Franklin, TNremote

Salary
Posted
Jul 9, 2026
Location
Franklin, TN
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

A senior-level role focused on managing the full lifecycle of security incidents — from forensic analysis across host, network, memory, and log sources to coordinating cross-functional response efforts and communicating findings to executive leadership. The position also involves maintaining and improving incident response playbooks, running tabletop exercises, and mentoring junior analysts, making it suited to an experienced digital forensics and incident response professional.

Senior level · 5+ years · Remote

Must have (6)
digital forensics · 3+ yrsincident response · 3+ yrsSIEM or Ids Ipshost forensicsnetwork forensicsmemory forensics
Nice to have (3)
MITRE ATT&CK or Cyber Kill ChainPython or PowerShellcloud forensics

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
incident response62%SIEM55%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The minimum education requirement is a H.S. Diploma/GED (hard gate); an Associate's or Bachelor's degree is explicitly 'preferred', so the degree requirement is set to None.

The 5+ years of IT/InfoSec experience (with 3+ years specifically in DFIR) is stated in the Qualifications section and drives the overall years minimum of 5 and the years demanded of 3 on the DFIR skills.

MITRE ATT&CK, Cyber Kill Chain, scripting/automation (Python/PowerShell), AI for security operations, and cloud forensics all appear under 'preferred' or 'familiarity with' language in the Qualifications section and are marked accordingly.

IDS/IPS is listed as an alternative to SIEM since the JD groups them together as detection technologies the candidate must have experience with; SIEM is the primary named tool.

Industry certifications (SANS, ISC2, EC-Council, CompTIA) are mentioned in the Knowledge, Skills and Abilities section without firm gating language — they are not emitted as a discrete skill since no specific certification is named as a hard requirement.

No compensation figures are provided in the posting.

The title 'Incident Response Specialist' carries no explicit seniority level word, so the title states no level; however, the scope (technical incident commander, mentorship of junior/senior analysts, strategy ownership, 5+ years required) firmly supports a Senior classification.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): log analysis.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗