A regulated financial services organization is seeking a mid-level Cybersecurity Incident Response Analyst to support security monitoring, incident coordination, documentation, and process improvement across its cybersecurity function.
This role is well suited for someone who understands incident response workflows, can monitor and triage security alerts, and is highly comfortable maintaining policies, procedures, runbooks, reports, and incident documentation. The position is process-focused and collaborative, with regular coordination across cybersecurity, engineering, architecture, compliance, risk, and operations teams.
RESPONSIBILITIES- Monitor and triage cybersecurity alerts from security platforms and user escalations.
- Document incident response activity clearly and thoroughly.
- Support incident prioritization based on severity, business impact, and scope.
- Maintain and improve incident response procedures, runbooks, and playbooks.
- Coordinate with engineering and architecture teams for deeper technical investigation or remediation.
- Support audit, regulatory, and governance needs through accurate evidence and reporting.
- Contribute to weekly, monthly, and executive-level cyber reporting.
- Participate in post-incident reviews and process improvement efforts.
QUALIFICATIONS- Experience in cybersecurity operations, incident response, SOC, or alert triage.
- Strong documentation, reporting, and procedural writing skills.
- Understanding of cybersecurity policies, controls, and regulatory expectations.
- Ability to communicate effectively with technical and business stakeholders.
- Experience escalating issues to engineering, architecture, or specialist teams.
- Ability to manage multiple priorities in a structured, risk-aware environment.
- Comfort working in a hybrid onsite model in New York City.
- Banking, financial services, or regulated industry experience preferred.
PREFERRED EXPERIENCE- Experience with SIEM, phishing, DLP, threat intelligence, or related security platforms.
- Familiarity with KPIs, KRIs, dashboards, and executive cyber reporting.
- Exposure to audits, evidence collection, or regulatory examinations.
- Experience supporting tabletop exercises or post-incident reviews.