Cyber Incident Responder
Fairmont, Marion County, West Virginia, 26554, USA
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, Information Security, Network Security, IT Support
Company :
Highmark Health
Job Description : JOB SUMMARYThis role will manage and investigate live security incidents. Cyber Incident Responders work independently or collaboratively depending on each event and will serve as a subject matter expert who works to improve security processes and procedures. Responders discover opportunities to improve the security posture of the organization and drive process improvements.
ESSENTIAL RESPONSIBILITIESCoordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents. (20%)
Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. (20%)
Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security. (20%)
Perform cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation. (10%)
Perform cyber defense trend analysis and reporting. (10%)
Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems. (5%)
Perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs). (5%)
Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts. (5%)
Track and document cyber defense incidents from initial detection through final resolution. (5%)
Other duties as assigned or requested.
3 years of Malware Analysis, Digital Forensics, Data/Network Analysis, Penetration testing, or Information Assurance
3 years of Cyber Incident Handling
- None
Identifying, capturing, containing, and reporting malware
Preserving evidence integrity according to standard operating procedures or national standards
Securing network communications
Recognizing and categorizing types of vulnerabilities and associated attacks
Protecting a network against malware (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters)
Performing damage assessments
Using security event correlation tools
Design incident response for cloud service models
- Bachelors in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field.
- 6 years of experience with information security and systems analysis and experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
- None
- None
Cyber Incident/Security Certifications
Information Technology Infrastructure Library (ITIL)
Two of the following certifications: CISSP, GCFA, GCIH, GCFE, GNFA, GREM or GCCC
None
Travel Requirement:0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONSPosition Type
Office- or Remote-based
Teaches / trains others
Occasionally
Travel from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
No
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer:The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement:This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).