Pittsburgh, PA

Salary
Posted
Jul 7, 2026
Location
Pittsburgh, PA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A hands-on cyber forensics and incident response analyst role within a global corporate security team based in Pittsburgh, PA. The position covers the full incident lifecycle — triage, investigation, containment, and post-incident reporting — alongside malware analysis, threat hunting, and security tooling development. It suits candidates with at least three years of practical DFIR experience who are comfortable working across distributed international teams and on-call rotations.

Mid level · 3+ years · Pittsburgh, PA · Bachelor's required · Full-time

Must have (8)
incident responsedigital forensicsWindowsActive DirectoryPython, Shell Scripting or PowerShellSIEMSOAREDR
Nice to have (7)
GIAC, Isc2, Ec Council or Offensive SecuritySplunkEnCase, Ftk, Sift, X Ways or Sleuth KitVolatilityVelociraptorMITRE ATT&CKmachine learning

“or” means any one of them counts — you don't need all of them.

Posted 3 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 20 people in the Pittsburgh, PA area plausibly meet what this posting asks for (information security analysts). range 9–35

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
incident response62%SIEM55%Python51%Active Directory50%EDR40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $105,909 (middle half $83,067–$132,910).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The role requires 3+ years of hands-on experience in incident response, digital forensics, or a combination — this maps to a Mid-level band despite the broad scope of responsibilities.

Python, Bash, and PowerShell are listed together as interchangeable scripting options under Basic Qualifications; Python is used as the primary name with Bash and PowerShell as alternatives.

Certifications (GIAC, ISC2, EC-Council, Offensive Security) appear under Preferred Qualifications and are not a hard gate.

Splunk is listed under Preferred Qualifications ('Experience working with Splunk or comparable SIEM platforms'); it is not a required gate despite SIEM being required generally.

Forensic tools (EnCase, FTK, SIFT, X-Ways, Volatility, Sleuth Kit/Autopsy, Velociraptor) and MITRE ATT&CK all appear under Preferred Qualifications.

The role requires occasional international travel to Stuttgart, Germany (approximately 1–2 weeks annually), which cannot be represented in structured fields.

The role includes an on-call rotation and flexibility for off-hours work during critical incidents — relevant operational expectations not captured in structured fields.

No compensation range is stated in the posting.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): malware analysis, packet capture analysis, memory analysis.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗