Demo

Cybersecurity Incident Response Analyst

TalentAlly
Atlanta, GA Full Time
POSTED ON 5/7/2026
AVAILABLE BEFORE 6/7/2026
Job Description

Southern Company is seeking a highly experienced Cybersecurity Incident Response Analyst. In this role, you will be the escalation point for cybersecurity incidents and lead response efforts from initial triage through containment, eradication, and remediation. You will assess potential business impacts (including reputational and financial risk), partner with other IT security teams during investigations, and stay current on the evolving threat landscape to improve detection and response capabilities. When not actively responding to incidents, you will proactively update procedures, investigate suspicious cyber events, and make recommendations to improve overall cybersecurity and hygiene.

Responsibilities

  • Take technical ownership of cybersecurity incidents end to end including triage, containment, eradication, and recovery
  • Coordinate mitigation and remediation tasks with stakeholders and supporting teams; identify when additional resources are needed
  • Communicate incident status, impact, and next steps to management and key stakeholders
  • Document investigative actions, evidence, and findings
  • Lead post-incident root cause analysis and lessons learned
  • Monitor and analyze alerts and telemetry from SIEM and related security tooling; determine severity, priority, and escalation needs
  • Perform endpoint and network forensics using forensically sound acquisition and evidence handling procedures
  • Conduct self-initiated investigations to identify potential breaches or undiscovered threats
  • Track and communicate emerging threats, IOCs, and attacker TTPs from your investigations; recommend and help implement detective/protective improvements
  • Assist in tuning detections by improving alert logic and SIEM use cases
  • Write technical articles and share knowledge to improve team effectiveness and repeatability
  • Build and maintain strong working relationships across cybersecurity, infrastructure support teams, and business unit operations centers

Qualifications

  • B.S. in Engineering, Computer Science, Cybersecurity, or equivalent
  • 7 years of cyber security experience, at least 5 in a security operations center investigating endpoint and network security events
  • Advanced proficiency with SIEM, EDR, NDR, SOAR, and other cybersecurity tools
  • Advanced knowledge, experience, and proficiency with several of the following:
    • Operating systems fundaments in Windows and Unix/Linux
    • Networking fundamentals such as TCP/IP, DNS, HTTPS, routing, firewalls
    • Scripting languages
    • Windows/Unix command-line utilities
    • Cloud investigations in AWS, Azure, Google Cloud, and Oracle Cloud
  • Experience drafting and maintaining incident response/SOC procedures
  • Demonstrable experience on an incident response team during a major cyber incident
  • Knowledge of common cybersecurity frameworks (e.g., NIST CSF, MITRE ATT&CK, SANS Security Controls)
  • Able to explain technical findings and business impact
  • Demonstrated ownership of incident investigations from discovery through recovery
  • Experience mentoring and training other cyber security professionals
  • Willing and able to obtain a US government security clearance to support threat investigations
  • Desire to develop competency in OT cybersecurity and incident response in industrial environments
Desired Certifications

  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Certified Forensics Examiner (GCFE)
  • Offensive Security Certified Professional (OSCP)

This position falls under the company's Insider Threat Program and will have access to, and control over sensitive data, systems or assets. Enhanced personnel screening, which includes a background review, drug screen and psychological assessment, will be required if you are selected for this position

PDN-a181de6c-40e8-4e3e-b016-37522922452c

Salary.com Estimation for Cybersecurity Incident Response Analyst in Atlanta, GA
$113,762 to $142,592
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity Incident Response Analyst?

Sign up to receive alerts about other jobs on the Cybersecurity Incident Response Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$142,618 - $183,267
Income Estimation: 
$173,252 - $220,888
Income Estimation: 
$115,647 - $153,495
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at TalentAlly

  • TalentAlly Concord, NH
  • Benefits Start Day 1 for Full-Time Colleagues - No Waiting Period! For more information about our benefits, see below! We are proud to be a member of the R... more
  • 16 Days Ago

  • TalentAlly Baton Rouge, LA
  • At Texas Roadhouse, we are a people-first company that just happens to serve steaks. Legendary Food and Legendary Service is who we are. We're about loving... more
  • 16 Days Ago

  • TalentAlly Mesa, AZ
  • Summary Base Pay: $37,000 On-Target Earnings: $70,000 ($17.75/hr base pay with uncapped commission, top earners $100k ) Are you highly competitive, motivat... more
  • 16 Days Ago

  • TalentAlly Indianapolis, IN
  • Who We Are NFP, an Aon company, is a multiple Best Places to Work award winner in Business Insurance. We are an organization of consultative advisors and p... more
  • 16 Days Ago


Not the job you're looking for? Here are some other Cybersecurity Incident Response Analyst jobs in the Atlanta, GA area that may be a better fit.

  • Alignerr Atlanta, GA
  • Incident Response Analyst (AI Training) About The Role We're partnering with world-leading AI research labs to build the next generation of security-focuse... more
  • 21 Days Ago

  • Fortuna Cysec Atlanta, GA
  • Description Company Overview Fortuna Cysec delivers unified cybersecurity operations through TheFense platform—our integrated MDR, SIEM, EDR, and response ... more
  • 23 Days Ago

AI Assistant is available now!

Feel free to start your new journey!