships, and RSOC Customers.
  • Perform digital forensic investigations including collection, processing, and analysis of forensic evidence from diverse devices (Windows, Linux, macOS, mobile).
  • Maintain an "Always Be Timelining" (ABT) approach, continuously updating incident timelines as findings are discovered.
  • Support proactive, reactive, and exploratory threat hunting activities across the ecosystem.
  • Analyze emerging cyber threats, attacker TTPs, and track threat actors/groups to anticipate and mitigate potential attacks.
  • Collaborate closely with the 24/7 SOC, Threat Detection Engineering, Vulnerability Management, and Insider Risk Management teams.
  • Prepare and deliver forensic reports, incident communications, and executive updates during active incidents.
  • Participate in weekly on-call rotation schedule for 24/7 incident response coverage.
  • Conduct malware analysis (behavioral and static) using TRRAC Labs' dynamic analysis capabilities.
  • Help develop, refine, and maintain incident response playbooks, SOPs, and training materials to improve team effectiveness.
  • Participate in quarterly tabletop exercises to test incident response workflows and controls.
  • Stay current on emerging threats, attacker techniques, and industry best practices.

Requirements

  • Minimum of 3-5 years of hands-on experience in incident response and digital forensics.
  • Proven ability to act as Incident Commander within a team setting during high-pressure incidents.
  • Strong technical expertise in Windows, Linux, and macOS internals related to monitoring and threat detection.
  • Experience with cloud security incident response and threat mitigation.
  • Skilled in malware analysis (behavioral and static) and basic cryptanalysis.
  • Familiarity with security frameworks and compliance standards (NIST, HIPAA, ISO, OWASP, etc.).
  • Proficient with DFIR tools such as Autopsy, The Sleuth Kit, Volatility, Magnet Axiom, FTK, and others.
  • Competent in scripting languages like Python, PowerShell, and Bash for automation and analysis.
  • Excellent communication skills with the ability to collaborate effectively across technical teams and stakeholders.

Preferred / Bonus Skills

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred)
  • Experience in enterprise, manufacturing, or software industries.
  • Familiarity with SOAR platforms and security automation.
  • Prior experience contributing to or improving incident response programs in a team environment.

Why Join Us?

  • Be part of a skilled, collaborative incident response team where your expertise helps drive collective success.
  • Lead and support incident response efforts alongside experienced peers.
  • Continuously grow your skills through diverse investigations, threat hunting, and team knowledge sharing.
  • Help shape and improve our incident response processes and training.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.