Back to jobs
Eaton10K+ employees

Senior Incident Response Ready Analyst

Beachwood, OH$113,000 – $165,000Posted 9 days ago

Immigration summary

Visa sponsorship

UnclearLow confidence

The posting's wording is ambiguous.

113 recent H-1B filings

View visa evidence

Green card sponsorship

Some historyMedium confidence

This employer has recently sponsored green cards.

17 recent certified PERM filings

View green card evidence

Job description

Eaton’s Corporate Sector division is currently seeking a Senior Incident Response Ready Analyst.  The expected annual salary range for this role is $113000 - $165000 a year.

Please note the salary information shown above is a general guideline only. Salaries are based upon candidate skills, experience, and qualifications, as well as market and business considerations.

What you’ll do:

The Senior Incident Response Readiness Analyst is a senior individual contributor responsible for strengthening the organization’s ability to prepare for, respond to, and recover from cyber, technology, and operational disruptions. This role focuses on incident response planning, playbook development, Product Owner and business stakeholder advisory support, readiness exercises, training, awareness, and continuous improvement. The position partners with technology, product, business, crisis management, communications, legal, cybersecurity, infrastructure, and business continuity stakeholders to create and validate response plans, maintain BCDR and incident response artifacts, coordinate readiness activities, assess response and recovery capabilities, report program health, and drive remediation of identified gaps. Through this work, the Senior Incident Response Readiness Analyst helps ensure that critical services, applications, business capabilities, response teams, and third-party dependencies are prepared to execute coordinated, timely, and effective response and recovery activities in alignment with enterprise resiliency standards and business impact expectations.

Job Responsibilities:

  • Maintain and update BCDR and incident response readiness artifacts, including BIAs, recovery plans, runbooks, incident response plans, playbooks, RTO/RPO targets, escalation paths, response owner rosters, and dependency mappings.
  • Develop, maintain, validate, and improve incident response plans and playbooks for critical products, applications, services, business capabilities, and supporting technology environments.
  • Advise Product Owners and business stakeholders on response roles, decision points, escalation criteria, communications expectations, recovery dependencies, plan ownership, maintenance responsibilities, and readiness requirements.
  • Serve as an incident response coordinator during cyber, technology, or operational incidents by supporting playbook activation, war room coordination, containment and triage task tracking, action documentation, timeline management, stakeholder updates, and post-incident review activities.
  • Plan, design, and execute incident response readiness activities such as tabletop exercises, simulation drills, playbook walkthroughs, service failovers, and recovery rehearsals; define objectives, scenarios, success criteria, and evidence expectations.
  • Author and maintain incident response materials, exercise materials, response checklists, evidence capture templates, communication guidance, lessons-learned reports, maturity updates, and remediation tracking artifacts.
  • Liaise with application, service, product, infrastructure, cybersecurity, business continuity, and business owners to validate response procedures, recovery procedures, escalation contacts, acceptance criteria, and response ownership.
  • Coordinate with Crisis Management, Communications, Legal, cybersecurity, infrastructure, business continuity, and executive stakeholders to ensure integrated response, escalation, stakeholder briefing, and recovery planning alignment.
  • Manage third-party continuity and incident response dependencies by integrating vendor roles, escalation contacts, contractual expectations, service restoration assumptions, and recovery dependencies into plans, playbooks, and exercises.
  • Measure and report incident response readiness program health, including plan coverage, playbook quality, exercise results, incident lifecycle metrics, time-to-coordinate containment or initial recovery actions, stakeholder readiness, training completion, and remediation closure.
  • Train and onboard incident responders, Product Owners, business stakeholders, recovery participants, and support teams; deliver awareness sessions and readiness guidance to build organizational maturity in incident response planning and execution.

Qualifications:

Basic (required) Qualifications:

  • Bachelor’s degree from an accredited institution
  • Minimum of five (5) years of experience in in incident response readiness, cyber incident response, business continuity, disaster recovery, cyber resilience, crisis management, technology risk, IT operations, cybersecurity operations, or an equivalent combination.
  • Strong understanding of the incident response lifecycle, including preparation, detection support, triage coordination, escalation, containment coordination, recovery support, stakeholder communications, post-incident review, and continuous improvement.
  • Must be legally authorized to work in the US without company sponsorship No relocation is offered for this position. All candidates must currently reside within 50 miles of Beachwood, OH, Galesburg MI, Houston TX, Menomonee Falls WI, Moon Township PA, or Raleigh NC to be considered.
  • Must be authorized to work in the United States without company sponsorship now or in the future

Preferred Qualifications:

  • Experience developing, maintaining, and improving incident response plans, playbooks, runbooks, escalation paths, response checklists, evidence capture templates, communication guidance, and lessons-learned documentation.
  • Demonstrated ability to advise Product Owners, business stakeholders, application teams, infrastructure teams, and recovery owners on incident response readiness expectations, plan ownership, response roles, decision points, communications, recovery dependencies, and maintenance requirements.
  • Experience designing and facilitating incident response readiness activities, including tabletop exercises, simulation drills, playbook walkthroughs, war room simulations, service failovers, recovery rehearsals, and after-action reviews.
  • Familiarity with BCDR concepts, BIA outputs, RTO/RPO targets, recovery planning, escalation frameworks, crisis management practices, business continuity operating models, service restoration practices, and enterprise resiliency standards.
  • Technical familiarity with cybersecurity operations, application recovery, infrastructure recovery, cloud services, backups, replication, virtualization, endpoint recovery, networking, third-party dependencies, and service management processes.
  • Strong facilitation and coordination skills, with the ability to lead cross-functional readiness workshops, response planning sessions, exercises, post-mortems, remediation reviews, and stakeholder briefings.
  • Strong documentation, training, reporting, project coordination, governance support, and continuous improvement capabilities, including the ability to develop maturity metrics and communicate program health.
  • Certifications preferred: GCIH, CISSP, CISM, CBCP, DRCP, MBCP, ISO 22301 Lead Implementer or Auditor, ITIL, CISA, or related incident response, cybersecurity, resilience, or continuity credentials.

Skills:

Soft skills

  • Analytical thinker with attention to detail and process orientation.
  • Able to translate technical risk into actionable recovery plans and testable requirements.
  • Effective trainer/facilitator and confident presenter.
  • Project oriented with the ability to manage multiple DR/IR initiatives and deliverables.
  • Calm under pressure with strong follow-through for continuous improvement.

All positions may require participation in video and in-person interviews as part of the hiring process. All candidates will be evaluated based on job-related competencies, and all candidates’ privacy rights and data security will be protected in accordance with applicable laws.

We are committed to ensuring equal employment opportunities for all job applicants and employees. Employment decisions are based upon job-related reasons regardless of an applicant's race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, marital status, genetic information, protected veteran status, or any other status protected by law.

Eaton believes in second chance employment. Qualified applicants with arrest or conviction history will be considered regardless of their arrest or conviction history, consistent with the Los Angeles County Fair Chance Ordinance, the California Fair Chance Act and other local laws.

You do not need to disclose your conviction history or participate in a background check until a conditional job offer is made to you. After making a conditional offer and running a background check, if Eaton is concerned about conviction that is directly related to the job, you will be given the chance to explain the circumstances surrounding the conviction, provide mitigating evidence, or challenge the accuracy of the background report.

To request a disability-related reasonable accommodation to assist you in your job search, application, or interview process, please call us at 1-800-836-6345 to discuss your specific need. Only accommodation requests will be accepted by this phone number.

We know that good benefit programs are important to employees and their families. Eaton provides various Health and Welfare benefits as well as Retirement benefits, and several programs that provide for paid and unpaid time away from work. Click here for more detail: Eaton Benefits Overview. Please note that specific programs and options available to an employee may depend on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.

Sponsorship evidence

Why Openbound reached the conclusions above.

Visa sponsorship evidence

Current posting

Asks for work authorization, silent on sponsorship

“Authorized to work in the United States”

Detected directly from this job posting.

Other openings

9 of 2431 recent openings at this employer mention sponsorship.

Employer H-1B history

113
recent certified H-1B filings
79
new-hire petitions
0
filings for similar roles
99
so far in FY2026
More evidence details
  • 113 recent certified H-1B filings across the employer
  • Still filing this year — 99 filings in FY2026
  • 15 USCIS H-1B new-employment approvals, counted separately from LCA filings
  • Some filing activity in OH
  • 9 other recent postings at this company mention sponsorship
  • 111 further USCIS approvals for extensions or transfers
  • The posting asks for work authorisation without saying whether sponsorship is available
  • We checked 170 filing titles for this employer and none describe work like this role
  • 32 other recent postings at this company state a sponsorship restriction

Some filing activity in OH.

Green card sponsorship evidence

Employer PERM history

17
recent certified PERM filings
0
filings for similar roles
3
filings in this location
Certified PERM filings by fiscal year
202312
20248
202524
202613YTD

Filing history reflects past employer behavior; it isn't a promise for this opening.

All open roles at Eaton
How Openbound evaluates sponsorship

Visa history uses official U.S. Department of Labor H-1B LCA disclosure data and USCIS H-1B petition history. Green card history uses DOL PERM disclosure data. Each is read for the employer as a whole, for roles like this one, and for this location, weighted toward the most recent fiscal years.

An employer is matched to its filing entities by verified legal name and reviewed aliases; a match is never made on a name resemblance alone. Where no verified entity can be matched, the page says so and draws no conclusion from the absence. 170 filing titles were examined for this employer.

What this posting states outranks history in both directions, and an employer's published policy outranks past filings. Filing history reflects past behavior; it is not a promise of sponsorship for this opening, and none of this is legal advice.