Career

Cybersecurity careers by domain

Explore job families and certification issuers — two ways to map credentials to your path.

Incident Responder

Leads containment, eradication, and recovery during security incidents.

Roles in this job family

  • Incident Response Analyst

    Mid-level

    Executes playbooks, collects artifacts, and documents timelines.

  • Incident Response Manager

    Senior

    Coordinates stakeholders, communications, and post-incident reviews.

Related certifications

GCIH

GCIH

GIAC Certified Incident Handler

GIAC / SANS

Incident handling credential focused on detecting intrusions, collecting evidence, and coordinating effective response workflows.

Recruiter appeal
4.5
Difficulty
Medium
Community

ECIH

ECIH

EC-Council Certified Incident Handler

EC-Council

Incident response certification for handling breaches, containment, eradication, and recovery with structured IR playbooks.

Recruiter appeal
3.5
Difficulty
Medium
Community

GCFA

GCFA

GIAC Certified Forensic Analyst

GIAC / SANS

Digital forensics certification covering host and network artifact analysis, timeline reconstruction, and evidence handling.

Recruiter appeal
4.7
Difficulty
Hard
Community

CySA+

CySA+

CompTIA Cybersecurity Analyst

CompTIA

Analyst-level credential covering threat detection, vulnerability management, and security monitoring operations.

Recruiter appeal
4.4
Difficulty
Medium
Community

GCIA

GCIA

GIAC Certified Intrusion Analyst

GIAC / SANS

Advanced SOC and intrusion analysis certification for network traffic, IDS/IPS, and attacker technique detection.

Recruiter appeal
4.5
Difficulty
Hard
Community

GREM

GREM

GIAC Reverse Engineering Malware

GIAC / SANS

Malware analysis and reverse engineering for investigators — static/dynamic analysis, unpacking, and threat intelligence workflows.

Recruiter appeal
4.5
Difficulty
Hard
Community

SC-200

SC-200

Microsoft Security Operations Analyst

Microsoft

SOC analyst path using Microsoft Sentinel and Defender for threat detection and incident response.

Recruiter appeal
4.4
Difficulty
Medium
Community

GSEC

GSEC

GIAC Security Essentials

GIAC / SANS

Broad technical security baseline covering networking, IAM, crypto, and defense fundamentals.

Recruiter appeal
4.4
Difficulty
Medium
Community

GCFE

GCFE

GIAC Certified Forensic Examiner

GIAC / SANS

Windows-focused digital forensics certification for investigators collecting and analyzing endpoint evidence.

Recruiter appeal
4.3
Difficulty
Medium
Community

CCNP Sec

CCNP Sec

Cisco Certified Network Professional Security

Cisco

Network security professional track covering firewalls, VPNs, identity, automation, and secure network architecture on Cisco stacks.

Recruiter appeal
4.3
Difficulty
Hard
Community

SecurityX

SecurityX

CompTIA SecurityX

CompTIA

Advanced practitioner certification (CAS-004) for senior security architects — technical depth beyond CASP+ in enterprise environments.

Recruiter appeal
4.3
Difficulty
Hard
Community

CCFA

CCFA

CrowdStrike Certified Falcon Administrator

CrowdStrike

Validates deployment and administration of the CrowdStrike Falcon platform: sensors, prevention policies, detection tuning, and operational response workflows. Common for SOC and endpoint security teams standardizing on Falcon.

Recruiter appeal
4.3
Difficulty
Medium
Community

BTL1

BTL1

Blue Team Level 1

Security Blue Team

Practical blue-team certification focused on log analysis, SIEM workflows, and incident triage for SOC analysts.

Recruiter appeal
4.2
Difficulty
Easy
Community

CSLS

CSLS

Certified Stormshield Log Supervisor

Stormshield

Certification sur Stormshield Log Supervisor (SLS) : collecte de logs SNS, tableaux de bord, rapports, règles d'alarme et investigation SOC. Prérequis CSNA. Complète le parcours défensif Stormshield aux côtés de CSNE.

Recruiter appeal
4.2
Difficulty
Medium
Community

SSCP

SSCP

Systems Security Certified Practitioner

(ISC)²

Hands-on security operations certification spanning access controls, incident response, and network monitoring.

Recruiter appeal
4.1
Difficulty
Medium
Community

CHFI

CHFI

Computer Hacking Forensic Investigator

EC-Council

Digital forensics investigation certification for evidence handling and incident analysis.

Recruiter appeal
4.0
Difficulty
Medium
Community

GASF

GASF

GIAC Advanced Smartphone Forensics

GIAC

GIAC Advanced Smartphone Forensics — professional certification mapped from the Paul Jerimy security certification roadmap.

Recruiter appeal
4.0
Difficulty
Hard
Community

GBFA

GBFA

GIAC Battlefield Forensics and Acquisition

GIAC

GIAC Battlefield Forensics and Acquisition — professional certification mapped from the Paul Jerimy security certification roadmap.

Recruiter appeal
4.0
Difficulty
Hard
Community

GCFR

GCFR

GIAC Cloud Forensics Responder

GIAC

GIAC Cloud Forensics Responder — professional certification mapped from the Paul Jerimy security certification roadmap.

Recruiter appeal
4.0
Difficulty
Hard
Community

GNFA

GNFA

GIAC Network Forensic Analyst

GIAC

GIAC Network Forensic Analyst — professional certification mapped from the Paul Jerimy security certification roadmap.

Recruiter appeal
4.0
Difficulty
Hard
Community

Learning resources