NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Analyst in United States of America
3 days ago
Apply with autofill
Apply with autofill
Accendra·3 days ago
3 days ago

Security Incident Response Analyst

Remote - VirginiaFull-timeRemoteMid · 2+ yearsSecurity Analyst

Sign up free to see how well your resume matches this role.

Boost your chances at accendra

How you compare FREE

?
Your scoreYour score: not yet known
→
48
Top 10%Top 10%: 48 out of 100

Top 10% of NextRaise users matched against Security Analyst roles in United States.

Must-have skills for this role

  • microsoft entra id
  • active directory
  • kql
  • microsoft sentinel

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Lead high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry; build and defend a timeline and root cause, not just a list of alerts.
  • Make and execute containment decisions: session revocation, credential resets, token invalidation, host isolation, mailbox rule removal, conditional access changes, and network blocks — weighing business impact against risk.
  • Run eradication and recovery, verify the adversary is actually out, and confirm persistence mechanisms (OAuth grants, inbox rules, MFA device registrations, scheduled tasks, service principals) are removed.
  • Perform log analysis and light forensics (memory, disk, M365/Entra audit logs, proxy/firewall/VPN logs) and preserve evidence to a standard that survives legal and regulatory review.
  • Lead investigations involving protected health information (PHI) and personally identifiable information (PII): unauthorized access, misdirected or exposed data, insider misuse, lost or compromised devices, and third-party or vendor exposures.
  • Determine what data was involved, who had access, for how long, and whether it was actually viewed or exfiltrated — and document that determination to a standard that supports HIPAA breach risk assessments and regulatory response.
  • Work directly with Privacy, Compliance, and Legal to feed incident facts into breach determination and notification decisions, and coordinate takedown or remediation of exposed data (public sites, file-sharing platforms, misconfigured storage, email).
  • Contribute to data protection controls (DLP, access reviews, data classification, secure file-transfer) based on what incidents reveal.
  • Own incident communications: concise, accurate status updates to the CISO and security leadership, plain-language briefings to business owners, and clear handoffs to IT, Legal, Privacy, and HR.
  • Write incident reports and post-incident reviews that a non-technical executive can read and that an engineer can act on.
  • Coordinate with external parties as needed: MDR/MSSP, forensic retainers, cyber insurance, vendors, and third-party partners involved in an incident.
  • Tune and build SIEM detections and response playbooks from what you learn in incidents; measure and reduce false positives, dwell time, and time to contain.

What they're looking for

  • 5+ years in security operations or incident response, with at least 2 years leading investigations independently on high-severity incidents.
  • Deep, practical expertise in: SIEM / detection engineering — query languages (KQL, SPL, or equivalent), correlation logic, detection tuning, log source onboarding (e.g., Microsoft Sentinel, Rapid7 InsightIDR, Splunk).
  • Identity and access — Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, offboarding controls.
  • Email security — BEC and phishing investigation, header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateway and API-based email security tools.
  • Endpoint — EDR investigation and response (Defender for Endpoint, CrowdStrike, or similar), persistence and lateral movement techniques.
  • Network security — firewall, proxy, VPN, and DNS log analysis; understanding of segmentation, C2 patterns, and data exfiltration indicators.
  • Fluency with MITRE ATT&CK and the ability to map observed activity to it.
  • Strong written communication: you can write an executive status update and a technical timeline in the same hour, and both are clear.
  • Judgment: you know when to contain immediately, when to watch, and when to escalate, and you can explain why.
  • Experience investigating incidents involving PHI/PII or other regulated data, including scoping data exposure and supporting breach risk assessments.

Nice to have

  • Healthcare industry experience and working knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy laws.
  • Cloud incident response experience (Azure, M365, AWS, or GCP) including SaaS/OAuth-based compromises.
  • Scripting for investigation and automation (PowerShell, Python, KQL).
  • Experience with SOAR platforms and automating response actions.
  • Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200.
  • Experience handling incidents involving third parties, vendors, or divested/carved-out business units with shared infrastructure.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

At Accendra Health, we understand that healthcare is complex, and we’re here to make it easier. We help deliver care beyond traditional settings, making essential products and services more accessible through every stage of life. As part of the care team, our teammates play a critical role in delivering personalized, long-term care for the patients we serve.

 

With deep expertise promoting health outside the hospital and a presence in communities nationwide through our Apria and Byram Healthcare brands, Accendra Health does more than just deliver the essentials.

 

If you’re interested in meaningful work with impact, explore our career opportunities and join us in our purpose of Bringing Care To Life™.

 

 

Role Summary

The L3 Security Incident Response Analyst is a technical investigator on the Security Operations team. You own incidents end to end: scoping, investigation, containment, eradication, recovery, and the communication that keeps leadership and business stakeholders informed while it happens. You are the escalation point for L1/L2 analysts, the person who decides "this is contained" or "this is bigger than it looks," and the one who turns each incident into detection, tooling, and process improvements so the same thing doesn't happen twice.

This is a hands-on role in a regulated healthcare environment. You will handle incidents involving PHI/PII, identity compromise, business email compromise, and third-party exposure, and you will be expected to make sound containment decisions under time pressure with incomplete information.

The anticipated salary for this position is up to $95,000 annually. Actual compensation may vary based on job-related factors such as experience, skills, education, and location.  

What You'll Do

Investigation and containment

  • Lead high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry; build and defend a timeline and root cause, not just a list of alerts.
  • Make and execute containment decisions: session revocation, credential resets, token invalidation, host isolation, mailbox rule removal, conditional access changes, and network blocks — weighing business impact against risk.
  • Run eradication and recovery, verify the adversary is actually out, and confirm persistence mechanisms (OAuth grants, inbox rules, MFA device registrations, scheduled tasks, service principals) are removed.
  • Perform log analysis and light forensics (memory, disk, M365/Entra audit logs, proxy/firewall/VPN logs) and preserve evidence to a standard that survives legal and regulatory review.

PHI/PII and data security incidents

  • Lead investigations involving protected health information (PHI) and personally identifiable information (PII): unauthorized access, misdirected or exposed data, insider misuse, lost or compromised devices, and third-party or vendor exposures.
  • Determine what data was involved, who had access, for how long, and whether it was actually viewed or exfiltrated — and document that determination to a standard that supports HIPAA breach risk assessments and regulatory response.
  • Work directly with Privacy, Compliance, and Legal to feed incident facts into breach determination and notification decisions, and coordinate takedown or remediation of exposed data (public sites, file-sharing platforms, misconfigured storage, email).
  • Contribute to data protection controls (DLP, access reviews, data classification, secure file-transfer) based on what incidents reveal.

Communication

  • Own incident communications: concise, accurate status updates to the CISO and security leadership, plain-language briefings to business owners, and clear handoffs to IT, Legal, Privacy, and HR.
  • Write incident reports and post-incident reviews that a non-technical executive can read and that an engineer can act on.
  • Coordinate with external parties as needed: MDR/MSSP, forensic retainers, cyber insurance, vendors, and third-party partners involved in an incident.

Detection and improvement

  • Tune and build SIEM detections and response playbooks from what you learn in incidents; measure and reduce false positives, dwell time, and time to contain.
  • Threat hunt proactively using current intelligence, and convert findings into detections or hardening recommendations.
  • Identify control gaps (offboarding, SSO/MFA coverage, mail-flow protections, privileged access) and drive them to closure with the owning teams.

Team leverage

  • Serve as escalation point and mentor for L1/L2 analysts; review their investigations and raise the quality bar.
  • Maintain and improve runbooks, severity definitions, and escalation criteria.
  • Participate in the on-call rotation and lead tabletop exercises.

What You Bring

Required

  • 5+ years in security operations or incident response, with at least 2 years leading investigations independently on high-severity incidents.
  • Deep, practical expertise in:
    • SIEM / detection engineering — query languages (KQL, SPL, or equivalent), correlation logic, detection tuning, log source onboarding (e.g., Microsoft Sentinel, Rapid7 InsightIDR, Splunk).
    • Identity and access — Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, offboarding controls.
    • Email security — BEC and phishing investigation, header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateway and API-based email security tools.
    • Endpoint — EDR investigation and response (Defender for Endpoint, CrowdStrike, or similar), persistence and lateral movement techniques.
    • Network security — firewall, proxy, VPN, and DNS log analysis; understanding of segmentation, C2 patterns, and data exfiltration indicators.
  • Fluency with MITRE ATT&CK and the ability to map observed activity to it.
  • Strong written communication: you can write an executive status update and a technical timeline in the same hour, and both are clear.
  • Judgment: you know when to contain immediately, when to watch, and when to escalate, and you can explain why.
  • Experience investigating incidents involving PHI/PII or other regulated data, including scoping data exposure and supporting breach risk assessments.

Preferred

  • Healthcare industry experience and working knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy laws.
  • Cloud incident response experience (Azure, M365, AWS, or GCP) including SaaS/OAuth-based compromises.
  • Scripting for investigation and automation (PowerShell, Python, KQL).
  • Experience with SOAR platforms and automating response actions.
  • Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200.
  • Experience handling incidents involving third parties, vendors, or divested/carved-out business units with shared infrastructure.

Teammate Benefits

As an Accendra Health employee, you have choices to fit your life. Our comprehensive benefits program is designed to meet you where you are — through all of life’s stages. We’ve got you and your family covered with benefits that support your health, finances, and overall wellness.

 

Our benefits program includes:

  • Medical, dental, and vision care coverage

  • Paid time off plan

  • 401(k) Plan

  • Flexible Spending Accounts

  • Basic life insurance

  • Short-and long-term disability coverage

  • Accident insurance

  • Teammate Assistance Program

  • Paid parental leave

  • Domestic partner benefits

  • Mental, physical, and financial well-being programs

If you feel this opportunity could be the next step in your career, we encourage you to apply.

Accendra is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, sex, sexual orientation, genetic information, religion, disability, age, status as a veteran, or any other status prohibited by applicable national, federal, state or local law.

Note: Accendra is not accepting unsolicited assistance from search firms for this employment opportunity. Please, no phone calls or emails. All resumes submitted by search firms to any employee at our Company via email, the Internet, or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of our Company. No fee will be paid in the event the candidate is hired by our Company as a result of the referral or through other means.

#AccendraHealth

Company

Accendra
Remote - Virginia

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Accendra's careers site·first seen 18 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Information Security Analyst at gditUSA VA Virginia Beach–match not yet calculated
  • Associate Cybersecurity Analyst at swaDallas, United States of America–match not yet calculated
  • Spring 2027 IT Security Analyst Intern at standoutforgoodKnoxville, United States of America–match not yet calculated
  • Principal Cybersecurity Analyst at ngcSunnyvale, United States of America–match not yet calculated
  • Lead, Insider Threat at bridgewater89Westport, United States of America–match not yet calculated

Browse more jobs

  • Security Analyst jobs in United States
  • Security Engineer jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Analyst jobs in India
  • Security Analyst jobs in Canada