Incident Response Analyst
Listed on 2026-04-23
-
IT/Tech
Cybersecurity, Information Security
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information across enterprises, governments, and consumers. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend harnesses AI to protect organizations and individuals across clouds, networks, devices, and endpoints. The Trend Vision One™ enterprise cybersecurity platform accelerates proactive security outcomes by predicting and preventing threats across the entire digital estate and environments like AWS, Google, Microsoft, and NVIDIA.
Proactive security starts here.
This is a hybrid role with a minimum in‑office requirement of 3 days per week in the Las Colinas, Texas office located at 225 E John W Carpenter Fwy #1500, Irving, TX 75062.
Position SummaryAs an Incident Response Analyst, you'll investigate sophisticated security breaches, lead containment under pressure and become the person enterprise customers trust when everything is on the line. You'll be the critical link between Trend
AI Vision One™ and customer recovery, operating across global threat operations where seconds matter, relationships are everything and AI amplifies what you're already capable of.
- Forensic Investigation:
Conduct root cause analysis of security breaches; determine attack vectors, scope and business impact with precision and accountability. - Incident Response:
Lead containment and threat eradication using Trend
AI Vision One™, coordinating across internal teams and customer stakeholders from first alert to resolution. - Threat Analysis & Detection:
Analyze malware and threat components; develop and refine detection rules; generate threat intelligence and IoCs. - Customer Reporting:
Create executive‑ready incident reports; deliver briefings to stakeholders; recommend security improvements. - Proactive Threat Operations:
Hunt for advanced threat indicators across customer networks; improve detection logic and fidelity. - AI Orchestration:
Contribute to automation and AI initiatives that compress response times, reduce analyst burden, and sharpen the overall quality of MDR delivery.
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field
- 3+ years in security operations with demonstrated expertise in:
- Incident response and forensics
- Malware analysis and threat investigation
- SOC operations or security monitoring
- AI in Practice:
Familiarity with how AI and automation are reshaping incident response workflows, from alert triage to forensic analysis. Curiosity about where it's going matters as much as where you are today. - OS & Network Forensics:
Advanced Windows and Linux forensics (registry, event logs, artifacts, file system analysis). - Forensics Tools: SIFT Workstation, WinPMEM, dd/dclfdd, Autopsy, Volatility Framework, FTK Imagerm Wireshark, Bro/SiLK, Netflow, tcpdump – or similar OS/Network Tools.
- Log Analysis & Correlation: SIEM platforms, syslog analysis, event correlation procedures
- Malware analysis:
Static and dynamic analysis techniques. - Threat Intelligence:
Understand threat actor TTPs and MITRE ATT&CK framework alignment; contribute to organizational threat intelligence. Leverage threat intelligence platforms. - Trend
AI familiarity:
Working knowledge of the Vision One platform or equivalent threat intelligence/XDR platforms.
- GCIH (GIAC Certified Incident Handler).
- GCFA / GCFE (GIAC Certified Forensic Analyst / Examiner).
- CISSP or OSCP.
- Strong written and verbal communication, ability to translate complex forensic findings for technical and executive audiences.
- Self‑directed learner with aptitude for rapidly mastering new tools and threat landscapes.
- Comfortable working under pressure; thrives in fast‑paced, high‑stakes environments.
- Ability to work 24/7 rotating shifts, including nights, weekends, and holidays.
- Willing to travel when required.
- Strong analytical and problem‑solving skills with ability to work effectively in a global team environment.
- Comfortable speaking to customer via e‑mail, chat and phone.
- Comprehensive…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).