Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Franciscan Health

Lead Cyber Security Specialist

Franciscan Health

. Investigate and analyze cyber incident response activities within network environments or enclaves .

Posted 9/30/2026full-timeRemote • United StatesSenior💰 $96,732 - $133,006 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity incident response, including the development and execution of SOAR playbooks, and possesses advanced skills in Splunk for monitoring and reporting. Strong background in analyzing security data and leading investigations in high-severity incidents within network environments.

Highest-signal resume keywords
SOAR Playbook DevelopmentSplunk Dashboard CreationHigh-Severity Incident InvestigationCybersecurity Policy DevelopmentHealthcare Industry Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Incident ResponseData AnalysisSPL Query OptimizationRisk-Based AlertingDetection ThresholdsPenetration TestingSecurity Data Quality TroubleshootingAnomalous User Behavior DetectionSIEM KnowledgeVulnerability Management
Soft Skills
CoachingCommunicationLeadership
Tools & Technologies
Splunk CloudSplunk On-PremiseCND ToolsIntrusion Detection SystemsFirewall LogsNetwork Traffic Logs
Certifications & Qualifications
Associate's DegreeBachelor's Degree (Preferred)Security Certificate (Preferred)
Industry Keywords
CybersecurityInformation TechnologyInformation SecurityHealthcare IndustrySOC Operations

Tech Stack

Tools & technologies
CloudCyber SecuritySplunk

About the role

Key responsibilities & impact
  • Investigate and analyze cyber incident response activities within network environments or enclaves
  • Collect and analyze data from CND tools, intrusion detection alerts, firewall and network traffic logs, and host system logs
  • Provide persistent monitoring of designated networks, enclaves, and systems
  • Interpret, analyze, and report events and anomalies in accordance with computer network directives
  • Act as the highest-level escalation point
  • Distribute directives, vulnerability advisories, and threat advisories to identified consumers
  • Work with Security Architects on roadmaps and implementation plans for security technologies
  • Lead SOC efforts during high-severity security incident investigations and guide analysts through the incident response lifecycle
  • Develop, maintain, and safely execute SOAR playbooks; automate enrichment and response tasks
  • Troubleshoot security data quality issues and validate detections against reliable data
  • Coach analysts, review investigations, establish investigation standards, and communicate with SOC management and security teams
  • Build Splunk dashboards and reports measuring data sources, alert volume, detection performance, investigation quality, and SOC effectiveness
  • Develop procedures for investigating compromised accounts and lateral movement
  • Work with internal resources and external third parties to design and conduct penetration tests
  • Create and review cybersecurity policies, procedures, and standards for SOC, Vulnerability Management, and Incident Response

Requirements

What you’ll need
  • Required Associate's Degree
  • 8 years Information Technology or Information Security Department experience required
  • Preferred Bachelor's Degree
  • Preferred Certificate
  • 5 years healthcare industry experience; experience in security operations activities aligning with Essential Job Functions preferred
  • Splunk Cloud / on-premise experience preferred
  • Advanced proficiency writing and optimizing complex SPL queries
  • Experience creating, testing, tuning, and maintaining high-fidelity detections
  • Experience with risk-based alerting and detection thresholds/governance
  • Knowledge of SIEM artificial intelligence capabilities
  • Experience with high-severity security incident investigation and incident response
  • Experience developing and executing SOAR playbooks
  • Understanding of security data sources, field extractions, data models, and CIM
  • Experience building Splunk dashboards and reports
  • Experience building anomalous user and entity behavior detections
  • Experience conducting penetration tests
  • Knowledge of cybersecurity policies, procedures, and standards

Benefits

Comp & perks
  • Comprehensive benefit offerings for eligible employees
  • Travel is never or rarely required