Senior Cyber Incident Responder

Labcorp

North Carolina

Hybrid

USD 120,000 - 170,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical coverage
Dental coverage
Vision coverage
Life insurance
401(k)
Paid Time Off

Job summary

Labcorp is seeking a Senior Incident Responder to lead investigations and containment of cybersecurity incidents across the enterprise, including clinical systems and PHI. The role emphasizes collaboration with IT, privacy, and compliance teams to protect patient care and data integrity.

The position is full-time with a hybrid schedule based in Burlington, NC or Durham, NC, requiring incident leadership experience in large organizations and a strong security operations mindset.

Qualifications

  • Bachelor’s Degree required.
  • 3+ years of cybersecurity experience.
  • 5+ years of Windows and Linux investigations, network analysis, and EDR telemetry.
  • 2+ years in incident response frameworks (NIST 800-61, HITRUST IRM) and adversary models (MITRE ATT&CK).
  • 2+ years of experience with SIEM (e.g., Splunk) and EDR tools (CrowdStrike, SentinelOne).

Responsibilities

  • Lead responder for validated cyber incidents impacting clinical operations and PHI.
  • Coordinate with technical and clinical stakeholders to contain threats across hospitals and clinics.
  • Drive improvements to the Incident Response Plan for ransomware and other threats.
  • Lead triage, containment, and root cause analyses of events affecting clinical systems.
  • Analyze logs and EDR telemetry across devices, cloud, and infrastructure.
  • Conduct investigations across Windows, Linux, iOS, and cloud platforms using SIEM and manual analysis.

Skills

Cybersecurity
Incident response
Windows investigations
Linux investigations
EDR telemetry
SIEM
Threat hunting

Education

Bachelor's Degree

Tools

Splunk
Anvilogic
CrowdStrike
SentinelOne

Job description

Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data, technology and laboratory network, we advance diagnostics, accelerate innovation and help address some of the world’s most important health challenges. As we shape the future of healthcare, we are leveraging advanced technologies, intelligent digital solutions and data-driven innovation across our operations to enhance how work gets done and deliver greater value to customers and patients. With our global scale and deep expertise, you’ll have the opportunity to do meaningful work, grow your career and make a real impact on people’s health around the world. Together, we’re improving health and improving lives.

Labcorp is a global leader in diagnostic testing and drug development solutions, helping healthcare providers, researchers, and patients make informed decisions that advance care. Join us in our mission to improve health and improve lives.

Work Schedule

This is a full‑time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible.

Applicants who live within 35 miles of either the Burlington, NC or Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in-office days per week at an assigned location, either Burlington or Durham, supporting both collaboration and flexibility.

RESPONSIBILITIES
  • Serve as the lead responder for validated cyber incidents—prioritizing threats that could impact clinical operations, electronic health records (EHR), connected medical devices, or protected health information (PHI).
  • Coordinate with technical and clinical stakeholders to contain and remediate threats across hospitals, clinics, and remote care environments.
  • Drive improvements to the Incident Response Plan—ensuring readiness for ransomware, business email compromise, and other threats.
  • Lead triage, containment, and root cause analysis of events affecting clinical applications, patient portals, imaging systems, and backend infrastructure.
  • Analyze logs and EDR telemetry from a wide range of systems—medical devices, cloud applications, employee workstations, and data exchange platforms
  • Perform investigations across Windows, Linux, iOS, and cloud platforms, using SIEM and manual log analysis where required.
  • Lead stakeholder briefings during high‑severity incidents.
  • Enrich investigations using internal threat intel, OSINT, and health sector‑specific sources (e.g., H‑ISAC, HC3 bulletins).
  • Contribute to detection engineering and playbook development aligned with healthcare‑specific threat vectors.
  • Write post‑incident reports with clear insights for operational, risk, and compliance teams.
MINIMUM REQUIREMENTS
  • Bachelor’s Degree.
  • 3 or more years of experience in cybersecurity.
  • 5 or more years of experience in Windows and Linux OS investigations, network protocol analysis, and EDR telemetry.
  • 2 or more years of experience with incident response frameworks (NIST 800‑61, HITRUST IRM, etc.) and adversary models (MITRE ATT&CK, Cyber Kill Chain).
  • 2 or more years of experience in SIEM (e.g., Splunk, Anvilogic), EDR platforms (e.g., CrowdStrike, SentinelOne), and forensic tools.
ADDITIONAL JOB STANDARDS
  • Hands‑on incident response experience in large enterprise environments (30K+ users, multiple business units or hospitals).
  • Strong understanding of HIPAA security rule, HITECH, and how regulatory requirements intersect with incident handling.
  • Familiarity with common healthcare systems such as Epic, Cerner, HL7/FHIR interfaces, or IoMT devices.
  • Proficient in writing detection rules and custom signatures to identify malicious activity.
  • PowerShell, Python, or Bash scripting skills.
  • Clear communicator with experience handling sensitive incidents in regulated industries.
  • Ability to lead investigations that involve patient data and coordinate with privacy and compliance officers.
  • Exposure to healthcare IT, hospital systems, or regulated environments.

As a core member of the Office of Information Security’s Detection and Response Team (DaRT), the Senior Incident Responder plays a mission‑critical role in protecting patient care, safeguarding sensitive health information, ensuring clinical continuity, and enabling diagnostic and genetic innovation. This position leads the investigation, containment, and resolution of cybersecurity incidents that could impact the confidentiality, integrity, or availability of systems across the enterprise.

You’ll collaborate across clinical, IT, and compliance teams to respond to security threats. You’ll handle escalated events from the SOC, perform technical investigations, and lead recovery efforts while maintaining compliance with requirements associated with HIPAA, HITRUST, GDPR, etc. If you’re driven by purpose, technically sharp, and thrive in fast‑paced environments where security meets patient care—this is the role for you.

Benefits: Employees regularly scheduled to work 20 or more hours per week are eligible for comprehensive benefits including: Medical, Dental, Vision, Life, STD/LTD, 401(k), Paid Time Off (PTO) or Flexible Time Off (FTO), Tuition Reimbursement and Employee Stock Purchase Plan.Employees regularly scheduled to work less than 20 hours, Casual, Intern, and Temporary employees are only eligible to participate in the 401(k) Plan.Employees who are regularly scheduled toworka 7 on 7 off schedule are eligible to receive all the foregoing benefits except PTO or FTO. For more detailed information, please click here.

Labcorp is proud to be an Equal Opportunity Employer:

Labcorp strives for inclusion and belonging in the workforce and does not tolerate harassment or discrimination of any kind. We make employment decisions based on the needs of our business and the qualifications and merit of the individual. Qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), family or parental status, marital, civil union or domestic partnership status, sexual orientation, gender identity, gender expression, personal appearance, age, veteran status, disability, genetic information, or any other legally protected characteristic. Additionally, all qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law.

If you are an individual with a disability who needs assistance using our online tools to search and apply for jobs, or needs an accommodation, please visit our accessibility site or contact us at Labcorp Accessibility. Formore information about how we collect and store your personal data, please see our Privacy Statement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Responder
Senior Cyber Incident Responder

Talentify • Durham (NC)

Hybrid
USD 110,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+5
Senior Cyber Incident Responder
Senior Cyber Incident Responder

LCA Lab. Corp. of America • North Carolina

Hybrid
USD 110,000 - 140,000
Medical benefits
Dental benefits
Vision benefits
+6
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Labcorp • Durham (NC)

Hybrid
USD 120,000 - 180,000
Medical
Dental
Vision
+6
Senior Lead Cyber Compliance
Senior Lead Cyber Compliance

Labcorp • Durham (NC)

On-site
USD 120,000 - 170,000
Medical, dental, vision, life
401(k) with employer match
Tuition reimbursement
+1
Senior Lead Cyber Compliance
Senior Lead Cyber Compliance

LCH Lab. Corp. of America Holdings • North Carolina

On-site
USD 110,000 - 150,000
Medical Insurance
401(k)
Paid Time Off
+1
Software Development Engineer II
Software Development Engineer II

LCA Lab. Corp. of America • North Carolina

Hybrid
USD 110,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+6
Senior Laboratory Application Support Specialist
Senior Laboratory Application Support Specialist

LCH Lab. Corp. of America Holdings • North Carolina

On-site
USD 110,000 - 140,000
Medical, Dental, Vision, Life
STD/LTD, 401(k), PTO/FTO, Tuition Reim
Employee Stock Purchase Plan
Software Development Engineer II
Software Development Engineer II

Labcorp • Durham (AR)

Hybrid
USD 110,000 - 150,000
Medical, Dental, Vision
401(k) with company matching
PTO / Flexible Time Off
+2
Senior IT Auditor - "life-science industry"-REMOTE
Senior IT Auditor - "life-science industry"-REMOTE

Labcorp • Durham (NC)

On-site
USD 90,000 - 120,000
Medical, Dental, Vision insurance
401(k) plan
Paid Time Off (PTO)
+1
Senior IT Auditor - "life-science industry"-REMOTE
Senior IT Auditor - "life-science industry"-REMOTE

Labcorp • Greensboro (NC)

On-site
USD 90,000 - 120,000
Comprehensive benefits
401(k) plan
Tuition Reimbursement
+2