Search Remote Jobs

Security Incident Response Analyst

Job not on LinkedIn

🔥 0 minutes ago

🌲 North Carolina, Virginia – Remote

infoinfo

💵 $95k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🛡️ Security Operations

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Accendra Health

Accendra Health

5001 - 10000 employees

Founded 1882

🏥 Healthcare

🤝 B2B

👥 B2C

Healthcare • B2B • B2C

Accendra Health is a healthcare company (formerly Owens & Minor, Inc. ) focused on home-based care delivery and medical supplies. Backed by its Apria and Byram Healthcare brands, Accendra provides a broad portfolio of essentials for diabetes, sleep health, wound care, respiratory care, urology, and ostomy, and connects patients, providers, and insurers to improve outcomes. The company operates a nationwide network of over 250 service locations and employs more than 6,000 teammates, emphasizing patient support, care coordination, and distribution of durable medical equipment and related services.

📋 Description

• Lead high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry • Build and defend incident timelines and determine root cause • Execute containment decisions including session revocation, credential resets, token invalidation, host isolation, mailbox rule removal, conditional access changes, and network blocks • Run eradication and recovery, verify adversary removal, and eliminate persistence mechanisms • Perform log analysis and light forensics across memory, disk, M365/Entra audit logs, proxy/firewall/VPN logs • Preserve evidence for legal and regulatory review • Lead PHI/PII investigations involving unauthorized access, exposed data, insider misuse, compromised devices, and third-party exposures • Determine data involvement, access, duration, viewing, and exfiltration; document findings for HIPAA breach risk assessments • Work with Privacy, Compliance, and Legal on breach determinations and notifications • Coordinate takedown or remediation of exposed data • Contribute to DLP, access reviews, data classification, and secure file-transfer controls • Own incident communications to the CISO, security leadership, business owners, IT, Legal, Privacy, and HR • Write incident reports and post-incident reviews • Coordinate with MDR/MSSP, forensic retainers, cyber insurance, vendors, and third-party partners • Tune and build SIEM detections and response playbooks • Measure and reduce false positives, dwell time, and time to contain • Conduct proactive threat hunts and convert findings into detections or hardening recommendations • Identify control gaps and drive remediation with owning teams • Mentor and review L1/L2 analyst investigations • Maintain runbooks, severity definitions, and escalation criteria • Participate in the on-call rotation and lead tabletop exercises

🎯 Requirements

• 5+ years in security operations or incident response • At least 2 years leading investigations independently on high-severity incidents • Deep, practical expertise in SIEM and detection engineering • Query languages such as KQL, SPL, or equivalent • Experience with correlation logic, detection tuning, and log source onboarding • Experience with Microsoft Sentinel, Rapid7 InsightIDR, Splunk, or equivalent SIEM tools • Expertise with Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, and offboarding controls • Expertise in BEC and phishing investigation, header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateways, and API-based email security tools • EDR investigation and response experience, including Defender for Endpoint, CrowdStrike, or similar • Endpoint persistence and lateral movement knowledge • Firewall, proxy, VPN, and DNS log analysis experience • Understanding of network segmentation, C2 patterns, and data exfiltration indicators • Fluency with MITRE ATT&CK • Strong written communication • Experience investigating incidents involving PHI/PII or other regulated data, including scoping data exposure and supporting breach risk assessments • Healthcare industry experience and working knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy laws preferred • Cloud incident response experience preferred • Scripting with PowerShell, Python, or KQL preferred • Experience with SOAR platforms preferred • Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200 preferred • Experience handling incidents involving third parties, vendors, or divested/carved-out business units preferred

🏖️ Benefits

• Medical, dental, and vision care coverage • Paid time off plan • 401(k) Plan • Flexible Spending Accounts • Basic life insurance • Short-and long-term disability coverage • Accident insurance • Teammate Assistance Program • Paid parental leave • Domestic partner benefits • Mental, physical, and financial well-being programs

Apply Now

Similar Jobs

🕒 2 days ago

Live Nation Entertainment

10,000+ employees

📱 Media

Senior Director leading cyber threat detection and incident response for Live Nation Entertainment. Managing analysts, automation, monitoring, and global security operations.

🕒 3 days ago

Prudential Financial

10,000+ employees

💸 Finance

🛡️ Insurance

🏠 Real Estate

Leading Prudential’s remote network security operations team for enterprise financial services. Managing incident response, firewalls, proxies, and continuous security operations improvement.

🕒 3 days ago

Odevo

5001 - 10000

🏠 Real Estate

☁️ SaaS

🤖 Artificial Intelligence

Cyber Security Operations Analyst managing vulnerability programs, penetration tests, and security incidents. Supporting secure coding and security solutions for Odevo’s U.S. IT operations.

🇺🇸 United States – Remote

💰 Private equity on 2024-09

⏰ Full Time

🟢 Junior

🟡 Mid-level

🛡️ Security Operations

🚫👨‍🎓 No degree required

🕒 3 days ago

Everbridge

1001 - 5000

🏥 Healthcare

📦 Logistics

💼 Consulting

Security Operations Associate supporting Everbridge’s critical event management technology. Coordinating secure journey services, security assistance, vendors, client communications, and operational records.

🕒 6 days ago

Huntress

201 - 500

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

Security Operations Analyst triaging intrusions and malware for Huntress, a managed cybersecurity provider protecting businesses worldwide. Investigating EDR, M365, and forensic data on a weekend 4x10 shift.

🇺🇸 United States – Remote

💵 $100k - $125k / year

⏰ Full Time

🟢 Junior

🟡 Mid-level

🛡️ Security Operations

🚫👨‍🎓 No degree required