Haystack
← Back to Jobs
Technology
AS

Incident Response Analyst

Apex SystemsWarrenville, IL🇺🇸United StatesPosted 8 Sept 2026

Why This Role Stands Out

This hybrid Incident Response Analyst role offers a fantastic opportunity to develop your cybersecurity expertise within a dynamic, co-sourced environment, investigating complex threats and collaborating across teams to strengthen security. If you thrive on problem-solving and want to gain hands-on experience in a critical technology field with competitive hourly compensation, this position is perfect for you. Apply today to join a leading company and advance your career in incident response!

Quick Overview

Salary
$55 - $60/hr
Seniority
Mid Senior
Work mode
Hybrid
Location
Warrenville, IL, United States
Posted
2 days ago
401kServiceNow

Job Description

Job#: 3047633

Job Description:
Incident Response Analyst

Location: Remote

Pay Rate: $55-60/hr based on experience

Duration: 6+ months contract

Role Overview

An Incident Response Analyst is sought to join a co-sourced cyber operations environment. In this setting, an external managed security service provider handles primary SOC monitoring, and the internal team manages escalated investigations through to remediation. This position will provide operational coverage, investigate security events, coordinate response activities across technical teams, and strengthen vulnerability management and data loss prevention capabilities.

Key Responsibilities
  • Receive escalated alerts and tickets from the SOC, initiate investigations, determine scope and impact, and manage incidents through remediation and closure.
  • Investigate malware, phishing, unexpected network connections, and other security events by reviewing SIEM logs, endpoint telemetry, affected assets, and impacted users.
  • Coordinate with infrastructure, application, clinical technology, privacy, and other internal teams to contain threats and execute corrective actions.
  • Participate in the rotating SOC alert and on-call coverage model.
  • Execute and improve established incident response runbooks and support the continued development of operational procedures.
  • Use packet capture data at network egress points to trace threats and support response actions that require internal access or credentials.
  • Create, tune, and maintain custom detections and response scripts within the co-sourced security model.
  • Support vulnerability management operations by researching newly disclosed CVEs, identifying affected assets, validating exposure, and assisting in the prioritization of remediation.
  • Account for systems that may not appear in standard vulnerability tools, such as medical and other specialized devices, when assessing exposure.
  • Review DLP alerts and policies, investigate potential data exposure events, and coordinate escalation to the privacy team when events may involve PHI or patient impact.
  • Document investigations, response actions, findings, and remediation activities in ServiceNow in alignment with ITIL-based processes.
Required Qualifications
  • Approximately 5-10 years of relevant cybersecurity operations experience, with hands-on incident response and SOC escalation responsibility.
  • Demonstrated ability to independently investigate alerts, build a complete picture from multiple data sources, and coordinate an incident through remediation.
  • Experience reading and interpreting SIEM logs; Sumo Logic experience is preferred.
  • Hands-on experience with CrowdStrike for endpoint investigation, threat response, exposure research, and detection or response scripting.
  • A solid foundation in vulnerability management, including practical experience assessing CVEs, identifying affected assets, interpreting scanner findings, and prioritizing remediation.
  • Experience with vulnerability management platforms such as Tenable Nessus and Qualys; direct Tenable experience is preferred.
  • Experience investigating DLP events and understanding how DLP policies trigger; Microsoft Purview experience is preferred.
  • Working knowledge of ITIL practices and experience using ServiceNow for security operations workflows and ticket management.
  • Clear communication, sound judgment, and the ability to work effectively across technical and business teams during active investigations.
Preferred Qualifications
  • Experience in a healthcare environment or with security events involving PHI, medical devices, or patient-impacting systems.
  • Deep vulnerability management expertise and the ability to improve prioritization practices, recommend better operating approaches, and share knowledge with other team members.
  • Experience working in an operational security function where workload shifts based on active incidents and emerging threats.
  • Experience authoring custom detections and developing scripts that automate or accelerate threat response.


Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at

Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.

Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.

UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.

Similar jobs