Cyber Incident Responder
Listed on 2026-04-23
-
IT/Tech
Cybersecurity, Information Security
Company: Highmark Health
Job Summary: This role will manage and investigate live security incidents. Cyber Incident Responders work independently or collaboratively depending on each event and serve as a subject‑matter expert who works to improve security processes and procedures. Responders discover opportunities to improve the organization’s security posture and drive process improvements.
Essential Responsibilities- Coordinate and provide expert technical support to enterprise‑wide cyber defense technicians to resolve cyber defense incidents. (20%)
- Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. (20%)
- Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and IDS logs) to identify possible threats to network security. (20%)
- Perform cyber defense incident triage, including determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation. (10%)
- Perform cyber defense trend analysis and reporting. (10%)
- Perform initial, forensically sound collection of images and inspect to discern possible mitigation/remediation on enterprise systems. (5%)
- Perform real‑time cyber defense incident handling (e.g., forensic collections, intrusion correlation & tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs). (5%)
- Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts. (5%)
- Track and document cyber defense incidents from initial detection through final resolution. (5%)
- Other duties as assigned or requested.
- 3 years of Malware Analysis, Digital Forensics, Data/Network Analysis, Penetration Testing, or Information Assurance
- 3 years of Cyber Incident Handling
- Identifying, capturing, containing, and reporting malware
- Preserving evidence integrity according to standard operating procedures or national standards
- Securing network communications
- Recognizing and categorizing types of vulnerabilities and associated attacks
- Protecting a network against malware (e.g., NIPS, anti‑malware, restrict/prevent external devices, spam filters)
- Performing damage assessments
- Using security event correlation tools
- Designing incident response for cloud service models
- Bachelor's in Computer Science, Cybersecurity, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related field.
- 6 years of experience with information security and systems analysis and experience working within an information security function using HITRUST CSF, or the NIST 800‑83 cyber security framework
- Cyber Incident/Security Certifications
- Information Technology Infrastructure Library (ITIL)
- Two of the following certifications: CISSP, GCFA, GCIH, GCFE, GNFA, GREM or GCCC
Other than English:
None
0% – 25%
Physical, Mental Demands and Working ConditionsPosition Type:
Office‑ or Remote‑based. Occasionally travel from the office to various work sites or from site‑to‑site. Physical work site required.
Lifting: up to 10 pounds (Constantly). 10–25 pounds (Occasionally). 25–50 pounds (Rarely).
Compliance RequirementsEmployees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. All employees must comply with HIPAA, the company’s privacy policies, and all data security guidelines. All employees are required to adhere to the company’s Code of Business Conduct and applicable laws.
Pay RangeMinimum: $72,700.00
Maximum: $
Equal Employment Opportunity StatementHighmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
Accessibility and AccommodationWe endeavor to make this site accessible to any and all users. For accommodation requests, please contact HR Services Online at HRServices.
Privacy NoticeCalifornia Consumer Privacy Act Employees, Contractors, and Applicants Notice. Req : J278845.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).