Get the latest updates on AI-powered hiring, career growth, and technical deep-dives delivered to your inbox.
First American Bank
The Technical Incident Response Analyst is responsible for monitoring, analyzing, and responding to cybersecurity alerts and incidents across enterprise infrastructure and security platforms.
This role serves as a primary investigator for security events, ensuring timely detection, containment, remediation, documentation, and escalation of incidents in alignment with established incident response playbooks, regulatory requirements, and internal controls.
The position combines real‑time alert monitoring, technical investigation, firewall and configuration change validation, and execution of defined recurring operational tasks to maintain a strong security posture across the organization.DUTIES & RESPONSIBILITESMonitor and respond to cybersecurity alerts generated from SIEM provider dashboards and security monitoring platforms.
Investigate, remediate, and document security incidents reported through automated alerts, tickets, emails, phone calls, or external SOC notifications.
Act as the primary investigator for potential security incidents identified by SOC analysts or monitoring tools.
Follow documented incident response playbooks while exercising sound judgment to contain and remediate threats.
Investigate phishing emails, user‑reported security concerns, and potential attempts at fraud or financial loss.
Review authentication, endpoint, network, and application activity for anomalous or malicious behavior.
Analyze firewall logs, IDS alerts, intrusion prevention activity, anti‑malware events, server logs, and application logs.
Monitor intrusion detection systems, for indicators of compromise or suspicious activity.
Correlate data across SIEM, IDS, endpoint, and firewall platforms to support incident investigations.
Perform log reviews using standardized incident response and log review templates.
Perform reconciliation of firewall rule and configuration changes.
Validate that all changes are authorized, approved, and compliant with change management and security policies.
Identify unauthorized or out‑of‑policy changes and escalate violations as requiredExecute daily, weekly, and periodic tasks defined in the Incident Response recurring task schedule, including: Reviewing Microsoft Defender security incidents and assigning or resolving alerts, Reviewing external SOC (e.g., Proficio) incident tickets to ensure proper closure, Reviewing SIEM and Kibana dashboards for authentication failures and other abnormal activity, and Validating completion and documenting evidence through screenshots and reports.
Document incident activity, evidence, analysis, and remediation actions in an audit‑ready manner.
Communicate incident status clearly to Information Security leadership, infrastructure teams, and management.
Provide incident reporting suitable for internal audit, regulatory examination, and compliance reviews.
Track incidents end‑to‑end to ensure timely closure and proper documentation.
Participate in SOC and security working group sessions to improve detection rules and reduce false positives.
Review and update automated alerts and incident response playbooks for accuracy and effectiveness.
Collaborate with networking, systems, endpoint, and application teams during investigations.
First American Bank is an
(Disabled/Veterans).
First American Bank will not sponsor applicants for work visas.
Verified Listing
This role has been verified for authenticity, market-rate compensation, and remote eligibility.