bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCareers Firstambank Icims ComTechnical Incident Response Analyst - Hybrid (IL)

Technical Incident Response Analyst - Hybrid (IL)

Careers Firstambank Icims Com · Elk Grove Village, IL, US · Remote · Active · $8 / day · iCIMS

Job facts

FieldValue
CompanyCareers Firstambank Icims Com
TitleTechnical Incident Response Analyst - Hybrid (IL)
Normalized title-
Department / teamInformation Technology
LocationElk Grove Village, IL, United States
Work modelRemote / Remote
Employment typeFull Time
Salary$8 / day
Statusactive
ATS provideriCIMS
Posted / first seen2026-05-14 / 2026-05-31
Changed / last seen2026-06-10 / 2026-06-18

Related slices

PageWhat it containsOpen
Company jobsActive postings from Careers Firstambank Icims Com.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through iCIMS.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Elk Grove Village.Open
Department jobsActive postings in Information Technology.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCareers Firstambank Icims Com
Source8e7ea43b-f5e3-4c87-8112-f6caa8250eb8
ATS provideriCIMS

Description

Job Description First American Bank was founded in Chicago, and over the years has expanded throughout Wisconsin and Florida. As the largest privately held bank in Illinois, we now have over 60 locations and assets of $8+ billion. We are a community bank at heart with international expertise, traditional values, and a forward-looking philosophy. Our employees have the experience and vision to meet the needs of savers, borrowers, and businesses in the 21st century. First American Bank can offer employees a level of visibility, career growth, and stability that is difficult to find in many larger corporations. The Technical Incident Response Analyst is responsible for monitoring, analyzing, and responding to cybersecurity alerts and incidents across enterprise infrastructure and security platforms. This role serves as a primary investigator for security events, ensuring timely detection, containment, remediation, documentation, and escalation of incidents in alignment with established incident response playbooks, regulatory requirements, and internal controls. The position combines real‑time alert monitoring, technical investigation, firewall and configuration change validation, and execution of defined recurring operational tasks to maintain a strong security posture across the organization. DUTIES & RESPONSIBILITES Monitor and respond to cybersecurity alerts generated from SIEM provider dashboards and security monitoring platforms. Investigate, remediate, and document security incidents reported through automated alerts, tickets, emails, phone calls, or external SOC notifications. Act as the primary investigator for potential security incidents identified by SOC analysts or monitoring tools. Follow documented incident response playbooks while exercising sound judgment to contain and remediate threats. Investigate phishing emails, user‑reported security concerns, and potential attempts at fraud or financial loss. Review authentication, endpoint, network, and application activity for anomalous or malicious behavior. Analyze firewall logs, IDS alerts, intrusion prevention activity, anti‑malware events, server logs, and application logs. Monitor intrusion detection systems, for indicators of compromise or suspicious activity. Correlate data across SIEM, IDS, endpoint, and firewall platforms to support incident investigations. Perform log reviews using standardized incident response and log review templates. Perform reconciliation of firewall rule and configuration changes. Validate that all changes are authorized, approved, and compliant with change management and security policies. Identify unauthorized or out‑of‑policy changes and escalate violations as required Execute daily, weekly, and periodic tasks defined in the Incident Response recurring task schedule, including: Reviewing Microsoft Defender security incidents and assigning or resolving alerts. Reviewing external SOC (e.g., Proficio) incident tickets to ensure proper closure. Reviewing SIEM and Kibana dashboards for authentication failures and other abnormal activity. Validating completion and documenting evidence through screenshots and reports. Document incident activity, evidence, analysis, and remediation actions in an audit‑ready manner. Communicate incident status clearly to Information Security leadership, infrastructure teams, and management. Provide incident reporting suitable for internal audit, regulatory examination, and compliance reviews. Track incidents end‑to‑end to ensure timely closure and proper documentation. Participate in SOC and security working group sessions to improve detection rules and reduce false positives. Review and update automated alerts and incident response playbooks for accuracy and effectiveness. Collaborate with networking, systems, endpoint, and application teams during investigations. QUALIFICATIONS Minimum of three years of experience directly related to incident response, security monitoring, or cybersecurity operations. Hands‑on experience with SIEM platforms, incident response tooling, and alert monitoring solutions. Experience with firewall technologies, network security concepts, and endpoint protection platforms. Experience performing log analysis and incident investigations across multiple data sources. Exposure to Linux operating systems preferred. Working knowledge of: SIEM and security monitoring platforms Firewalls, TCP/IP networking, LAN/WAN infrastructure Endpoint protection and anti‑malware solutions IDS/HIDS platforms Microsoft 365 security tools Demonstrated ability to reconcile configuration changes and validate security controls. Qualified military veterans are encouraged to apply. Must be professional, comfortable speaking with external and internal contacts with a demonstrated ability to tailor the message appropriately to the audience and situation effectively. Ability to relay technical information to both technical and non-technical personnel. Ability to write technical documentation. Demonstrated ability to convey thoughts and ideas effectively and succinctly via written formats, including emails, letters, and electronic platforms. Maintain professional standards relating to spelling and grammar. Maintain credibility through professional demeanor, appearance, and presence by modeling standards appropriate to our environment and industry. Maintain good working relationships with internal partners by exhibiting exemplary interpersonal skills, adopting a constructive, solutions-focused approach. Use sound professional judgment to balance the interests of the organization and customer, understanding and using available resources to mitigate risks. Proficiency with Microsoft 365 products and applications, including the ability to effectively prepare or review documents, procedures, and reports. Proficiency in Network Management and Firewalls, Servers, TCP/IP Schema, Remote Access Solutions, & NFS/ISCCI/CIFS networking/storage interdependencies. Demonstrated ability to learn new systems and applications, as well as the ability to understand, adapt and adjust responsibilities/workflows as a result of system upgrades. Occasional travel to other First American Bank locations, Bank functions, and training facilities may be required. Typical schedule is Monday through Friday 8:00 a.m. to 5:00 p.m. Additional hours may be required depending upon business need. Rotational Saturday work and off-hours on-call availability. Punctuality is required to maintain First American Bank’s customer service standards.

Full job record

Job ID106730c08048e964092b40ca837940ec1c59f0e0
Org IDf4a5c649-d658-4074-b536-b9562282bcb1
Source ID8e7ea43b-f5e3-4c87-8112-f6caa8250eb8
Board ID8e7ea43b-f5e3-4c87-8112-f6caa8250eb8
Providericims
Provider Job Key3385
TitleTechnical Incident Response Analyst - Hybrid (IL)
Normalized Title
Statusactive
Activeyes
Location TextElk Grove Village, IL, US
DepartmentInformation Technology
Team
Employment Typefull_time
Workplace Typeremote
Remote Policyremote
CountryUnited States
RegionIL
CityElk Grove Village
Salary RawJob Description First American Bank was founded in Chicago, and over the years has expanded throughout Wisconsin and Florida. As the largest privately held bank in Illinois, we now have over 60 locations and assets of $8+ billion. We are a community bank at heart with international expertise, traditional values, and a forward-looking philosophy. Our employees have the experience and vision to meet the needs of savers, borrowers, and businesses in the 21st century. First American Bank can offer employees a level of visibility, career growth, and stability that is difficult to find in many larger corporations. The Technical Incident Response Analyst is responsible for monitoring, analyzing, and responding to cybersecurity alerts and incidents across enterprise infrastructure and security platforms. This role serves as a primary investigator for security events, ensuring timely detection, containment, remediation, documentation, and escalation of incidents in alignment with established incident response playbooks, regulatory requirements, and internal controls. The position combines real‑time alert monitoring, technical investigation, firewall and configuration change validation, and execution of defined recurring operational tasks to maintain a strong security posture across the organization. DUTIES & RESPONSIBILITES Monitor and respond to cybersecurity alerts generated from SIEM provider dashboards and security monitoring platforms. Investigate, remediate, and document security incidents reported through automated alerts, tickets, emails, phone calls, or external SOC notifications. Act as the primary investigator for potential security incidents identified by SOC analysts or monitoring tools. Follow documented incident response playbooks while exercising sound judgment to contain and remediate threats. Investigate phishing emails, user‑reported security concerns, and potential attempts at fraud or financial loss. Review authentication, endpoint, network, and application activity for anomalous or malicious behavior. Analyze firewall logs, IDS alerts, intrusion prevention activity, anti‑malware events, server logs, and application logs. Monitor intrusion detection systems, for indicators of compromise or suspicious activity. Correlate data across SIEM, IDS, endpoint, and firewall platforms to support incident investigations. Perform log reviews using standardized incident response and log review templates. Perform reconciliation of firewall rule and configuration changes. Validate that all changes are authorized, approved, and compliant with change management and security policies. Identify unauthorized or out‑of‑policy changes and escalate violations as required Execute daily, weekly, and periodic tasks defined in the Incident Response recurring task schedule, including: Reviewing Microsoft Defender security incidents and assigning or resolving alerts. Reviewing external SOC (e.g., Proficio) incident tickets to ensure proper closure. Reviewing SIEM and Kibana dashboards for authentication failures and other abnormal activity. Validating completion and documenting evidence through screenshots and reports. Document incident activity, evidence, analysis, and remediation actions in an audit‑ready manner. Communicate incident status clearly to Information Security leadership, infrastructure teams, and management. Provide incident reporting suitable for internal audit, regulatory examination, and compliance reviews. Track incidents end‑to‑end to ensure timely closure and proper documentation. Participate in SOC and security working group sessions to improve detection rules and reduce false positives. Review and update automated alerts and incident response playbooks for accuracy and effectiveness. Collaborate with networking, systems, endpoint, and application teams during investigations. QUALIFICATIONS Minimum of three years of experience directly related to incident response, security monitoring, or cybersecurity operations. Hands‑on experience with SIEM platforms, incident response tooling, and alert monitoring solutions. Experience with firewall technologies, network security concepts, and endpoint protection platforms. Experience performing log analysis and incident investigations across multiple data sources. Exposure to Linux operating systems preferred. Working knowledge of: SIEM and security monitoring platforms Firewalls, TCP/IP networking, LAN/WAN infrastructure Endpoint protection and anti‑malware solutions IDS/HIDS platforms Microsoft 365 security tools Demonstrated ability to reconcile configuration changes and validate security controls. Qualified military veterans are encouraged to apply. Must be professional, comfortable speaking with external and internal contacts with a demonstrated ability to tailor the message appropriately to the audience and situation effectively. Ability to relay technical information to both technical and non-technical personnel. Ability to write technical documentation. Demonstrated ability to convey thoughts and ideas effectively and succinctly via written formats, including emails, letters, and electronic platforms. Maintain professional standards relating to spelling and grammar. Maintain credibility through professional demeanor, appearance, and presence by modeling standards appropriate to our environment and industry. Maintain good working relationships with internal partners by exhibiting exemplary interpersonal skills, adopting a constructive, solutions-focused approach. Use sound professional judgment to balance the interests of the organization and customer, understanding and using available resources to mitigate risks. Proficiency with Microsoft 365 products and applications, including the ability to effectively prepare or review documents, procedures, and reports. Proficiency in Network Management and Firewalls, Servers, TCP/IP Schema, Remote Access Solutions, & NFS/ISCCI/CIFS networking/storage interdependencies. Demonstrated ability to learn new systems and applications, as well as the ability to understand, adapt and adjust responsibilities/workflows as a result of system upgrades. Occasional travel to other First American Bank locations, Bank functions, and training facilities may be required. Typical schedule is Monday through Friday 8:00 a.m. to 5:00 p.m. Additional hours may be required depending upon business need. Rotational Saturday work and off-hours on-call availability. Punctuality is required to maintain First American Bank’s customer service standards.
Salary Min8
Salary Max
Salary CurrencyUSD
Salary Periodday
Source URLhttps://careers-firstambank.icims.com/jobs/3385/technical-incident-response-analyst---hybrid-%28il%29/job
Apply URLhttps://careers-firstambank.icims.com/jobs/3385/technical-incident-response-analyst---hybrid-%28il%29/job
First Seen At2026-05-31 18:43:23Z
Last Seen At2026-06-18 08:32:14Z
Last Checked At2026-06-18 08:32:14Z
Last Changed At2026-06-10 08:29:53Z
Inactive At
Source Posted At2026-05-14 04:00:00Z
Source Updated At2026-06-09 18:53:20Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-firstambank.icims.com/date=2026-06-18/2026-06-18T08-32-13-554Z-66ec480c39d1faa999d8f8465624d334b62c2083f125b1dba3e65269cb2f9a24.json
Event Fields
{
  "content_hash": "29ba95ff4d2fb7163a2fd0088fb0ca8cd612db25bf7363a20e835cc56d5b5f9a",
  "source_hash": "f61b86e95ef7b535c8c971dbea12391bbc2f2af45da3cc3d66bac4e95130b120",
  "last_changed_at": "2026-06-10T08:29:53.430Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Elk Grove Village, IL, US",
    "city": "Elk Grove Village",
    "region": "IL",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": null,
  "salary_min": 8,
  "inferred_at": "2026-06-18T08:32:14.262Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Elk Grove Village, IL, US",
      "city": "Elk Grove Village",
      "region": "IL",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": "day",
  "workplace_type": "remote",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "json_ld": {
    "url": "https://careers-firstambank.icims.com/jobs/3385/technical-incident-response-analyst---hybrid-%28il%29/job",
    "@type": "JobPosting",
    "title": "Technical Incident Response Analyst - Hybrid (IL)",
    "@context": "http://schema.org",
    "baseSalary": {
      "@type": "MonetaryAmount",
      "currency": "USD",
      "maxValue": 115000,
      "minValue": 85000
    },
    "datePosted": "2026-05-14T04:00:00.000Z",
    "description": "<h2>Job Description</h2>\n<p>First American Bank was founded in Chicago, and over the years has expanded throughout Wisconsin and Florida.  As the largest privately held bank in Illinois, we now have over 60 locations and assets of $8+ billion.  We are a community bank at heart with international expertise, traditional values, and a forward-looking philosophy.  Our employees have the experience and vision to meet the needs of savers, borrowers, and businesses in the 21st century.  First American Bank can offer employees a level of visibility, career growth, and stability that is difficult to find in many larger corporations. </p>\n<p> </p>\n<p>The Technical Incident Response Analyst is responsible for monitoring, analyzing, and responding to cybersecurity alerts and incidents across enterprise infrastructure and security platforms. This role serves as a primary investigator for security events, ensuring timely detection, containment, remediation, documentation, and escalation of incidents in alignment with established incident response playbooks, regulatory requirements, and internal controls.</p>\n<p> </p>\n<p>The position combines real‑time alert monitoring, technical investigation, firewall and configuration change validation, and execution of defined recurring operational tasks to maintain a strong security posture across the organization.</p>\n<p> </p>\n<p><strong>DUTIES & RESPONSIBILITES</strong></p>\n<ul>\n <li>Monitor and respond to cybersecurity alerts generated from SIEM provider dashboards and security monitoring platforms.</li>\n <li>Investigate, remediate, and document security incidents reported through automated alerts, tickets, emails, phone calls, or external SOC notifications.</li>\n <li>Act as the primary investigator for potential security incidents identified by SOC analysts or monitoring tools.</li>\n <li>Follow documented incident response playbooks while exercising sound judgment to contain and remediate threats.</li>\n <li>Investigate phishing emails, user‑reported security concerns, and potential attempts at fraud or financial loss.</li>\n <li>Review authentication, endpoint, network, and application activity for anomalous or malicious behavior.</li>\n <li>Analyze firewall logs, IDS alerts, intrusion prevention activity, anti‑malware events, server logs, and application logs.</li>\n <li>Monitor intrusion detection systems, for indicators of compromise or suspicious activity.</li>\n <li>Correlate data across SIEM, IDS, endpoint, and firewall platforms to support incident investigations.</li>\n <li>Perform log reviews using standardized incident response and log review templates.</li>\n <li>Perform reconciliation of firewall rule and configuration changes.</li>\n <li>Validate that all changes are authorized, approved, and compliant with change management and security policies.</li>\n <li>Identify unauthorized or out‑of‑policy changes and escalate violations as required</li>\n</ul>\n<p>Execute daily, weekly, and periodic tasks defined in the Incident Response recurring task schedule, including:</p>\n<p> </p>\n<p>         Reviewing Microsoft Defender security incidents and assigning or resolving alerts.         </p>\n<p>         Reviewing external SOC (e.g., Proficio) incident tickets to ensure proper closure.</p>\n<p>         Reviewing SIEM and Kibana dashboards for authentication failures and other abnormal activity.</p>\n<p>         Validating completion and documenting evidence through screenshots and reports.</p>\n<ul>\n <li>Document incident activity, evidence, analysis, and remediation actions in an audit‑ready manner.</li>\n <li>Communicate incident status clearly to Information Security leadership, infrastructure teams, and management.</li>\n <li>Provide incident reporting suitable for internal audit, regulatory examination, and compliance reviews.</li>\n <li>Track incidents end‑to‑end to ensure timely closure and proper documentation.</li>\n <li>Participate in SOC and security working group sessions to improve detection rules and reduce false positives.</li>\n <li>Review and update automated alerts and incident response playbooks for accuracy and effectiveness.</li>\n <li>Collaborate with networking, systems, endpoint, and application teams during investigations.</li>\n</ul>\n<p> </p>\n<p><strong>QUALIFICATIONS</strong></p>\n<ul>\n <li>Minimum of three years of experience directly related to incident response, security monitoring, or cybersecurity operations.</li>\n <li>Hands‑on experience with SIEM platforms, incident response tooling, and alert monitoring solutions.</li>\n <li>Experience with firewall technologies, network security concepts, and endpoint protection platforms.</li>\n <li>Experience performing log analysis and incident investigations across multiple data sources.</li>\n <li>Exposure to Linux operating systems preferred.</li>\n</ul>\n<p>Working knowledge of:</p>\n<p> </p>\n<p>         SIEM and security monitoring platforms</p>\n<p>         Firewalls, TCP/IP networking, LAN/WAN infrastructure</p>\n<p>         Endpoint protection and anti‑malware solutions</p>\n<p>         IDS/HIDS platforms</p>\n<p>         Microsoft 365 security tools</p>\n<ul>\n <li>Demonstrated ability to reconcile configuration changes and validate security controls.</li>\n <li>Qualified military veterans are encouraged to apply.</li>\n <li>Must be professional, comfortable speaking with external and internal contacts with a demonstrated ability to tailor the message appropriately to the audience and situation effectively.</li>\n <li>Ability to relay technical information to both technical and non-technical personnel.</li>\n <li>Ability to write technical documentation.</li>\n <li>Demonstrated ability to convey thoughts and ideas effectively and succinctly via written formats, including emails, letters, and electronic platforms. Maintain professional standards relating to spelling and grammar.</li>\n <li>Maintain credibility through professional demeanor, appearance, and presence by modeling standards appropriate to our environment and industry.</li>\n <li>Maintain good working relationships with internal partners by exhibiting exemplary interpersonal skills, adopting a constructive, solutions-focused approach.</li>\n <li>Use sound professional judgment to balance the interests of the organization and customer, understanding and using available resources to mitigate risks.</li>\n <li>Proficiency with Microsoft 365 products and applications, including the ability to effectively prepare or review documents, procedures, and reports.</li>\n <li>Proficiency in Network Management and Firewalls, Servers, TCP/IP Schema, Remote Access Solutions, & NFS/ISCCI/CIFS networking/storage interdependencies.</li>\n <li>Demonstrated ability to learn new systems and applications, as well as the ability to understand, adapt and adjust responsibilities/workflows as a result of system upgrades. </li>\n <li>Occasional travel to other First American Bank locations, Bank functions, and training facilities may be required.</li>\n <li>Typical schedule is Monday through Friday 8:00 a.m. to 5:00 p.m. Additional hours may be required depending upon business need.</li>\n <li>Rotational Saturday work and off-hours on-call availability.</li>\n <li>Punctuality is required to maintain First American Bank’s customer service standards.</li>\n</ul>",
    "directApply": true,
    "jobLocation": [
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "60007",
          "addressRegion": "IL",
          "streetAddress": "700 Busse Rd",
          "addressCountry": "US",
          "addressLocality": "Elk Grove Village",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      }
    ],
    "validThrough": "2027-05-14T04:00:00.000Z",
    "employmentType": "FULL_TIME",
    "salaryCurrency": "USD",
    "responsibilities": "First American Bank was founded in Chicago, and over the years has expanded throughout Wisconsin and Florida.  As the largest privately held bank in Illinois, we now have over 60 locations and assets of $8+ billion.  We are a community bank at heart with international expertise, traditional values, and a forward-looking philosophy.  Our employees have the experience and vision to meet the needs of savers, borrowers, and businesses in the 21st century.  First American Bank can offer employees a level of visibility, career growth, and stability that is difficult to find in many larger corporations. \r\n \r\nThe Technical Incident Response Analyst is responsible for monitoring, analyzing, and responding to cybersecurity alerts and incidents across enterprise infrastructure and security platforms. This role serves as a primary investigator for security events, ensuring timely detection, containment, remediation, documentation, and escalation of incidents in alignment with established incident response playbooks, regulatory requirements, and internal controls.\r\n \r\nThe position combines real‑time alert monitoring, technical investigation, firewall and configuration change validation, and execution of defined recurring operational tasks to maintain a strong security posture across the organization.\r\n \r\nDUTIES & RESPONSIBILITES\r\n- Monitor and respond to cybersecurity alerts generated from SIEM provider dashboards and security monitoring platforms.\r\n- Investigate, remediate, and document security incidents reported through automated alerts, tickets, emails, phone calls, or external SOC notifications.\r\n- Act as the primary investigator for potential security incidents identified by SOC analysts or monitoring tools.\r\n- Follow documented incident response playbooks while exercising sound judgment to contain and remediate threats.\r\n- Investigate phishing emails, user‑reported security concerns, and potential attempts at fraud or financial loss.\r\n- Review authentication, endpoint, network, and application activity for anomalous or malicious behavior.\r\n- Analyze firewall logs, IDS alerts, intrusion prevention activity, anti‑malware events, server logs, and application logs.\r\n- Monitor intrusion detection systems, for indicators of compromise or suspicious activity.\r\n- Correlate data across SIEM, IDS, endpoint, and firewall platforms to support incident investigations.\r\n- Perform log reviews using standardized incident response and log review templates.\r\n- Perform reconciliation of firewall rule and configuration changes.\r\n- Validate that all changes are authorized, approved, and compliant with change management and security policies.\r\n- Identify unauthorized or out‑of‑policy changes and escalate violations as required\r\nExecute daily, weekly, and periodic tasks defined in the Incident Response recurring task schedule, including:\r\n \r\n         Reviewing Microsoft Defender security incidents and assigning or resolving alerts.         \r\n         Reviewing external SOC (e.g., Proficio) incident tickets to ensure proper closure.\r\n         Reviewing SIEM and Kibana dashboards for authentication failures and other abnormal activity.\r\n         Validating completion and documenting evidence through screenshots and reports.\r\n- Document incident activity, evidence, analysis, and remediation actions in an audit‑ready manner.\r\n- Communicate incident status clearly to Information Security leadership, infrastructure teams, and management.\r\n- Provide incident reporting suitable for internal audit, regulatory examination, and compliance reviews.\r\n- Track incidents end‑to‑end to ensure timely closure and proper documentation.\r\n- Participate in SOC and security working group sessions to improve detection rules and reduce false positives.\r\n- Review and update automated alerts and incident response playbooks for accuracy and effectiveness.\r\n- Collaborate with networking, systems, endpoint, and application teams during investigations.\r\n \r\nQUALIFICATIONS\r\n- Minimum of three years of experience directly related to incident response, security monitoring, or cybersecurity operations.\r\n- Hands‑on experience with SIEM platforms, incident response tooling, and alert monitoring solutions.\r\n- Experience with firewall technologies, network security concepts, and endpoint protection platforms.\r\n- Experience performing log analysis and incident investigations across multiple data sources.\r\n- Exposure to Linux operating systems preferred.\r\nWorking knowledge of:\r\n \r\n         SIEM and security monitoring platforms\r\n         Firewalls, TCP/IP networking, LAN/WAN infrastructure\r\n         Endpoint protection and anti‑malware solutions\r\n         IDS/HIDS platforms\r\n         Microsoft 365 security tools\r\n- Demonstrated ability to reconcile configuration changes and validate security controls.\r\n- Qualified military veterans are encouraged to apply.\r\n- Must be professional, comfortable speaking with external and internal contacts with a demonstrated ability to tailor the message appropriately to the audience and situation effectively.\r\n- Ability to relay technical information to both technical and non-technical personnel.\r\n- Ability to write technical documentation.\r\n- Demonstrated ability to convey thoughts and ideas effectively and succinctly via written formats, including emails, letters, and electronic platforms. Maintain professional standards relating to spelling and grammar.\r\n- Maintain credibility through professional demeanor, appearance, and presence by modeling standards appropriate to our environment and industry.\r\n- Maintain good working relationships with internal partners by exhibiting exemplary interpersonal skills, adopting a constructive, solutions-focused approach.\r\n- Use sound professional judgment to balance the interests of the organization and customer, understanding and using available resources to mitigate risks.\r\n- Proficiency with Microsoft 365 products and applications, including the ability to effectively prepare or review documents, procedures, and reports.\r\n- Proficiency in Network Management and Firewalls, Servers, TCP/IP Schema, Remote Access Solutions, & NFS/ISCCI/CIFS networking/storage interdependencies.\r\n- Demonstrated ability to learn new systems and applications, as well as the ability to understand, adapt and adjust responsibilities/workflows as a result of system upgrades. \r\n- Occasional travel to other First American Bank locations, Bank functions, and training facilities may be required.\r\n- Typical schedule is Monday through Friday 8:00 a.m. to 5:00 p.m. Additional hours may be required depending upon business need.\r\n- Rotational Saturday work and off-hours on-call availability.\r\n- Punctuality is required to maintain First American Bank’s customer service standards.",
    "hiringOrganization": {
      "name": "First American Bank",
      "@type": "Organization",
      "sameAs": "UNAVAILABLE"
    },
    "occupationalCategory": "Information Technology"
  },
  "detail_meta": {
    "url": "https://careers-firstambank.icims.com/jobs/3385/technical-incident-response-analyst---hybrid-%28il%29/job?in_iframe=1",
    "http_status": 200,
    "content_type": "text/html;charset=UTF-8",
    "response_bytes": 72572,
    "compact_response_bytes": 15983,
    "original_response_bytes": 72572
  },
  "sitemap_job": {
    "id": "3385",
    "url": "https://careers-firstambank.icims.com/jobs/3385/technical-incident-response-analyst---hybrid-%28il%29/job",
    "slug": "technical-incident-response-analyst---hybrid-%28il%29",
    "lastmod": "2026-06-09T14:53:20-04:00"
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/106730c08048e964092b40ca837940ec1c59f0e0?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/f4a5c649-d658-4074-b536-b9562282bcb1JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/8e7ea43b-f5e3-4c87-8112-f6caa8250eb8JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/106730c08048e964092b40ca837940ec1c59f0e0/eventsJSON