Senior Cyber Incident Responder

Highmark Health
PA, Working at Home, Pennsylvania
$146K a year
Full-time

Description

JOB SUMMARY

This Position is the top investigator in the Cyber Fusion Center, capable of working any kind of incident, leading investigations, and ensuring incidents are properly documented and completed ensuring the CIRP (Cyber Incident Response Plan) is adhered to.

They will be considered the subject experts and may be called to lead projects and aid in formulation and execution of security strategy for the team.

The Senior Cyber Incident Responder interfaces with other internal teams to determine scope of work and resources for the team and delegates activities based upon complexity and capacity.

ESSENTIAL RESPONSIBILITIES

Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.

Handle escalated incidents serving as subject matter expert. (20%)

  • Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. (20%)
  • Analyze log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system IDS logs) to identify possible threats to network security. (10%)
  • Perform cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation. (10%)
  • Perform cyber defense trend analysis and reporting, making recommendations to leadership to mitigate future risks. (10%)
  • Perform initial, forensically sound collection of images and inspect to discern possible mitigation / remediation on enterprise systems. (10%)
  • Perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable Incident Response Teams (IRTs). (10%)
  • Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts. 95%)
  • Track and document cyber defense incidents from initial detection through final resolution. (5%)
  • Other duties as assigned or requested.

EXPERIENCE

Required

  • 5 years of Malware Analysis, Digital Forensics, Data / Network Analysis, Penetration testing, Trends Analysis, or Information Assurance
  • 5 years of Cyber Incident Handling

Preferred

None

SKILLS

  • Identifying, capturing, containing, and reporting malware
  • Preserving evidence integrity according to standard operating procedures or national standards
  • Securing network communications
  • Recognizing and categorizing types of vulnerabilities and associated attacks
  • Protecting a network against malware (e.g., NIPS, anti-malware, restrict / prevent external devices, spam filters)
  • Performing damage assessments
  • Using security event correlation tools
  • Design incident response for cloud service models

EDUCATION

Required

Bachelor's in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field

Substitutions

6 years of experience with information security and systems analysis and experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework

Preferred

Masters in computer science, cybersecurity, information technology, software engineering, information systems, computer engineering, or other related field

LICENSES or CERTIFICATIONS

Required

None

Preferred

  • Cyber Incident / Security Certifications
  • Information Technology Infrastructure Library (ITIL), two of the following certifications : CISSP, GCFA, GCIH, GCFE, GNFA, GREM or GCCC.

Language (Other than English) :

None

Travel Requirement : 0% - 25%

0% - 25%

PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS

Position Type

Office- or Remote-based

Teaches / trains others

Occasionally

Travel from the office to various work sites or from site-to-site

Rarely

Works primarily out-of-the office selling products / services (sales employees)

Never

Physical work site required

Lifting : up to 10 pounds

Constantly

Lifting : 10 to 25 pounds

Occasionally

Lifting : 25 to 50 pounds

Rarely

Pay Range Minimum : $78,900.00

$78,900.00

Pay Range Maximum : $146,000.00

$146,000.00

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, age, religion, sex, national origin, sexual orientation / gender identity or any other category protected by applicable federal, state or local law.

Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, age, religion, sex, national origin, sexual orientation / gender identity, protected veteran status or disability.

EEO is The Law

Equal Opportunity Employer Minorities / Women / Protected Veterans / Disabled / Sexual Orientation / Gender Identity ()

We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact number below.

For accommodation requests, please contact HR Services Online at

30+ days ago
Related jobs
Highmark Health
PA, Working at Home, Pennsylvania

This Position is the top investigator in the Cyber Fusion Center, capable of working any kind of incident, leading investigations, and ensuring incidents are properly documented and completed ensuring the CIRP (Cyber Incident Response Plan) is adhered to. The Senior Cyber Incident Responder interfac...

Highmark Health
PA, Working at Home, Pennsylvania

Cyber Incident Responders work independently or collaboratively depending on each event and will serve as a subject matter expert who works to improve security processes and procedures. Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defe...

Promoted
Valiant Integrated Services
Annville, Pennsylvania

Engineer provides networking support for the MTC and any exercise support in preparation for training. Unit S6 to successfully network the simulation with the Units systems. Responsible for TCP/IP networks and protocols. Recommends and performs application maintenance, upgrade as needed, conduct dat...

Promoted
The Azek Company
Scranton, Pennsylvania

AZEK is seeking a Cyber Security GRC Senior Analyst to help build out a successful cyber security GRC program. Analyst, Cyber Security Governance, Risk & Compliance. This role reports directly to the Chief information Security Officer (CISO) and is a key member of the cyber security team. Manage sec...

Promoted
Applied Research Laboratory at the Penn State University
State College, Pennsylvania

The Information Technology Services Office, located in the Enterprise Operations Office of The Applied Research Laboratory (ARL) at Penn State University is seeking a Network Engineer. This role will provide high-level network administration, development, and design assistance for ARL’s enterprise n...

Promoted
Univest Financial Corporation
Souderton, Pennsylvania

Senior Information Security Analyst. Senior Information Security Analyst. Souderton based Information Security Team. The primary responsibility of this position is to ensure the confidentiality, integrity, and availability of all corporate and customer data in accordance with the company's informati...

Promoted
RAND Corporation
Pittsburgh, Pennsylvania

AI & Information Security Analysts will use their. AI, biosecurity, and cybersecurity policy in government and beyond and help ensure that existing and future artificial intelligence systems are safe and secure. Security Analysts advance RAND's research in the intersection of AI. Security Analysts s...

Promoted
Duquesne Light Company
Pittsburgh, Pennsylvania

The Information Security Analyst will be directly responsible for working collaboratively and effectively with individuals across the enterprise to conduct cybersecurity activities including but not limited to: analyzing information security risk and threat data, monitoring and investigating anomali...

Promoted
Clarivate Analytics US LLC
Philadelphia, Pennsylvania

As a security team, our focus lies in four main areas (pillars) - Security Engineering and Operations, Product security, Security Architecture, and Governance Risk and Compliance. Possession of higher-level certifications such as CISSP (Certified Information Systems Security Professional), OSCP (Off...

Promoted
Penn State University
PA, United States

The Process, Physics, Analytics, & Engineering Department at the Applied Research Laboratory (ARL) at Penn State University is seeking an Additive Manufacturing Data Analyst to assist faculty and staff of the Center for Innovative Materials Processing through Direct Digital Deposition (CIMP-3D) of t...