Incident Responder
Listed on 2026-08-14
-
IT/Tech
Cybersecurity
Incident Responder
Location:
Long Island City, NY, US, 11101 Salt Lake City, UT, US, 84121 Washington, DC, US, 20005 Req Category:
Information Technology
Position Summary:
At Jet Blue, cyber security operates across a complex IT environment, encompassing traditional data centers, Software as a Service (SaaS) services, multiple cloud providers, e-commerce platforms, and a diverse end-user environment. We are seeking an experienced Incident Response Analyst to support the Cyber Security Incident Response function through escalated alert triage, investigation, containment support, and response activities. The ideal candidate has hands-on experience analyzing security telemetry across multiple tools, can work independently through ambiguous investigations, and can clearly document findings, risk, and recommended next steps.
- Monitor, triage, and investigate escalated security alerts and cases from internal tools, managed security providers, and other reporting channels.
- Analyze telemetry from multiple sources, including SIEM, endpoint detection and response tools, identity platforms, email security tools, cloud platforms, network devices, CDNs, and WAF technologies.
- Investigate suspicious or malicious activity, including phishing, malware, suspicious authentication, anomalous network activity, unauthorized access, endpoint compromise, and potential data exposure.
- Perform investigative scoping to identify affected users, hosts, accounts, applications, indicators, timelines, and potential business impact.
- Support incident response activities, including evidence gathering, containment support, remediation validation, and communication of technical findings.
- Execute approved response actions in accordance with established procedures, including account, endpoint, email, URL/domain, or indicator-based response steps.
- Create clear, defensible case notes and incident documentation, including observed activity, entities involved, timeframe, scope, conclusion, and remediation or follow-up actions.
- Collaborate with Threat Intelligence, Detection Engineering, Security Monitoring, IT Operations, Identity, Infrastructure, application teams, and other stakeholders during investigations.
- Identify detection gaps, logging gaps, process breakdowns, recurring alert patterns, and opportunities to improve security monitoring and response capabilities.
- Build or support dashboards, searches, playbooks, reports, process documentation, and other operational improvements that improve incident response efficiency and quality.
- Provide guidance and support to less experienced analysts during triage, investigation, documentation, and escalation activities.
Experience and Qualifications:
Bachelor's Degree in Cyber Security, Computer Science, Information Technology, or other relevant discipline; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience on a SOC, Incident Response, Threat Detection, or cyber security operations team. Three (3) years of hands-on experience performing alert triage, security investigations, incident response support, or similar technical security operations work.
Demonstrated ability to analyze disparate data sources such as network logs, endpoint activity, authentication logs, cloud logs, email data, and SIEM events to assess suspicious or malicious activity. Experience investigating common security events such as phishing, malware, suspicious logins, anomalous network traffic, unauthorized access, suspicious process execution, or endpoint compromise. Ability to assess risk, determine likely impact, scope activity, and make appropriate escalation recommendations based on available evidence.
Strong problem-solving and analytical skills, including the ability to work through ambiguous or incomplete information. Ability to demonstrate a high level of critical thinking and sound judgment during technical investigations. Ability to pass a live skills demonstration or technical interview on-site with Jet Blue Crew Members. Experience with scripting, querying, or automation languages such as Power Shell, Python, KQL, SPL, or similar technologies.
Ability to manage multiple cases and priorities in a fast-paced operational environment. Excellent written and verbal communication skills, including the ability to clearly document investigations and summarize technical findings. Available and willing to participate in periodic on-call duties and off-hours Incident Response as required. Available for occasional overnight travel (10%). Must pass a ten (10) year background check and pre-employment drug test.
Must be legally eligible to work in the country in which the position is located. Authorization to work in the United States is required. This position is not eligible for visa sponsorship. Must be eligible to hold a US government security clearance if Jet Blue deems it relevant to the role.
Experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).