Senior Cyber Incident Responder
$86.4kHighmark Health
Company :
Highmark Health
Job Description :
JOB SUMMARY
This Position is the top investigator in the Cyber Fusion Center, capable of working any kind of incident, leading investigations, and ensuring incidents are properly documented and completed ensuring the CIRP (Cyber Incident Response Plan) is adhered to. They will be considered the subject experts and may be called to lead projects and aid in formulation and execution of security strategy for the team. The Senior Cyber Incident Responder interfaces with other internal teams to determine scope of work and resources for the team and delegates activities based upon complexity and capacity.
ESSENTIAL RESPONSIBILITIES
Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents. Handle escalated incidents serving as subject matter expert. (20%)
Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. (20%)
Analyze log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security. (10%)
Perform cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation. (10%)
Perform cyber defense trend analysis and reporting, making recommendations to leadership to mitigate future risks. (10%)
Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems. (10%)
Perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs). (10%)
Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts. 95%)
Track and document cyber defense incidents from initial detection through final resolution. (5%)
Other duties as assigned or requested.
EXPERIENCE
Required
5 years of Malware Analysis, Digital Forensics, Data/Network Analysis, Penetration testing, Trends Analysis, or Information Assurance
5 years of Cyber Incident Handling
Preferred
- None
SKILLS
Identifying, capturing, containing, and reporting malware
Preserving evidence integrity according to standard operating procedures or national standards
Securing network communications
Recognizing and categorizing types of vulnerabilities and associated attacks
Protecting a network against malware (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters)
Performing damage assessments
Using security event correlation tools
Design incident response for cloud service models
EDUCATION
Required
- Bachelor's in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field?
Substitutions
- 6 years of experience with information security and systems analysis and experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
Preferred
- Masters in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field
LICENSES or CERTIFICATIONS
Required
- None
Preferred
Cyber Incident/Security Certifications
Information Technology Infrastructure Library (ITIL), two of the following certifications: CISSP, GCFA, GCIH, GCFE, GNFA, GREM or GCCC.
Language (Other than English):
None
Travel Requirement:
0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office- or Remote-based
Teaches / trains others
Occasionally
Travel from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
No
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement : This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times.? In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy.?
Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum:
$86,400.00
Pay Range Maximum:
$138,600.00
Base pay is determined by a variety of factors including a candidate's qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at View email address on click.appcast.io
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J278529
- ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates disciplined... ...and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual...CyberSeniorContract workWork experience placementWork at officeShift work
$80.2k - $111.3k
...Creates cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate high level data and... ...the investigation of complex computer and information security incidents to determine extent of compromise to national security information...CyberSeniorContract workWork at office$50 per hour
...ePO, ACAS, etc.) to identify and mitigate threats, vulnerabilities and non-compliance. Investigating, analyzing and responding to cyber events, incidents and non-compliance, including trend analysis, creating detailed written reports and briefing the appropriate parties...CyberSeniorFull timeTemporary workWork experience placementCasual workFlexible hoursShift workDay shift- ...motivated, career and customer-oriented Senior Software Developer to join our innovative... ...critical system failures, sudden security incidents, or infrastructure bottlenecks, restoring... ...certification).Experience with the primary cyber risk and compliance automation tools....CyberSeniorFull timeContract workWork at officeLocal areaRemote work
$66.9k - $82.1k
...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity... ...tools and service management platforms integrated with SOC and cyber defense functions. Certifications such as ITIL Foundation...CyberContract workWork experience placementWork at office- ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service... ...and hierarchical escalations to Senior Coordinators and the Senior Incident Manager... ...data to route incidents; engage infra/app/cyber/vendor dependencies. Communications &...CyberContract workWork experience placementWork at officeShift work
$130k - $135k
...Hands‑on experience performing responsibilities aligned to incident response, security operations, and security initiatives. Background... ...in SOC operations, detection engineering, threat hunting, or cyber threat intelligence. Must be comfortable supporting a...CyberSeniorFull timeRemote workFlexible hoursShift workWeekend workAfternoon shift$55.7k - $82.1k
...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and... ...genuine incidents, and escalates significant events to senior analysts or incident responders as appropriate. The analyst supports basic containment...Contract workWork at officeShift work$132.23k - $176.31k
...Black Lotus Labs has an opening for a Senior Lead Security Engineer that will leverage... ...goal of automating detection. Work with cyber operators, when requested, to conduct in-... ...outside groups. Support customer RFIs on incidents and emerging threats. Use approved AI-...CyberSeniorFull timeTemporary workWork experience placementWork at officeRemote work- ...security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic,... ...fostering empowerment, inclusion, respect, and accountability. Senior Account Executive, Enterprise Remote Location: Atlanta, Georgia...CyberSeniorApprenticeshipLocal areaRemote workShift work
- ...analytics, digital workplace solutions, and cyber compliance. With our global footprint, we... ...guidelines. Responsibilities: Respond to and diagnose UNIX/Linux problems through... ...providing end-to-end ownership of incidents with actual or potential impact to operations...CyberContract workWork at officeLocal areaAfternoon shift
- ...protect and grow what matters, including Insurance, Reinsurance, Cyber Services, Mortgage Origination and more. Acrisure employs over 1... ...violations of rules, regulations, policies, and procedures. The Senior level ER Specialist will have the proven ability to...CyberSeniorWork at officeImmediate startFlexible hours
- ...- Strong analytical skills for effective security analysis and incident response. - Ability to identify endpoint anomalies and malware... ...Preferred Certifications: CompTia Security ISC2 Certified in Cyber security Certified Ethical Hacker Microsoft SC-200CyberWork at office
$40k
...operations by monitoring security tools, performing initial incident triage, and assisting with containment, vulnerability... ..., and compliance activities. The role works under senior guidance to execute defined cyber actions, maintain incident documentation, support POA&M...CyberContract workRemote work- ...transformative. Our expertise spans Enterprise IT, Mission IT and Cyber. With our global footprint, we place a strong emphasis on... ...Conduct troubleshooting and root cause analysis for network incidents impacting JSSC Command and Control (C2) systems. Coordinate...CyberContract workDay shift
$76.4k - $138.6k
...deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our... ...Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we...CyberSummer holidayLocal areaFlexible hours$152.7k - $294k
...Global Information Security Strategist is a senior role responsible for shaping and... ...step ahead of evolving business demands and cyber risks. Key Responsibilities:... ...management, identity and access management (IAM), incident response, and emerging threat mitigation...CyberSummer holidayLocal areaFlexible hoursShift work- ...technical and sales presentations to customer's technical staff and senior management. Serves as a trusted technology advisor to... ...Operations Company, leads at the intersection of data protection, cyber resilience, and enterprise AI acceleration. Rubrik Security Cloud...CyberSeniorLocal areaImmediate start
- ...include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be... ...security management) relative to assigned duties Execute the cyber security portion of the self-inspection, to include provide...CyberWork at office
$60k
...Perform escalation-level response actions, including coordinating and executing directed cyber activities. Lead and support containment and restoration efforts during security incidents, ensuring timely resolution and stabilization of affected systems. Ensure all...CyberContract workRemote workShift work$94.1k - $150k
...Position Overview The Cyber Threat Hunter proactively protects enterprise environments from advanced cyber threats by analyzing... ...tactics, techniques, and procedures to strengthen cyber defense and incident response operations. This role directly supports a proactive...CyberContract workWork at office- Torch Technologies seeks an Architect Principal to join the ERP Common Services team in Huntsville, AL. The role focuses on establishing, integrating, and evolving ERP applications across DoD environments. Responsibilities include guiding enterprise architecture, engaging...Senior
$105k - $145k
...Overview GovCIO is currently hiring for Senior Splunk Engineer - Infrastructure... ...components to ensure optimal resource usage. Respond promptly to health alerts, DMC warnings,... ...functioning as expected. Document incidents, RCA findings, and preventive actions for...SeniorFull timeCurrently hiringWork at officeRemote workFlexible hours- ...expertise spans Enterprise IT, Mission IT and Cyber. With our global footprint, we place a... ...and integrity. The Position The Senior System Administrator provides Tier I/II/III... ...supporting disaster recovery procedures. Support incident and problem management activities,...CyberRelocationDay shift
- ...core network services (i.e., Active Directory, network file servers, storage area network, virtual server environment, etc.).Provide cyber security services in support of the Authorization to Operate (ATO) for the Development, Test, and Evaluation (DT&E) authorizing...CyberFull time
- ...operations. Responsibilities include: Conducting complex criminal investigations into financial crimes, including counterfeiting, cyber fraud, and other threats to the financial infrastructure of the United States. Providing physical protection for the President,...Cyber
- ...Cyber Excepted Service Position This position is being recruited under 10 USC 1599f into the Cyber Excepted Service and does NOT convey eligibility to be converted to the Competitive Service. It has been identified as a position necessary to carry out and support the...CyberWork at office
- ...Building Intelligence®. We design, build, operate, and maintain cyber-physical solutions for the nation’s most mission-critical facilities... ...:Survey Reports measurement results in actionable form to more senior personnel and management.Conducts any surveys, inspections,...CyberWork at officeLocal areaFlexible hours
- ...Create, maintain, and facilitate custom queries, reports, and dashboards for system, module, and policy compliance. Monitor and report cyber and insider threats. Facilitate and approve endpoint protection application upgrades and changes. Monitor, evaluate, remediate, and...CyberFull timeContract workTemporary workWork at officeShift work
- DescriptionTechFlow is seeking an experienced Senior Software Architect / Lead Software Engineer to support a mission-critical DoD software development and modernization program in Montgomery, AL. This program provides software development and technical support services...SeniorFull timeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cyber Incident Responder. Be the first to apply!
- senior network engineer remote Montgomery, AL
- senior manager legal Montgomery, AL
- sr project manager Montgomery, AL
- senior staff systems engineer Montgomery, AL
- senior commercial counsel Montgomery, AL
- senior manager tax Montgomery, AL
- senior construction accountant Montgomery, AL
- senior living Montgomery, AL
- senior implementation project manager Montgomery, AL
- senior marketing project manager Montgomery, AL



