Senior Cyber Incident Responder

Labcorp

Durham (NC)

Hybrid

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Life insurance
STD/LTD
401(k)
Paid Time Off
Tuition Reimbursement
Employee Stock Purchase Plan

Job summary

Labcorp is seeking a cybersecurity professional to lead incident response for high-severity events impacting clinical operations, EHR, and PHI. You’ll coordinate with hospitals, clinics, and cloud environments to contain threats and drive playbook enhancements.

The role requires strong Windows/Linux investigation skills, experience with SIEM/EDR, and collaboration with privacy and compliance teams in a regulated healthcare setting. Hybrid schedule in the Durham/Burlington area.

Qualifications

  • Bachelor's degree required.
  • 3+ years in cybersecurity.
  • 5+ years in Windows/Linux investigations, network analysis, and EDR telemetry.
  • 2+ years with incident response frameworks (NIST 800-61, HITRUST IRM).
  • 2+ years with SIEM/EDR and forensic tools.

Responsibilities

  • Serve as lead responder for validated cyber incidents impacting clinical ops, EHR, devices, or PHI.
  • Coordinate with technical and clinical stakeholders to contain threats across hospitals and clinics.
  • Drive updates to the Incident Response Plan for ransomware and other threats.
  • Lead triage, containment, and root-cause analysis of events affecting clinical apps and backend systems.
  • Analyze logs and EDR telemetry across devices, apps, and cloud platforms.
  • Perform investigations on Windows, Linux, iOS, and cloud platforms using SIEM and manual analysis.
  • Lead stakeholder briefings during high-severity incidents.
  • Enrich investigations with internal threat intel and health sector sources.
  • Contribute to detection engineering and playbook development for healthcare threats.
  • Write post-incident reports for operational, risk, and compliance teams.

Skills

Cybersecurity experience
Incident response
Windows investigations
Linux investigations
SIEM
EDR
Forensic tools
Scripting (PowerShell/Python/Bash)
Healthcare/regulatory familiarity
Communication & leadership

Education

Bachelor's Degree

Tools

Splunk
Anvilogic
CrowdStrike
SentinelOne

Job description

Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data, technology and laboratory network, we advance diagnostics, accelerate innovation and help address some of the world’s most important health challenges. As we shape the future of healthcare, we are leveraging advanced technologies, intelligent digital solutions and data-driven innovation across our operations to enhance how work gets done and deliver greater value to customers and patients. With our global scale and deep expertise, you’ll have the opportunity to do meaningful work, grow your career and make a real impact on people’s health around the world. Together, we’re improving health and improving lives.

Labcorp is a global leader in diagnostic testing and drug development solutions, helping healthcare providers, researchers, and patients make informed decisions that advance care. Join us in our mission to improve health and improve lives.

Work Schedule

This is a full‑time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible. Applicants who live within 35 miles of either the Burlington, NC or Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in-office days per week at an assigned location, either Burlington or Durham, supporting both collaboration and flexibility.

Responsibilities
  • Serve as the lead responder for validated cyber incidents—prioritizing threats that could impact clinical operations, electronic health records (EHR), connected medical devices, or protected health information (PHI).
  • Coordinate with technical and clinical stakeholders to contain and remediate threats across hospitals, clinics, and remote care environments.
  • Drive improvements to the Incident Response Plan—ensuring readiness for ransomware, business email compromise, and other threats.
  • Lead triage, containment, and root cause analysis of events affecting clinical applications, patient portals, imaging systems, and backend infrastructure.
  • Analyze logs and EDR telemetry from a wide range of systems—medical devices, cloud applications, employee workstations, and data exchange platforms
  • Perform investigations across Windows, Linux, iOS, and cloud platforms, using SIEM and manual log analysis where required.
  • Lead stakeholder briefings during high-severity incidents.
  • Enrich investigations using internal threat intel, OSINT, and health sector-specific sources (e.g., H-ISAC, HC3 bulletins).
  • Contribute to detection engineering and playbook development aligned with healthcare-specific threat vectors.
  • Write post-incident reports with clear insights for operational, risk, and compliance teams.
Minimum Requirements
  • Bachelor's Degree.
  • 3 or more years of experience in cybersecurity.
  • 5 or more years of experience in Windows and Linux OS investigations, network protocol analysis, and EDR telemetry.
  • 2 or more years of experience with incident response frameworks (NIST 800-61, HITRUST IRM, etc.) and adversary models (MITRE ATT&CK, Cyber Kill Chain).
  • 2 or more years of experience in SIEM (e.g., Splunk, Anvilogic), EDR platforms (e.g., CrowdStrike, SentinelOne), and forensic tools.
Additional Job Standards
  • Hands-on incident response experience in large enterprise environments (30K+ users, multiple business units or hospitals).
  • Strong understanding of HIPAA security rule, HITECH, and how regulatory requirements intersect with incident handling.
  • Familiarity with common healthcare systems such as Epic, Cerner, HL7/FHIR interfaces, or IoMT devices.
  • Proficient in writing detection rules and custom signatures to identify malicious activity.
  • PowerShell, Python, or Bash scripting skills.
  • Clear communicator with experience handling sensitive incidents in regulated industries.
  • Ability to lead investigations that involve patient data and coordinate with privacy and compliance officers.
  • Exposure to healthcare IT, hospital systems, or regulated environments.
Benefits

Employees regularly scheduled to work 20 or more hours per week are eligible for comprehensive benefits including: Medical, Dental, Vision, Life, STD/LTD, 401(k), Paid Time Off (PTO) or Flexible Time Off (FTO), Tuition Reimbursement and Employee Stock Purchase Plan. Employees regularly scheduled to work less than 20 hours, Casual, Intern, and Temporary employees are only eligible to participate in the 401(k) Plan. Employees who are regularly scheduled to work a 7 on 7 off schedule are eligible to receive all the foregoing benefits except PTO or FTO. For more detailed information,

Labcorp Is Proud To Be An Equal Opportunity Employer

Labcorp strives for inclusion and belonging in the workforce and does not tolerate harassment or discrimination of any kind. We make employment decisions based on the needs of our business and the qualifications and merit of the individual. Qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), family or parental status, marital, civil union or domestic partnership status, sexual orientation, gender identity, gender expression, personal appearance, age, veteran status, disability, genetic information, or any other legally protected characteristic. Additionally, all qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law.

If you are an individual with a disability who needs assistance using our online tools to search and apply for jobs, or needs an accommodation, please visit our accessibility site or contact us at Labcorp Accessibility. For more information about how we collect and store your personal data, please see our Privacy Statement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Responder
Senior Cyber Incident Responder

Talentify • Durham (NC)

Hybrid
USD 110,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+5
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Labcorp • North Carolina

Hybrid
USD 120,000 - 170,000
Medical coverage
Dental coverage
Vision coverage
+3
Senior Cyber Incident Responder
Senior Cyber Incident Responder

LCA Lab. Corp. of America • North Carolina

Hybrid
USD 110,000 - 140,000
Medical benefits
Dental benefits
Vision benefits
+6
Software Development Engineer II
Software Development Engineer II

Labcorp • Durham (NC)

Hybrid
USD 110,000 - 150,000
Medical, Dental, Vision, Life
401(k)
Paid Time Off (PTO)
+2
Software Development Engineer II
Software Development Engineer II

Labcorp • Durham (AR)

Hybrid
USD 110,000 - 150,000
Medical, Dental, Vision
401(k) with company matching
PTO / Flexible Time Off
+2
Software Development Engineer II
Software Development Engineer II

LCA Lab. Corp. of America • North Carolina

Hybrid
USD 110,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+6
Lead Software Engineer
Lead Software Engineer

Labcorp • Burlington (NC)

Hybrid
USD 120,000 - 160,000
Medical, Dental, Vision
401(k)
PTO/FTO
+2
Lead Software Engineer
Lead Software Engineer

Labcorp • Durham (NC)

Hybrid
USD 125,000 - 160,000
Medical, Dental, Vision
Life, STD/LTD
401(k)
+3
Principal Software Engineer
Principal Software Engineer

Labcorp • Durham (NC)

On-site
USD 140,000 - 170,000
Medical, Dental, Vision
401(k)
PTO/FTO
+2
Application Security Strategist
Application Security Strategist

Labcorp • North Carolina

On-site
USD 160,000 - 170,000
Medical, Dental, Vision
Life insurance
STD/LTD
+4