Cybersecurity Forensic Examiner I
Sign up free to see how well your resume matches this role.
About this role
Department Name:
IT Incident Mgmt & ForensicsWork Shift:
DayJob Category:
Information Technology
Banner Health was named to Fortune’s Most Innovative Companies in America 2025 list for the third consecutive year and named to Newsweek's list of Most Trustworthy Companies in America for the second year in a row. We’re proud to be recognized for our commitment to the latest health care advancements and excellent patient care.
The CIFER Team performs sensitive digital investigations which may involve computers, mobile devices and network computer systems. It works with HR, Compliance, and other legal verticals as well as Cybersecurity. CIFER interacts with professionals and executives at top levels within the organization
Daily routine work involves reviewing case assignments and following legally defensible procedures and routines. Responding to escalations and being able to gather pertinent facts to perform an investigation. This is a remote position. In this role you would work Monday through Friday normal business hours 8am - 5pm AZ time zone and can be a remote position if you live in the following states only: AL, AK, AR, AZ, CA, CO, FL, GA, IA, ID, IN, KS, KY, LA, MD, MI, MN, MO, MS, NC, ND, NE, NH, NM, NV, NY, OH, OK, OR, PA, SC, TN, TX, UT, VA, WA, WI, WV & WY. No other states will be consider.
Your pay and benefits (Total Rewards) are important components of your Journey at Banner Health. Banner Health offers a variety of benefit plans to help you and your family. We provide health and financial security options, so you can focus on being the best at what you do and enjoying your life.
Within Banner Health Corporate, you will have the opportunity to apply your unique experience and expertise in support of a nationally-recognized healthcare leader. We offer stimulating and rewarding careers in a wide array of disciplines. Whether your background is in Human Resources, Finance, Information Technology, Legal, Managed Care Programs or Public Relations, you'll find many options for contributing to our award-winning patient care.POSITION SUMMARY
This position is responsible for investigating and responding to escalated security incidents, coordinating various teams and departments as needed, leading technical analysis and discussions, and creating various forms of incident documentation and communication. This position advises on countermeasures and participates in improving security analytics and alerts. This position assists in formulating and defining incident response scope and objectives based on business needs and a good understanding of applicable industry and regulatory requirements. Competent to work at the highest practical understanding of most phases of cybersecurity analysis and design as it applies to current and future system requirements. Proficiency in investigation and legal preservation workflows and performing complex operational task that require thoughtful analysis. Trouble-shooting tasks related to access control, provisioning requests, network & endpoint security systems. Required to operate under the highest standards of integrity while providing fair and impartial findings for internal and external Investigations.
CORE FUNCTIONS
1. Assess escalated security events and incidents and drive response actions to minimize impact to the business. May support various departments with investigative services as business requires.
2. Acts as Incident Coordinator and Scribe for high impact cyber breaches and advanced attacks. Supports the communication hub during handling of cybersecurity incidents, recoveries, breaches, intrusions, and system abuses. Collaborates on countermeasures.
3. Participates in security reviews, evaluations, tabletop exercises, risk assessments, and post-incident activities and develops appropriate security posture recommendations.
4. Creates documentation of incident response activities supporting identified outcomes, metrics, reporting, and lessons learned.
5. Participates and assists in development of alerts and Indicators of Compromise detection capabilities. Participates in the ongoing evaluation and development of security policies and procedures and maintains Incident Response documents.
6. Responsible for providing technical expertise and support for security software, including operational aspects of the software.
7. Manages and conducts eDiscovery operations including legal preservation, litigation hold, forensic collections, and native file productions. Including the management of evidence documentation and chain-of-custody.
8. Responsible for providing guidance, direction, and oversight for company’s compliance with all federal, state, and local mandated cybersecurity laws, rules, and guidelines. Remain current with the latest industry technical information.
9. Under general direction, this position is responsible for cybersecurity, digital forensic examinations, and eDiscovery operations across multiple departments system-wide and requires interaction at all levels of staff and management.
MINIMUM QUALIFICATIONS
Must possess strong knowledge of business, information security and/or computer science as normally obtained through the completion of a bachelor's degree or equivalent combination of relevant education, technical, business and healthcare experience. Certification in at least one of the following areas within one year of entering the position. EnCase Certified Examiner (EnCE), EnCase Certified eDiscovery Practitioner (EnCEP), Certified Computer Examiner (CCE), or other certification designated by the Cybersecurity Leader.
Must possess at least two years of experience in Information Technology, Cybersecurity, in a corporate or similar environment with Forensic knowledge or training. Requires ability to communicate and interact across cross functional departments and facilities and at various levels. Ability to balance project workloads with customer support and on-call demands. The position will be required to work variable shifts and hours and carrying/responding to a page may be required.
PREFERRED QUALIFICATIONS
Additional related certification preferred. Experience in cybersecurity controls, policies, and procedures. Experience with analyzing network activities, responding to anomalies, and reporting events. Experience with level 1 incident response handling and addressing reported or detected incidents. Digital forensics experience and incident response experience preferred. IAC Certified Forensic Examiner (GCFE), EC-Council Certified Incident Handler (ECIH), COMPTIA Security + or other Cybersecurity Certifications.
Additional related education and/or experience preferred.
DATE APPROVED 03/30/2025
Estimated Pay Range:
$35.37 - $58.95 / hour

Banner Health is committed to pay equity and transparency. The posted compensation range is a reasonable estimate that extends from the lowest to the highest pay Banner Health in good faith believes it might pay for this particular job, based on the circumstances at the time of posting.

This range is based on possible base salaries and does not include the value of our total rewards package. Actual pay determined at offer will be based on years of relevant work experience, education, certifications, skills, and geographic location, along with a review of current employees in similar roles to ensure pay equity is achieved and maintained.

EEO Statement:
Our organization supports a drug-free work environment.
Privacy Policy:
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.