Remote Incident Response Engineer Jobs
Remote incident response engineer jobs are open across cybersecurity, financial services, healthcare technology, and cloud infrastructure, with hiring concentrated at remote-first security firms, managed detection and response providers, and distributed enterprise security teams. Roles range from entry-level SOC-adjacent positions to senior and staff-level incident commander roles. Employers hiring remotely right now include Google, Quorum Cyber, and FICO. Scan the live roles below and apply to whichever ones fit.
Find JobsOverview
Showing 5 of 20+ Remote Incident Response Engineer jobs




Position Overview
OSC Technical Solutions is seeking a Cyber Security Analyst III – Digital Forensics and Incident Response to support incident response for the cybersecurity program at the U.S. Department of Energy Hanford Site in Richland, Washington. The Analyst conducts forensic investigations on target endpoints, monitors and responds to security events across the enterprise, and contributes to remediation and reporting for confirmed incidents. This is a mid-level role that combines hands-on technical investigation with growing responsibility for process improvement and for mentoring junior analysts.
Major Activities (Typical Duties/Responsibilities)
- Utilize digital forensics tools to conduct forensic investigations on target endpoints.
- Utilize a range of security tools (e.g., SIEM, NIDS, SOAR, Endpoint Protection, Firewalls, DLP, Email Filtering, Scanners, PCAP) to monitor, analyze, and respond to security events on the network.
- Follow established procedures to identify reportable security incidents; act as an incident handler by gathering data and artifacts, performing analysis, writing incident reports, reporting to management, and carrying out mitigating actions to contain and recover from cyber-attacks.
- Monitor and respond to reports and threat intelligence from various sources.
- Distribute threat advisories, vulnerability reports, and official directives to customers and leadership.
- Participate in disaster recovery exercises and events.
- Support operation and maintenance of security tools.
- Support cyber security audits, assessments, data calls, and investigations.
- Manage projects and processes independently with limited supervision.
- Coach and review the work of lower-level professionals.
- Serve as a technical mentor and trainer for junior analysts.
- Perform other duties as appropriate and as assigned.
Knowledge/Skills/Abilities
- Working knowledge of a cyber security compliance framework, such as the National Institute of Standards and Technology (NIST), Center for Internet Security (CIS) Critical Security Controls, or ISO 27001/27002.
- Ability to set and manage priorities judiciously.
- Excellent written and verbal communication and interpersonal skills.
- Ability to work cooperatively in a team environment.
- Strong customer service orientation.
Physical Abilities
- Sufficient fine motor skills for the use of computers, calculators with an ability to withstand repetitive keyboarding for extended periods of time.
- Visual and communications ability adequate to perform the essential functions of the job.
- Ability to kneel, bend and twist at the waist on an occasional basis.
- Ability to reach below shoulder height with regular frequency (desk position) and at or above shoulder height on occasion.
- Ability to push, pull, carry and lift objects weighing up to 10 pounds on a regular basis, and greater weights on an occasional basis.
- Ability to travel by vehicle or aircraft, and ability to safely operate a motor vehicle
Minimum Requirements
- Bachelor's Degree and 5 or more years of experience, or an equivalent combination of education, training and experience
- Ability to pass a pre-employment background check and drug screening.
- Must have identification compliant with the REAL ID Act at time of hire.
- Must be able to obtain and maintain a Department of Energy access authorization (HSPD-12 PIV credential); this requires a successful federal background investigation.
Preferred Qualifications
- Bachelor's Degree in Cyber Security, Computer Science or related field
- Experience in cyber security, information technology, systems analysis, or a similar role, including hands-on incident response or digital forensics experience.
- Certifications such as GCFA, GCIH, GNFA, CySA+, or CEH.
- Experience with industrial control system (ICS) / operational technology (OT) security or other federal FISMA-regulated environments.
Pay Range: $100,457.00- $161,384.00
Benefits: OSC Technical Solutions offers excellent benefits for eligible employees. Benefits include paid holidays, paid time off, 401k with employer match, dental, vision, health insurance plans through the Federal Employee Health Benefits (FEHB) program, as well as life and disability benefits.
OSC Technical Solutions does not discriminate, and the company provides equal employment opportunity for all employees and applicants without regard to race, religion, color, sex, gender, sexual orientation, national origin, citizenship status, age, marital status, pregnancy or parenthood, handicap or disability, genetics, veteran status or any other legally protected characteristic. OSC Technical Solutions adheres to all federal, state and local laws regarding equal employment opportunity and will not discriminate against you in violation of these laws. OSC Technical Solutions reserves the right to apply CIRI Shareholder preference to qualified Shareholders in employment and advancement opportunities.
OSC Technical Solutions participates in E-Verify. We will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee's Form I-9 to confirm work authorization.
Reasonable Accommodation:
OSC Technical Solutions will provide reasonable accommodations, according to applicable state and federal laws, to all qualified individuals with physical or mental disabilities. In compliance with the ADA Amendments Act (ADAAA), if you have a disability and would like to request an accommodation in order to apply for a position with OSC Global, LLC or any of its subsidiaries, please email recruiting@ciri.com.
Important Employment Notice: Federal Contract & RCW 49.44.240:
Due to our status as a federal contractor operating within the State of Washington, all applicants and employees must adhere to federal law, which classifies cannabis as a Schedule I controlled substance.
While Washington State’s RCW 49.44.240 (which generally prohibits employers from discriminating against an applicant based on their lawful use of cannabis off-site and during working hours) is state law, it does not supersede federal requirements.
Zero-Tolerance Policy and Disqualification
- Prohibition: The use, possession, or distribution of cannabis is strictly prohibited for all employees, regardless of state law.
- Testing: Applicants will be subject to pre-employment drug screening that includes testing for cannabis.
- Disqualification: A positive test result for cannabis will result in immediate disqualification from consideration for employment, as mandated by our federal contract obligations.
All applicants must be able to comply with all federal regulations, including those concerning controlled substances, as a condition of employment.
In compliance with Homeland Security Presidential Directive 12 (HSPD-12) and Department of Energy (DOE) Hanford Field Office (HFO) direction, employees issued initial badges on or after September 1st, 2025, are required to obtain and maintain a HSPD-12 Personal Identity Verification (PIV) Credential. To obtain this credential, new employees must successfully complete and pass a federal background check investigation. This investigation encompasses multiple areas of eligibility and includes a declaration of illegal drug activities, including use, supply, possession, or manufacture within the last year. This includes marijuana and cannabis derivatives, which are still considered illegal under federal law, regardless of state laws.
See All 20 Remote Incident Response Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Incident Response Engineer Job Market
Who's Hiring


Top Industries Hiring
- Technology & Software
What Employers Look For
The qualifications that appear most often in remote incident response engineer jobs.
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- Proficiency in digital forensics and malware analysis using tools like Volatility, FTK, or EnCase
- Knowledge of network traffic analysis and packet inspection with Wireshark or similar tools
- Relevant certification such as GCIH, GCFE, Security+, or CySA+
- Familiarity with endpoint detection and response platforms including CrowdStrike, SentinelOne, or Carbon Black
- Bachelor's degree in cybersecurity, computer science, information systems, or equivalent practical experience
Tips for Your Remote Incident Response Engineer Job Search
Apply early to remote roles that fit
Migrate Mate lists remote incident response engineer openings from across the U.S. in one place. Check it regularly and apply directly to roles that match your stack and seniority level before postings fill.
Document your incident-handling process publicly
Remote hiring managers can't watch you work, so show your process instead. Write up a post-incident review from a lab exercise or CTF, publish it, and link it in your application. Concrete documented decisions replace in-person reputation.
Prove async communication skills before the interview
Remote incident response teams rely on Slack, JIRA, and written runbooks during live incidents. Prepare concise written answers to technical screening questions and send follow-up emails that are clear and structured. Your writing is your first audition.
Emphasize remote tooling fluency on your resume
Call out specific SIEM platforms, EDR tools, ticketing systems, and collaboration tools you have used in distributed environments. Remote employers want to know you can operate their stack without onboarding hand-holding from day one.
Remote Incident Response Engineer Jobs: Frequently Asked Questions
How do I get a remote incident response engineer job?
Target companies with distributed security teams: remote-first MDR providers, cloud-native SaaS firms, and large enterprises that operate 24/7 SOCs across time zones. Remote hiring managers screen hard for self-direction, clear async written communication, and the ability to run an incident without real-time hand-holding. Demonstrable hands-on skills in SIEM platforms, endpoint forensics, and threat containment carry more weight than a polished resume alone.
Which companies hire remote incident response engineers?
Employers currently hiring remote incident response engineers include Google, Quorum Cyber, and FICO, per current remote listings on Migrate Mate as of September 2026. Remote openings for this role are most common at managed detection and response firms, cybersecurity consultancies, and large distributed enterprises across technology, financial services, and healthcare.
Can you get a remote incident response engineer job with no experience?
Yes, but remote entry roles are harder to land because employers expect you to triage and contain incidents without someone physically nearby to ask. Candidates who break in typically show home lab projects, documented CTF participation, or a self-built detection environment. Smaller remote-first MSSPs and cybersecurity consultancies are more open to entry-level hires than enterprise teams that need someone ready to work independently from day one.
Do you need a degree for remote incident response engineer jobs?
Not always. Remote employers in cybersecurity weigh practical skills, certifications like GCIH, GCFE, or CEH, and demonstrated incident-handling experience heavily alongside or instead of a degree. Candidates who can show documented playbooks they have written, real incident timelines they have managed, or lab environments they have built often compete effectively against degree holders for remote roles.
Which industries hire the most remote incident response engineers?
The sectors hiring the most remote incident response engineers are Technology & Software, based on current remote listings on Migrate Mate as of September 2026. These industries run distributed security operations across multiple time zones, which makes remote incident response engineers a practical and often preferred staffing model.
See All 20 Remote Incident Response Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs