Senior Cyber Incident Responder
Core
Lead responder for validated cyber incidents impacting clinical operations, EHR, connected medical devices, and PHI.
Role type
Senior hands-on incident responder (healthcare)
Builds
Incident response playbooks, detection rules, and post-incident reports for clinical and compliance teams.
Domain
Healthcare cybersecurity / Medical device security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response frameworks (NIST 800-61, HITRUST IRM), adversary models (MITRE ATT&CK), SIEM analysis, EDR telemetry analysis, forensic tools, Windows/Linux investigation, network protocol analysis, HIPAA/HITECH compliance, healthcare system familiarity (Epic, Cerner, HL7/FHIR, IoMT), detection rule writing, scripting (PowerShell/Python/Bash)
Preferred skills
Large enterprise incident response experience (30K+ users), OSINT integration, threat intelligence enrichment
Technologies
Splunk, Anvilogic, CrowdStrike, SentinelOne, Windows, Linux, iOS, Epic, Cerner
Responsibilities
Lead triage, containment, and root cause analysis of events affecting clinical applications and patient portals; Analyze logs and EDR telemetry from medical devices and cloud applications; Lead stakeholder briefings during high-severity incidents; Contribute to detection engineering and playbook development aligned with healthcare-specific threat vectors; Write post-incident reports with clear insights for operational, risk, and compliance teams.
Seniority
Senior, hands-on IC