Senior Cyber Incident Responder

Highmark Health

Richmond (VA)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Highmark Health is seeking a Senior Cyber Incident Responder to serve as the top investigator in the Cyber Fusion Center. You will lead investigations across all incident types, ensure proper documentation, and enforce the Cyber Incident Response Plan.

You will interface with internal teams to scope work, assign tasks by complexity, and drive security strategy via incident handling, trend analysis, and timely remediation.

Qualifications

  • Bachelor's degree in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field.
  • Minimum 5 years of Malware Analysis, Digital Forensics, Data/Network Analysis, Penetration testing, Trends Analysis, or Information Assurance.
  • 5 years of Cyber Incident Handling.
  • Certified security certifications are preferred (e.g., CISSP, GCFA, GCIH, GCFE, GNFA, GREM, GCCC).
  • 6 years of experience with HITRUST CSF or NIST CSF as substitution.

Responsibilities

  • Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve incidents.
  • Correlate incident data to identify vulnerabilities and enable expeditious remediation.
  • Analyze log files from hosts, networks, firewalls, and IDS to identify threats.
  • Perform cyber defense incident triage, determining scope, urgency, and impact.
  • Perform cyber defense trend analysis and reporting to leadership for risk mitigation.
  • Perform forensic image collection and preliminary analysis for remediation.
  • Handle real-time cyber defense incident handling to support deployable Incident Response Teams (IRTs).
  • Track and document cyber defense incidents from initial detection through final resolution.
  • Other duties as assigned.

Skills

Malware analysis
Evidence integrity
Network security
Vulnerability analysis
Malware protection
Damage assessment
Security event correlation
Cloud incident response

Education

Bachelor's degree in computer science / cybersecurity / IT / software engineering
6 years of HITRUST CSF / NIST CSF experience (substitution)

Job description

Company :

Highmark Health

Job Description :

JOB SUMMARY

This Position is the top investigator in the Cyber Fusion Center, capable of working any kind of incident, leading investigations, and ensuring incidents are properly documented and completed ensuring the CIRP (Cyber Incident Response Plan) is adhered to. They will be considered the subject experts and may be called to lead projects and aid in formulation and execution of security strategy for the team. The Senior Cyber Incident Responder interfaces with other internal teams to determine scope of work and resources for the team and delegates activities based upon complexity and capacity.

ESSENTIAL RESPONSIBILITIES

  • Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents. Handle escalated incidents serving as subject matter expert. (20%)

  • Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. (20%)

  • Analyze log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security. (10%)

  • Perform cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation. (10%)

  • Perform cyber defense trend analysis and reporting, making recommendations to leadership to mitigate future risks. (10%)

  • Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems. (10%)

  • Perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs). (10%)

  • Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts. 95%)

  • Track and document cyber defense incidents from initial detection through final resolution. (5%)

  • Other duties as assigned or requested.

EXPERIENCE

Required

  • 5 years of Malware Analysis, Digital Forensics, Data/Network Analysis, Penetration testing, Trends Analysis, or Information Assurance

  • 5 years of Cyber Incident Handling

Preferred

  • None

SKILLS

  • Identifying, capturing, containing, and reporting malware

  • Preserving evidence integrity according to standard operating procedures or national standards

  • Securing network communications

  • Recognizing and categorizing types of vulnerabilities and associated attacks

  • Protecting a network against malware (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters)

  • Performing damage assessments

  • Using security event correlation tools

  • Design incident response for cloud service models

EDUCATION

Required

  • Bachelor's in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field

Substitutions

  • 6 years of experience with information security and systems analysis and experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework

Preferred

  • Masters in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field

LICENSES or CERTIFICATIONS

Required

  • None

Preferred

  • Cyber Incident/Security Certifications

  • Information Technology Infrastructure Library (ITIL), two of the following certifications: CISSP, GCFA, GCIH, GCFE, GNFA, GREM or GCCC.

Language (Other than English):

None

Travel Requirement:

0% - 25%

PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS

Position Type

Office- or Remote-based

Teaches / trains others

Occasionally

Travel from the office to various work sites or from site-to-site

Rarely

Works primarily out-of-the office selling products/services (sales employees)

Never

Physical work site required

No

Lifting: up to 10 pounds

Constantly

Lifting: 10 to 25 pounds

Occasionally

Lifting: 25 to 50 pounds

Rarely

Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

Compliance Requirement : This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Incident Responder
Senior Cyber Incident Responder

Highmark Health • Columbus (OH)

On-site
USD 86,000 - 139,000
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Highmark Health • Louisiana (MO)

Hybrid
USD 86,000 - 139,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex-Communication • Town of Texas (WI)

On-site
USD 110,000 - 160,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex Communications, Ltd. • Town of Texas (WI), Northern (KY)

Hybrid
USD 110,000 - 150,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex • Town of Texas (WI)

On-site
USD 110,000 - 140,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Cyber Security Analyst
Cyber Security Analyst

Dale WorkForce Solutions • Columbia (SC)

On-site
USD 90,000 - 130,000
Engineer, Cyber Security
Engineer, Cyber Security

Memorial Physician Practices • Brentwood (TN)

Hybrid
USD 80,000 - 110,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000