Toyota Tsusho Systems
Incident Response Analyst (Mid-Senior Level)
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 10 days ago · Found 38m ago
First listed 10 days ago and still open.
Salary
Not stated
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
This employer didn't state pay. Jobs like this usually pay around $160k–$220k a year, a typical range taken from 597 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Plano, United States, Plano, Texas, United States, Plano, Texas, United States, Remote"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Founded in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) is a Toyota group company, that develops IT solutions wherever global businesses operate. Transforming into a technology and mobility company, TTS-US with it's 8 TTS affiliates worldwide is establishing a secure and resilient Toyota global value chain. The creative capacity to forge such limitless business opportunities is one of the strengths of Toyota Tsusho Systems. We are seeking a skilled and experienced Incident Response Analyst to join our collaborative cybersecurity incident response team within the Threat Research, Response & Analysis Center (TRRAC). In this role, you will combine technical expertise in digital forensics and incident response with proactive threat intelligence and hunting activities. You will respond to critical security incidents across the ecosystem, conduct comprehensive forensic investigations, and collaborate closely with the 24/7 SOC and other cybersecurity teams. When not actively responding to incidents, you will contribute to threat hunting, cyber threat intelligence, tooling improvements, and the development of SOPs and training materials—helping to elevate the entire team's capabilities.
What You'll Be Doing
Conduct comprehensive incident response activities following the NIST Cybersecurity Framework across all phases: Initial Detection, Analysis & Validation, Containment, Eradication, Recovery, and Post-Incident Activity.
Respond to cyber incidents impacting TMNA Corporate, Manufacturing Plants, Third-Parties, Dealerships, and RSOC Customers.
Perform digital forensic investigations including collection, processing, and analysis of forensic evidence from diverse devices (Windows, Linux, macOS, mobile).
Maintain an "Always Be Timelining" (ABT) approach, continuously updating incident timelines as findings are discovered.
Support proactive, reactive, and exploratory threat hunting activities across the ecosystem.
Analyze emerging cyber threats, attacker TTPs, and track threat actors/groups to anticipate and mitigate potential attacks.
Collaborate closely with the 24/7 SOC, Threat Detection Engineering, Vulnerability Management, and Insider Risk Management teams.
Prepare and deliver forensic reports, incident communications, and executive updates during active incidents.
Participate in weekly on-call rotation schedule for 24/7 incident response coverage.
Conduct malware analysis (behavioral and static) using TRRAC Labs' dynamic analysis capabilities.
Help develop, refine, and maintain incident response playbooks, SOPs, and training materials to improve team effectiveness.
Participate in quarterly tabletop exercises to test incident response workflows and controls.
Stay current on emerging threats, attacker techniques, and industry best practices.
Requirements
· Minimum of 3-5 years of hands-on experience in incident response and digital forensics.
· Proven ability to act as Incident Commander within a team setting during high-pressure incidents.
· Strong technical expertise in Windows, Linux, and macOS internals related to monitoring and threat detection.
· Experience with cloud security incident response and threat mitigation.
· Skilled in malware analysis (behavioral and static) and basic cryptanalysis.
· Familiarity with security frameworks and compliance standards (NIST, HIPAA, ISO, OWASP, etc.).
· Proficient with DFIR tools such as Autopsy, The Sleuth Kit, Volatility, Magnet Axiom, FTK, and others.
· Competent in scripting languages like Python, PowerShell, and Bash for automation and analysis.
Requirements
- ·· Minimum of 3-5 years of hands-on experience in incident response and digital forensics.
- ·· Proven ability to act as Incident Commander within a team setting during high-pressure incidents.
- ·· Strong technical expertise in Windows, Linux, and macOS internals related to monitoring and threat detection.
- ·· Experience with cloud security incident response and threat mitigation.
- ·· Skilled in malware analysis (behavioral and static) and basic cryptanalysis.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Toyota Tsusho Systems, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 38m ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $160k to $220k per year · You'll be taken to the employer's careers page.