459,924open jobs
15,541companies
67,347added this week
Browse all
Salary
$117k – $184k per year
Location
Remote (United States, Puerto Rico)
Seniority
Staff · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Merck & Co. is an American pharmaceutical company founded in 1891 as the United States arm of the German firm Merck and made independent after the First World War, trading as MSD outside the United States and Canada. Its portfolio is dominated by the immuno-oncology drug Keytruda, alongside vaccines such as Gardasil and Vaxneuvance, hospital acute care products, and a large animal health business covering livestock and companion animals. The company is headquartered in Rahway, New Jersey, listed on the New York Stock Exchange, and spends a very large share of revenue on research into oncology, infectious disease and cardiometabolic therapies.

Job Description

Summary:

The Lead Incident Response Analyst is responsible for the day-to-day operations of the team that enables the CFC to respond to an emerging security incident with a coordinated response in the first 0-24hours. The team consist of Incident Response Analysts in the US Tech Center. This position directly supports a 24x7x365 support staff and candidates should be opened to supporting incident response functions outside of core hours. This position will require flexibility to work Incidents to containment and collaborate across global technology centers for long-term investigations.

Key Responsibilities:

Position Responsibilities

  • Incident Response & InvestigationConduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency-only on-call availability is required for high-severity incidents.

  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and Various security tooling.

  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non-technical stakeholders.

  • Coordinate appropriate response activities across teams or directly with partners.

Managerial Responsibilities

  • Lead the initial response for the Cyber Fusion Center for high impact cybersecurity events.

  • Develop, mentor, and lead the teams and individual members.

  • Oversee the day-to-day operations of the team.

  • Coordinate incident transfer between geographical locations and shifts.

  • Provide data analysis of incidents base on prevalent correlations and data.

  • Evaluate events, escalations, and incidents to determine remediation and resolution actions.

  • Update playbooks to improve processes and information sharing across teams.

Minimum Qualifications

  • Bachelors in Computer Science, Cybersecurity or equivalent work experience

  • 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection.

  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.

  • Experience building or shaping a detection and response program in partnership with leadership.

  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.

  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).

  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.

  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload-level events) and taking containment measures in cloud environments.

  • Excellent written and verbal communication skills, including the ability to produce concise, high-clarity investigative findings.

Preferred Qualifications

  • Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.

  • Prior experience conducting in depth log analysis and correlating events across an enterprise.

  • Exposure to SIEM/SOAR platforms from an investigative perspective.

  • Incident response or forensics-related certifications (e.g., GCIH, GCFA, GNFA, GCFE).

Required Skills:

Adaptability, Adaptability, Analytical Thinking, Cybersecurity, Cyber Threat Analysis, Cyber Threat Hunting, Cyber Threat Intelligence, Data Loss Prevention (DLP), Detail-Oriented, Digital Forensics, Endpoint Management, Event Monitoring, Event Support, Forensic Analysis, Governance Management, Incident/Breach Triage and Containment, Incident Analysis, Incident Management, Incident Response, Incident Response Management, Insider Threat Mitigation, Log Analysis, Malware Analysis, Network Forensics, Offensive Cyber Operations {+ 17 more}

Preferred Skills:

Current Employees apply HERE

Current Contingent Workers apply HERE

US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics. Asa federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:

EEOC Know Your Rights

EEOC GINA Supplement

We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

The salary range for this role is

$117,000.00 - $184,200.00

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs.

The successful candidate will be eligible for annual bonus and long-term incentive, if applicable.

We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits.

You can apply for this role through https://jobs.merck.com/us/en (or via the Workday Jobs Hub if you are a current employee). The application deadline for this position is stated on this posting.

San Francisco Residents Only: We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance

Los Angeles Residents Only: We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance

Search Firm Representatives Please Read Carefully

Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.

Employee Status:

Regular

Relocation:

No relocation

VISA Sponsorship:

No

Travel Requirements:

10%

Flexible Work Arrangements:

Remote

Shift:

1st - Day

Valid Driving License:

No

Hazardous Material(s):

N/A

Job Posting End Date:

09/17/2026

*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
459,924 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
United States
$79k – $203k per year (Estimated) • In office • Internship • London
Python
PowerShell
Databases
ElasticSearch
AI/ML
AI Agents
DevOps
GCP
Azure
AWS
Cybersecurity
Microsoft Sentinel
ISO 27001
MITRE ATT&CK
GDPR
Management
Slack
Miro
Outlook
Apply
$19k – $47k per year (Estimated) • In office • Full-Time • 13+ years exp • Hyderabad • Bengaluru
DevOps
Terraform
CI/CD
AWS
Amazon S3
IAM
Cybersecurity
Least Privilege
Apply
$106k – $130k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • San Francisco • Chicago • Scottsdale
DevOps
GCP
Azure
CI/CD
AWS
Harbor
Platform Engineering
Incident Management
Apply
In office • Full-Time • 8+ years exp • PhD • France
JavaScript
TypeScript
Node JS
AI/ML
AI Agents
LLM Guardrails
Frontend
Next.js
React.js
DevOps
Rest API
Splunk
Terraform
GitLab CI
CI/CD
AWS
Docker
Grafana
AppDynamics
GitHub
GitLab
Amazon CloudWatch
QA
Vitest
Apply
Backend Engineer 1 hour ago
$27k – $64k per year (Estimated) • Remote/Hybrid • 5+ years exp • Bengaluru
Java
Java
Spring Boot
Spring Security
Databases
Apache Kafka
AI/ML
Prompt Engineering
LLM
DevOps
Terraform
GCP
Prometheus
Azure
AWS
Kubernetes
Grafana
Amazon EKS
Amazon EC2
Amazon ECS
Amazon Kinesis
Cybersecurity
HIPAA
Web3
Rollup
Apply
$40k – $111k per year • Remote/Hybrid • Internship • Bachelor's Degree • Rahway
Apply
$40k – $111k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • United States
Apply
$24k – $56k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Hyderabad
JavaScript
TypeScript
SQL
C#
C#
.NET
Databases
Azure SQL Database
Frontend
Angular
React.js
DevOps
Rest API
Terraform
Azure DevOps
Azure
CI/CD
Git
Gitflow
Bicep
Analytics
Azure Data Factory
Apply
$131k – $207k per year • In office • Full-Time • Bachelor's Degree • South San Francisco
AI/ML
Multimodal AI
Apply
$191k – $300k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • North Wales
DevOps
IAM
Apply
Painter Technician 1 day ago
$54k – $62k per year • In office • Full-Time • 3+ years exp • High School Diploma • United States
Apply
$61k per year • In office • Internship • High School Diploma • United States
Apply
$60k – $120k per year (Estimated) • In office • Full-Time • 2+ years exp • United States
Apply
$120k – $160k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Atlanta • Pittsburgh • San Diego • Reston • Chicago
SQL
DevOps
Windows Server
SLI/SLO/SLA
IoT
Matter
Apply
$137k – $265k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 10+ years exp • United States
Apply
See all jobs
This is one of many
459,924 more open roles from verified company boards, updated every day.