Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Accendra Health

Security Incident Response Analyst

Accendra Health

. Lead high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry .

Posted 9/17/2026full-timeRemote • North Carolina • United StatesMid-LevelSenior💰 $95,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading high-severity incident investigations, including root cause analysis and remediation strategies. Proficient in SIEM tools, log analysis, and compliance with HIPAA regulations, with strong communication skills for incident reporting and coordination.

Highest-signal resume keywords
SIEM ExpertiseIncident Response LeadershipLog AnalysisPHI/PII InvestigationDetection Engineering

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Incident InvestigationRoot Cause AnalysisLog AnalysisData Exfiltration IndicatorsQuery Languages (KQL, SPL)Detection TuningEDR InvestigationNetwork SegmentationScripting (PowerShell, Python)Forensics
Soft Skills
Strong Written CommunicationMentoring
Tools & Technologies
Microsoft SentinelSplunkRapid7 InsightIDRDefender for EndpointSOAR Platforms
Certifications & Qualifications
GCIHGCFAGCIACISSPMicrosoft SC-200
Industry Keywords
HIPAA Privacy/Security RulesHealthcare IndustryData Loss Prevention (DLP)Breach Risk AssessmentsCloud Incident Response

Tech Stack

Tools & technologies
CloudDNSPythonSplunk

About the role

Key responsibilities & impact
  • Lead high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry
  • Build and defend incident timelines and determine root cause
  • Execute containment decisions including session revocation, credential resets, token invalidation, host isolation, mailbox rule removal, conditional access changes, and network blocks
  • Run eradication and recovery, verify adversary removal, and eliminate persistence mechanisms
  • Perform log analysis and light forensics across memory, disk, M365/Entra audit logs, proxy/firewall/VPN logs
  • Preserve evidence for legal and regulatory review
  • Lead PHI/PII investigations involving unauthorized access, exposed data, insider misuse, compromised devices, and third-party exposures
  • Determine data involvement, access, duration, viewing, and exfiltration; document findings for HIPAA breach risk assessments
  • Work with Privacy, Compliance, and Legal on breach determinations and notifications
  • Coordinate takedown or remediation of exposed data
  • Contribute to DLP, access reviews, data classification, and secure file-transfer controls
  • Own incident communications to the CISO, security leadership, business owners, IT, Legal, Privacy, and HR
  • Write incident reports and post-incident reviews
  • Coordinate with MDR/MSSP, forensic retainers, cyber insurance, vendors, and third-party partners
  • Tune and build SIEM detections and response playbooks
  • Measure and reduce false positives, dwell time, and time to contain
  • Conduct proactive threat hunts and convert findings into detections or hardening recommendations
  • Identify control gaps and drive remediation with owning teams
  • Mentor and review L1/L2 analyst investigations
  • Maintain runbooks, severity definitions, and escalation criteria
  • Participate in the on-call rotation and lead tabletop exercises

Requirements

What you’ll need
  • 5+ years in security operations or incident response
  • At least 2 years leading investigations independently on high-severity incidents
  • Deep, practical expertise in SIEM and detection engineering
  • Query languages such as KQL, SPL, or equivalent
  • Experience with correlation logic, detection tuning, and log source onboarding
  • Experience with Microsoft Sentinel, Rapid7 InsightIDR, Splunk, or equivalent SIEM tools
  • Expertise with Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, and offboarding controls
  • Expertise in BEC and phishing investigation, header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateways, and API-based email security tools
  • EDR investigation and response experience, including Defender for Endpoint, CrowdStrike, or similar
  • Endpoint persistence and lateral movement knowledge
  • Firewall, proxy, VPN, and DNS log analysis experience
  • Understanding of network segmentation, C2 patterns, and data exfiltration indicators
  • Fluency with MITRE ATT&CK
  • Strong written communication
  • Experience investigating incidents involving PHI/PII or other regulated data, including scoping data exposure and supporting breach risk assessments
  • Healthcare industry experience and working knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy laws preferred
  • Cloud incident response experience preferred
  • Scripting with PowerShell, Python, or KQL preferred
  • Experience with SOAR platforms preferred
  • Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200 preferred
  • Experience handling incidents involving third parties, vendors, or divested/carved-out business units preferred

Benefits

Comp & perks
  • Medical, dental, and vision care coverage
  • Paid time off plan
  • 401(k) Plan
  • Flexible Spending Accounts
  • Basic life insurance
  • Short-and long-term disability coverage
  • Accident insurance
  • Teammate Assistance Program
  • Paid parental leave
  • Domestic partner benefits
  • Mental, physical, and financial well-being programs