remote

Salary
$70,000–$100,000from the description
Posted
Jul 21, 2026
Location
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A security monitoring and incident response role within what appears to be an internal security operations function. Day-to-day work centers on triaging and responding to security events using SIEM tools, log data, and network flows, as well as supporting the deployment and upkeep of detection technologies. Suits candidates with a background in SOC or managed security environments and hands-on experience across areas such as intrusion detection, malware analysis, or vulnerability management.

Mid level · 3+ years · Full-time

Must have (8)
SIEMIDS/IPSTCP/IPWindowsLinuxincident responsenetwork intrusion detectionpacket capture
Nice to have (4)
vulnerability managementSANS GCIHGCIAISC2

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Linux65%incident response62%SIEM55%TCP/IP40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

No specific work location or metro is stated in the posting; CBSA is left blank. The role appears to be US-based but location is unspecified.

The degree requirement is listed as a Bachelor's 'or equivalent work experience,' so it is not treated as a hard gate.

The 3+ years of IT experience is used as the overall years minimum; the 2+ years of Information Security experience is a sub-requirement within that.

Incident response, SIEM, IDS/IPS, packet capture/protocol analysis, TCP/IP, Windows, and Linux are all listed under the core qualifications/requirements block and are treated as hard gates. Note that 'incident response/handling' is a named security discipline explicitly required, not a generic responsibility.

Vulnerability testing/management, SANS GCIH, GCIA, ISC2 certifications, malware analysis, and SOC experience are explicitly marked as 'preferred' in the posting.

The posting does not specify remote work; it is treated as on-site.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): malware analysis.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗