Security Incident Response Analyst
Straight from Match Group’s careers page. Apply on the company site — no recruiter, no middleman.
Security Incident Response Analyst
Team: Security
Location: Vancouver, British Columbia
Commitment: Full-time
Workplace Type: hybrid
Salary:
This salary range is reflective of Vancouver, Canada. For all other locations, this salary may be subject to a geographic adjustment (according to a specific city and state), if an authorization is granted to work outside of the location listed in this posting.
Match Group is a leading provider of dating products across the globe. Our portfolio includes Tinder, Hinge, Match, Meetic, PlentyOfFish, OkCupid, The League, HER, and others, each designed to spark meaningful connections for singles worldwide. Creating a sense of belonging doesn’t stop at our products - it’s the foundation of every team we hire.
About Match Group
Match Group (NASDAQ: MTCH) is a leading provider of dating products across the globe, operating a portfolio of brands including Tinder, Hinge, Match, OkCupid, Pairs, Meetic, and more. With hundreds of millions of users worldwide generating billions of interactions daily, our scale demands world-class security operations.
About the Team
The MG Security Engineering organization provides unified security services across all Match Group brands. The Monitoring, Incident Response & SOC team is responsible for real-time threat detection, investigation, and response across the full portfolio — operating 24/7 to ensure security alerts are effectively triaged and responded to, minimizing the impact of potential threats.About the Role
Were looking for a senior individual contributor to join our Detection & Response team as a Security Incident Response Analyst. In this role, youll serve as a senior-level investigator responsible for detecting, analyzing, and responding to advanced security threats across on-prem and cloud infrastructure in a multi-vendor environment. Youll lead investigations spanning phishing, malware, insider threats, and other complex security incidents — driving them from initial detection through containment, eradication, and recovery.
What Youll Do
- Lead end-to-end investigations into phishing, malware, insider threats, and other advanced security incidents
- Triage and analyze security alerts, distinguishing true threats from noise, and prioritize response based on risk and business impact.
- Perform technical malware analysis, including static and dynamic examination of suspicious files, to determine behavior, capability, and intent.
- Conduct host and network-based analysis — analyzing system logs, processes, registry/configuration artifacts, memory, traffic patterns, DNS activity, and connection logs — to reconstruct attacker activity and identify persistence, command-and-control, lateral movement, and data exfiltration.
- Investigate cloud-native incidents by analyzing audit logs, IAM and access activity, and network flow data to detect unauthorized access, privilege misuse, and malicious file activities across cloud environments.
- Drive incidents through containment, eradication, and recovery, coordinating with cross-functional teams as needed.
- Develop and refine detection logic, playbooks, and response procedures to improve the teams ability to identify and act on emerging threats.
- Act as an escalation point for the most technically complex cases, mentoring junior analysts.
- Document findings and communicate clearly with both technical and non-technical stakeholders, including post-incident reports and executive summaries.
What Were Looking For
-
5+ years of experience in Incident Response, DFIR, or Security Operations
-
Experience leading significant security investigations
-
Strong familiarity with cloud environments (AWS and/or GCP)
-
Hands-on experience with SIEM, EDR, and log analysis
-
Solid understanding of identity systems and distributed architectures
-
Ability to stay composed and structured during high-pressure situations
-
Clear written and verbal communication skills
Nice to Have
-
Experience in large-scale consumer or SaaS environments
-
Experience working across global teams
-
Familiarity with privacy-related incident handling (e.g., GDPR)
-
Scripting or automation experience (Python, etc.)
Why This Role Matters
-
We operate global consumer platforms that handle sensitive user data. When incidents happen, the way we respond matters.
-
This role plays a key part in containing impact, protecting user trust, and improving our overall response maturity.
- Generous vacation, flex days, professional development days
- RRSP matching, and employee stock purchase plan
- Professional development budget and unlimited access to Udemy from day one
- Match Group mentorship program
- Parental leave top up and fertility preservation benefits
- Extended health & dental benefits from day one
- Corporate ClassPass membership and other wellness benefits
Similar remote jobs
All Security Analyst jobs →



KeyBank
Data Security Administrator
Discover More than 100,000 Hidden Remote Jobs Before Everyone Else
Unlock All Remote Jobs Today
Simple pricing. Big savings on Quarterly and Yearly.
Monthly Access
- Instant access to fresh remote jobs from 500+ companies
- New opportunities added hourly, often 3-7 days before anywhere else
- Advanced filtering by role type, stack, pay, and location
- Priority customer support
Yearly Access
- Everything in Monthly
- Save $169 (~74%) vs paying monthly
- Average job search takes ~6 months - get covered for the whole journey
- Less than the cost of one lunch per month for competitive advantage
- Equivalent to just ~$4.92/month