T
Toyota Tsusho Systems US, Inc.
Posted 20 days agoVerified live 2d ago

Incident Response Analyst (Mid-Senior Level)

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
Incident ResponseDigital ForensicsWindows InternalsLinux InternalsmacOS InternalsCloud Security Incident ResponseThreat HuntingMalware AnalysisPythonPowerShellBashAutopsySleuth KitVolatilityMagnet AxiomFTKNIST Cybersecurity Framework

Job description

Summary

Toyota Tsusho Systems US, Inc. is a Toyota group technology and mobility company focused on secure and resilient IT solutions. The Incident Response Analyst will respond to critical cybersecurity incidents, conduct digital forensic investigations, and support threat intelligence and hunting activities. The role also contributes to incident response playbooks, tooling improvements, training materials, and collaboration across cybersecurity teams.

Responsibilities

  • Conduct comprehensive incident response activities following the NIST Cybersecurity Framework across all phases: Initial Detection, Analysis & Validation, Containment, Eradication, Recovery, and Post-Incident Activity
  • Respond to cyber incidents impacting TMNA Corporate, Manufacturing Plants, Third-Parties, Dealerships, and RSOC Customers
  • Perform digital forensic investigations including collection, processing, and analysis of forensic evidence from diverse devices (Windows, Linux, macOS, mobile)
  • Maintain an "Always Be Timelining" (ABT) approach, continuously updating incident timelines as findings are discovered
  • Support proactive, reactive, and exploratory threat hunting activities across the ecosystem
  • Analyze emerging cyber threats, attacker TTPs, and track threat actors/groups to anticipate and mitigate potential attacks
  • Collaborate closely with the 24/7 SOC, Threat Detection Engineering, Vulnerability Management, and Insider Risk Management teams
  • Prepare and deliver forensic reports, incident communications, and executive updates during active incidents
  • Participate in weekly on-call rotation schedule for 24/7 incident response coverage
  • Conduct malware analysis (behavioral and static) using TRRAC Labs' dynamic analysis capabilities
  • Help develop, refine, and maintain incident response playbooks, SOPs, and training materials to improve team effectiveness
  • Participate in quarterly tabletop exercises to test incident response workflows and controls
  • Stay current on emerging threats, attacker techniques, and industry best practices

Skills

  • Minimum of 3-5 years of hands-on experience in incident response and digital forensics
  • Proven ability to act as Incident Commander within a team setting during high-pressure incidents
  • Strong technical expertise in Windows, Linux, and macOS internals related to monitoring and threat detection
  • Experience with cloud security incident response and threat mitigation
  • Skilled in malware analysis (behavioral and static) and basic cryptanalysis
  • Familiarity with security frameworks and compliance standards (NIST, HIPAA, ISO, OWASP, etc.)
  • Proficient with DFIR tools such as Autopsy, The Sleuth Kit, Volatility, Magnet Axiom, FTK, and others
  • Competent in scripting languages like Python, PowerShell, and Bash for automation and analysis
  • Excellent communication skills with the ability to collaborate effectively across technical teams and stakeholders
  • Experience in enterprise, manufacturing, or software industries
  • Familiarity with SOAR platforms and security automation
  • Prior experience contributing to or improving incident response programs in a team environment
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred)

Qualifications

Must Haves

  • Minimum of 3-5 years of hands-on experience in incident response and digital forensics
  • Proven ability to act as Incident Commander within a team setting during high-pressure incidents
  • Strong technical expertise in Windows, Linux, and macOS internals related to monitoring and threat detection
  • Experience with cloud security incident response and threat mitigation
  • Skilled in malware analysis (behavioral and static) and basic cryptanalysis
  • Familiarity with security frameworks and compliance standards (NIST, HIPAA, ISO, OWASP, etc.)
  • Proficient with DFIR tools such as Autopsy, The Sleuth Kit, Volatility, Magnet Axiom, FTK, and others
  • Competent in scripting languages like Python, PowerShell, and Bash for automation and analysis
  • Excellent communication skills with the ability to collaborate effectively across technical teams and stakeholders
  • Experience in enterprise, manufacturing, or software industries
  • Familiarity with SOAR platforms and security automation
  • Prior experience contributing to or improving incident response programs in a team environment

Nice to Haves

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred)

Benefits

  • Remote work arrangement.
  • Continuously grow your skills through diverse investigations, threat hunting, and team knowledge sharing.
  • Be part of a skilled, collaborative incident response team.
  • Help shape and improve incident response processes and training.

More jobs like this