Lead Incident Response Analyst, Detection and Response

MSD

Confirmed live today High trust
Closes in 3 days Remote

Quick summary

Work type
Remote
Location
Rahway, NJ
Salary
$117,000–$184,200 / yr
Posted
4 days ago
Freshness
Confirmed live today
Closes
Sep 17, 2026 (soon)

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $160k
This role $151k
$108k most similar roles pay here $202k

This role pays less than 58% of similar roles. Most pay $133,500–$187,000 — the shaded band above. At the midpoint, this role pays about $151k versus about $160k for comparable roles.

Based on 240 similar postings.

Employer

About MSD

MSD (Merck Sharp & Dohme) is the international name for Merck & Co., a major U.S.-based pharmaceutical company.

MSD currently has 24 open roles on FindRole.

Listed pay typically runs $117,000–$184,200 across 24 roles with salary data.

Most-posted roles

View all roles at MSD

At a glance

TL;DR · Lead Incident Response Analyst, Detection and Response

Lead Incident Response Analyst - Detection and Response The Lead Incident Response Analyst manages the day-to-day operations of the Cyber Fusion Center team to coordinate responses to emerging security incidents within a 24-hour window. This role involves leading initial responses for high-impact cybersecurity events, mentoring team members, and overseeing incident transitions across global locations. Responsibilities include conducting forensic reviews, performing log correlation, and executing containment actions across cloud and endpoint environments. The candidate will manage escalated MSSP/MDR alerts while updating playbooks to improve information sharing. Technical requirements include proficiency with SIEM, EDR, proxy, WAF, and various security tools. Essential skills involve analyzing AWS and Azure logs, understanding MITRE ATT&CK TTPs, and performing digital forensics. The role addresses the critical need for rapid detection, investigation, and containment of threats within complex cloud and identity systems to mitigate organizational risk.

What you'll do

  • Conduct incident response for escalated MSSP/MDR alerts including scoping, investigation, and containment across cloud and endpoint environments.
  • Perform forensic reviews of affected systems through log correlation, event reconstruction, and identification of attacker techniques.
  • Provide clear investigative findings, timelines, and recommended remediation steps to both technical and non-technical stakeholders.
  • Lead the initial response for high-impact cybersecurity events within the Cyber Fusion Center.
  • Manage day-to-day team operations, including mentoring staff and coordinating incident handoffs between global locations.
  • Analyze cloud security logs from AWS and Azure to perform containment actions in cloud environments.
  • Update playbooks to improve internal processes and information sharing across various teams.

What we're looking for

  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent work experience.
  • 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals including artifact analysis and timeline creation.
  • Experience analyzing AWS and Azure security logs and taking containment measures in cloud environments.
  • Incident response or forensics-related certifications such as GCIH, GCFA, GNFA, or GCFE (preferred).

More like this

Similar roles

Lead, Incident Response

Salesforce

Remote (Mclean, VA) 10 days ago $172,500$260,100
Incident Response SOAR Detection-as-Code AWS Azure GCP CI/CD Network Forensics Malware Analysis Detection Engineering MITRE ATT&CK Linux Windows macOS Security Orchestration
8+ yrs exp Remote

Incident Response Analyst, React

Cloudflare, Inc

Bengaluru, India 82 days ago
Incident Response WAF AWS Azure Google Cloud Python Golang Yara BGP DNS TCP/IP Linux Windows MITRE ATT&CK NIST Cyber Security Framework Malware Analysis Reverse Engineering Bash Regular Expressions
5+ yrs exp

Cyber Defense Response Analyst II

CME Group

Chicago, IL 18 days ago $93,900$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM

Incident Response Analyst, Mid

Booz Allen Hamilton

Bethesda, MD 10 days ago $62,000$141,000
Splunk SIEM EDR IDS/IPS SOAR Digital Forensics Packet Analysis Malware Triage Threat Hunting Behavioral Analytics Threat Intelligence Identity and Access Management Container Security API Security Vulnerability Management Firewalls Log Analysis
2+ yrs exp

Senior Incident Response Analyst

Booz Allen Hamilton

Bethesda, MD 2 days ago $86,800$198,000
Splunk SIEM EDR IDS IPS SOAR Microsoft Defender Packet Analysis Malware Triage Digital Forensics Threat Hunting Behavioral Analytics Threat Intelligence Vulnerability Management Firewalls Identity and Access Management Container Security API Security
5+ yrs exp

Principal Security Engineer, Incident Response

F5 Inc

Remote 10 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote