Cybersecurity Incident Response Analyst

Remote Full-time
About the position

IMPORTANT, PLEASE READ BEFORE APPLYING
Due to Federal requirements, only US citizens, US naturalized citizens or US Permanent Residents, holding a green card, will be considered.
This role requires a minimum of 2 days per week in the San Diego, CA or Santa Clara, CA ServiceNow Offices. If you cannot meet this requirement, we ask that you please do not apply. Thank you.
The ServiceNow Security Organization (SSO)
The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact
What you get to do in this role:
ServiceNow has a large and highly skilled security team located at multiple sites globally. As part of a rapidly growing organization, ServiceNow is looking to expand its Global Incident Response team. This role is an opportunity to serve on the frontline of security operations, supporting both ServiceNow’s commercial customers and its federal environment. As a rapidly growing organization, ServiceNow offers strong opportunities for career growth while developing expertise across our commercial and federal environments and the ServiceNow platform itself.
As an Cybersecurity Incident Response Analyst, you will be a key member of the team monitoring tools and systems that defend ServiceNow’s production and corporate environments, defining relationships between seemingly unrelated events through deductive reasoning, and continuously finding ways to do things faster, better, and more effectively — while maintaining a laser focus on quality.
You will work on a geographically diverse team to respond to threats that may arise against our infrastructure and track cases to closure, working across functional teams.
You will be required to participate in an on-call rotation including weekends to ensure that Security Operations can respond to priority incidents in a timely manner. This role requires to work weekend rotational shifts and hours (pacific time zone) outside of standard business hours if necessary.

Responsibilities
• monitoring tools and systems that defend ServiceNow’s production and corporate environments
• defining relationships between seemingly unrelated events through deductive reasoning
• continuously finding ways to do things faster, better, and more effectively — while maintaining a laser focus on quality
• work on a geographically diverse team to respond to threats that may arise against our infrastructure and track cases to closure, working across functional teams
• participate in an on-call rotation including weekends to ensure that Security Operations can respond to priority incidents in a timely manner

Requirements
• Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI’s potential impact on the function or industry.
• 2+ years of related experience or equivalent combination of education and experience.
• Deep understanding of Security Operations Center and Security Incident Response Team protocols and procedures, including incident triage and escalation workflows.
• A solid foundation in networking fundamentals, with a deep understanding of TCP/IP and other core protocols.
• Experience with SIEM platforms (e.g., Splunk,) for log analysis and detection tuning.
• Familiarity with EDR tools for endpoint detection and response.
• Exposure to SOAR platforms for workflow automation and incident orchestration.
• Knowledge of cloud security concepts and experience working in cloud environments (AWS, Azure, or GCP).
• The ability to analyze event and system logs, perform forensic analysis, analyze malware, and process other incident response-related data as needed.
• Familiarity with intrusion detection systems.
• Understanding of Windows and Linux operating systems and command-line tools.
• Familiarity with scripting in any language.

Nice-to-haves
• Any cybersecurity or network related certifications (ex: CCNA, CompTIA, GSEC, GCIH, CEH certifications).
• ServiceNow platform knowledge is a plus.

Benefits
• health plans, including flexible spending accounts
• a 401(k) Plan with company match
• ESPP
• matching donations
• a flexible time away plan
• family leave programs

Apply tot his job

Apply To this Job
Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Solutions Architect (AI/ML) - Digital Native Business

Remote

**Experienced Full Stack Customer Service Coordinator – Bank Voice – Work from Home Opportunity at blithequark**

Remote

**Experienced Part-Time Customer Service and IT Support Representative – Remote Opportunity with arenaflex**

Remote

**Experienced Data Entry Specialist – Aviation Operations Support**

Remote

Urgently Hiring: Aetna Careers Remote $27/Hour

Remote

Zoho Configuration Analyst – Sales & Marketing Operations (Contract)

Remote

**Experienced Part-time Remote Data Entry Specialist for Clinical Trials at blithequark**

Remote

Experienced Remote Customer Service Representative – Delivering Exceptional Support and Magical Experiences for arenaflex Enthusiasts

Remote

Sr. Medical Science Liaison, Global Rare Diseases - Central (Colorado, US)

Remote

Senior Account Executive -Northeast (New Logo)

Remote
← Back