Senior Incident Response Analyst

Senior Incident Response Analyst

Type:

Contract To Hire

Location:

Charlotte - North Carolina

Rate Info:

$60-85/hr

Work Model:

Hybrid

Published:

17-Feb-2026

Job ID:

41450

Optomi, in partnership with a leading cybersecurity-focused organization, is looking for a Senior Incident Response Analyst to join their maturing IR/SWAT team.

 

Position Summary:  

Optomi is seeking a senior-level Incident Response resource to support their rapidly evolving security program. This role will focus on triaging escalations, performing end-to-end investigations, and collaborating on containment and remediation efforts in a high-urgency environment. The team operates within a Microsoft-centric ecosystem, leveraging tools like Sentinel and Defender, and places a heavy emphasis on email security and phishing investigations. The successful candidate will possess strong analytical and investigative skills, as well as the ability to navigate and interpret data across various log sources.

What the right candidate will enjoy:
  • Opportunity to work with a small, multi-discipline team covering Incident Response, Threat Hunting, Threat Intelligence, and Detection Engineering.
  • Exposure to a maturing security program with evolving processes, SOPs, and tooling.
  • A collaborative and supportive team environment that values trust, humility, and curiosity.
  • Hybrid work environment with potential flexibility based on office space constraints.
What type of experience does the right candidate have:
  • Strong understanding of Microsoft ecosystem (Sentinel + Defender stack).
  • Ability to write and interpret basic KQL queries.
  • Experience with email security and phishing investigations, including mail flow, URL analysis, and determining spread/impact.
  • Proficiency in analyzing various log sources such as firewall, IDS/IPS, cloud telemetry, and proxy logs.
  • Analytical and critical thinking skills with the ability to perform investigative pivots.
  • Strong communication skills and a team-first mindset.
What the responsibilities are of the right candidate:
  • Triaging escalations from Tier 1 SOC and taking investigations end-to-end.
  • Collaborating on containment and coordinating remediation efforts with appropriate owners.
  • Analyzing and interpreting data to identify root causes and impacts of incidents.
  • Leveraging playbooks and decision trees for regulated-environment steps.
  • Supporting crisis communications and regulatory notifications during material incidents.
  • Contributing to the continued stabilization and maturity of the IR program.

Join Optomi and make an impact in a dynamic and evolving cybersecurity environment by applying your expertise to protect and secure critical systems and data.

APPLY NOW

Share this job

SCHEMA MARKUP ( This text will only show on the editor. )