Senior Cyber Incident Responder

Highmark Health

Louisiana (MO)

Hybrid

USD 86,400 - 138,600

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Highmark Health is seeking a Senior Cyber Incident Responder to lead investigations within the Cyber Fusion Center, guiding incident response and strategy across the organization. The role requires triage, analysis, and remediation of complex cyber incidents with enterprise-wide impact.

The candidate will coordinate with internal teams, monitor alerts, and document the end-to-end incident lifecycle, ensuring adherence to the Cyber Incident Response Plan and data privacy standards.

Qualifications

  • Bachelor's degree in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or related field.
  • 5 years of Malware Analysis, Digital Forensics, Data/Network Analysis, Penetration testing, Trends Analysis, or Information Assurance.
  • 5 years of Cyber Incident Handling.

Responsibilities

  • Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.
  • Handle escalated incidents as subject matter expert.
  • Correlate incident data to identify vulnerabilities and recommend expeditious remediation.
  • Analyze log files from hosts, network traffic, firewalls, IDS to identify threats.
  • Perform cyber defense incident triage: scope, urgency, impact, and remediation.
  • Perform cyber defense trend analysis and reports to leadership to mitigate risks.
  • Collect and inspect images forensically to support remediation on enterprise systems.
  • Real-time cyber defense incident handling to support deployable Incident Response Teams.

Skills

Malware Analysis
Digital Forensics
Data/Network Analysis
Penetration Testing
Trend Analysis
Information Assurance
Incident Handling
Security Event Correlation
Cloud Incident Response

Education

Bachelor's in computer science or related field
CISSP
GCFA
GCFE
Masters in CS/Cybersecurity/IT

Tools

SIEM tools
IDS/IPS
Forensic tools
Threat intelligence platforms

Job description

## Senior Cyber Incident ResponderApplyremote type: Remotelocations: PA, Working at Home - Pennsylvania: MD, Working at Home - Maryland: WA, Working at Home - Washington: NC, Working at Home - N Carolina: LA, Working at Home - Louisianatime type: Full timeposted on: Posted Todayjob requisition id: J278529## **Company :**Highmark Health## **Job Description :****JOB SUMMARY**This Position is the top investigator in the Cyber Fusion Center, capable of working any kind of incident, leading investigations, and ensuring incidents are properly documented and completed ensuring the CIRP (Cyber Incident Response Plan) is adhered to. They will be considered the subject experts and may be called to lead projects and aid in formulation and execution of security strategy for the team. The Senior Cyber Incident Responder interfaces with other internal teams to determine scope of work and resources for the team and delegates activities based upon complexity and capacity.**ESSENTIAL RESPONSIBILITIES*** Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents. Handle escalated incidents serving as subject matter expert. (20%)* Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. (20%)* Analyze log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security. (10%)* Perform cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation. (10%)* Perform cyber defense trend analysis and reporting, making recommendations to leadership to mitigate future risks. (10%)* Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems. (10%)* Perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs). (10%)* Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts. 95%)* Track and document cyber defense incidents from initial detection through final resolution. (5%)* Other duties as assigned or requested.**EXPERIENCE****Required*** 5 years of Malware Analysis, Digital Forensics, Data/Network Analysis, Penetration testing, Trends Analysis, or Information Assurance* 5 years of Cyber Incident Handling**Preferred*** None**SKILLS*** Identifying, capturing, containing, and reporting malware* Preserving evidence integrity according to standard operating procedures or national standards* Securing network communications* Recognizing and categorizing types of vulnerabilities and associated attacks* Protecting a network against malware (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters)* Performing damage assessments* Using security event correlation tools* Design incident response for cloud service models**EDUCATION****Required*** Bachelor's in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field**Substitutions*** 6 years of experience with information security and systems analysis and experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework**Preferred*** Masters in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field**LICENSES or CERTIFICATIONS****Required*** None**Preferred*** Cyber Incident/Security Certifications* Information Technology Infrastructure Library (ITIL), two of the following certifications: CISSP, GCFA, GCIH, GCFE, GNFA, GREM or GCCC.**Language (Other than English):**None**Travel Requirement:**0% - 25%**PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS****Position Type**Office- or Remote-basedTeaches / trains othersOccasionallyTravel from the office to various work sites or from site-to-siteRarelyWorks primarily out-of-the office selling products/services (sales employees)NeverPhysical work site requiredNoLifting: up to 10 poundsConstantlyLifting: 10 to 25 poundsOccasionallyLifting: 25 to 50 poundsRarely***Disclaimer:*** *The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.* ***Compliance Requirement****: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.* *As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.* *Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.***Pay Range Minimum:**$86,400.00**Pay Range Maximum:**$138,600.00*Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.*
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Responder
Senior Cyber Incident Responder

Highmark Health • Jefferson City (MO)

Hybrid
USD 86,000 - 139,000
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Highmark Health • Oklahoma City (OK)

On-site
USD 86,000 - 139,000
Senior Clinical Informaticist
Senior Clinical Informaticist

Highmark Health • Louisiana (MO)

Hybrid
USD 86,000 - 139,000
Identity Access Management Security Engineer
Identity Access Management Security Engineer

Highmark Health • Northern (KY)

Hybrid
USD 86,000 - 139,000
Senior Regulatory Implementation and Assurance Analyst
Senior Regulatory Implementation and Assurance Analyst

Highmark Health • Louisiana (MO)

Hybrid
USD 79,000 - 128,000
Senior Technical Engineer - Senior Cloud Engineer
Senior Technical Engineer - Senior Cloud Engineer

Highmark Health • Louisiana (MO)

Hybrid
USD 94,000 - 151,000
Technical Engineer - Cloud Engineer
Technical Engineer - Cloud Engineer

Highmark Health • Washington (NC)

Hybrid
USD 79,000 - 127,000
Investigator
Investigator

Highmark Health • Northern (KY)

Hybrid
USD 63,000 - 97,000
Senior Financial Analyst
Senior Financial Analyst

Highmark Health • United States

Hybrid
USD 72,000 - 117,000
Senior Decision Support Analyst
Senior Decision Support Analyst

Highmark Health • Northern (KY)

Hybrid
USD 79,000 - 127,000
Remote work