Security Incident Response Analyst
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Accendra Health, we understand that healthcare is complex, and we’re here to make it easier. We help deliver care beyond traditional settings, making essential products and services more accessible through every stage of life.
With deep expertise promoting health outside the hospital and a presence in communities nationwide through our Apria and Byram Healthcare brands, Accendra Health does more than just deliver the essentials.
If you’re interested in meaningful work with impact, explore our career opportunities and join us in our purpose of Bringing Care To Life™.
Role SummaryThe L3 Security Incident Response Analyst is a technical investigator on the Security Operations team. You own incidents end to end: scoping, investigation, containment, eradication, recovery, and the communication that keeps leadership and business stakeholders informed while it happens. You are the escalation point for L1/L2 analysts, the person who decides "this is contained" or "this is bigger than it looks," and the one who turns each incident into detection, tooling, and process improvements so the same thing doesn't happen twice.
This is a hands‑on role in a regulated healthcare environment. You will handle incidents involving PHI/PII, identity compromise, business email compromise, and third‑party exposure, and you will be expected to make sound containment decisions under time pressure with incomplete information.
The anticipated salary for this position is up to $95,000 annually. Actual compensation may vary based on job‑related factors such as experience, skills, education, and location.
What You’ll Do Investigation and containment- Lead high‑severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry; build and defend a timeline and root cause, not just a list of alerts.
- Make and execute containment decisions: session revocation, credential resets, token invalidation, host isolation, mailbox rule removal, conditional access changes, and network blocks — weighing business impact against risk.
- Run eradication and recovery, verify the adversary is actually out, and confirm persistence mechanisms (OAuth grants, inbox rules, MFA device registrations, scheduled tasks, service principals) are removed.
- Perform log analysis and light forensics (memory, disk, M365/Entra audit logs, proxy/firewall/VPN logs) and preserve evidence to a standard that survives legal and regulatory review.
- Lead investigations involving protected health information (PHI) and personally identifiable information (PII): unauthorized access, misdirected or exposed data, insider misuse, lost or compromised devices, and third‑party or vendor exposures.
- Determine what data was involved, who had access, for how long, and whether it was actually viewed or exfiltrated — and document that determination to a standard that supports HIPAA breach risk assessments and regulatory response.
- Work directly with Privacy, Compliance, and Legal to feed incident facts into breach determination and notification decisions, and coordinate takedown or remediation of exposed data (public sites, file‑sharing platforms, misconfigured storage, email).
- Contribute to data protection controls (DLP, access reviews, data classification, secure file‑transfer) based on what incidents reveal.
- Own incident communications: concise, accurate status updates to the CISO and security leadership, plain‑language briefings to business owners, and clear handoffs to IT, Legal, Privacy, and HR.
- Write incident reports and post‑incident reviews that a non‑technical executive can read and that an engineer can act on.
- Coordinate with external parties as needed: MDR/MSSP, forensic retainers, cyber insurance, vendors,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).