CareerPlanSign in

Senior Cyber Incident Responder

Durham NC💼 Full-time🗓 2026-09-17 → 2026-09-25

Core

Lead responder for validated cyber incidents impacting clinical operations, EHR, connected medical devices, and PHI.

Role type

Senior hands-on incident responder (healthcare)

Builds

Incident response playbooks, detection rules, and post-incident reports for clinical and compliance teams.

Domain

Healthcare cybersecurity / Medical device security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Incident response frameworks (NIST 800-61, HITRUST IRM), adversary models (MITRE ATT&CK), SIEM analysis, EDR telemetry analysis, forensic tools, Windows/Linux investigation, network protocol analysis, HIPAA/HITECH compliance, healthcare system familiarity (Epic, Cerner, HL7/FHIR, IoMT), detection rule writing, scripting (PowerShell/Python/Bash)

Preferred skills

Large enterprise incident response experience (30K+ users), OSINT integration, threat intelligence enrichment

Technologies

Splunk, Anvilogic, CrowdStrike, SentinelOne, Windows, Linux, iOS, Epic, Cerner

Responsibilities

Lead triage, containment, and root cause analysis of events affecting clinical applications and patient portals; Analyze logs and EDR telemetry from medical devices and cloud applications; Lead stakeholder briefings during high-severity incidents; Contribute to detection engineering and playbook development aligned with healthcare-specific threat vectors; Write post-incident reports with clear insights for operational, risk, and compliance teams.

Seniority

Senior, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.