Labcorp · 2 hours ago
Senior Cyber Incident Responder
Labcorp is a leader in health care innovation, and they are seeking a Senior Cyber Incident Responder to protect patient care and sensitive health information. This role involves leading the investigation and resolution of cybersecurity incidents, collaborating with various teams to respond to security threats.
BiotechnologyHealth CareHospitalLife ScienceMedicalPrecision Medicine
Responsibilities
Serve as the lead responder for validated cyber incidents—prioritizing threats that could impact clinical operations, electronic health records (EHR), connected medical devices, or protected health information (PHI)
Coordinate with technical and clinical stakeholders to contain and remediate threats across hospitals, clinics, and remote care environments
Drive improvements to the Incident Response Plan—ensuring readiness for ransomware, business email compromise, and other threats
Lead triage, containment, and root cause analysis of events affecting clinical applications, patient portals, imaging systems, and backend infrastructure
Analyze logs and EDR telemetry from a wide range of systems—medical devices, cloud applications, employee workstations, and data exchange platforms
Perform investigations across Windows, Linux, iOS, and cloud platforms, using SIEM and manual log analysis where required
Lead stakeholder briefings during high-severity incidents
Enrich investigations using internal threat intel, OSINT, and health sector-specific sources (e.g., H-ISAC, HC3 bulletins)
Contribute to detection engineering and playbook development aligned with healthcare-specific threat vectors
Write post-incident reports with clear insights for operational, risk, and compliance teams
Qualification
Required
3+ years of experience in cybersecurity, preferably with exposure to healthcare IT, hospital systems, or regulated environments
Hands-on incident response experience in large enterprise environments (30K+ users, multiple business units or hospitals)
Strong understanding of HIPAA security rule, HITECH, and how regulatory requirements intersect with incident handling
Familiarity with common healthcare systems such as Epic, Cerner, HL7/FHIR interfaces, or IoMT devices
Experience with incident response frameworks (NIST 800-61, HITRUST IRM, etc.) and adversary models (MITRE ATT&CK, Cyber Kill Chain)
Proficient in SIEM (e.g., Splunk, Anvilogic), EDR platforms (e.g., CrowdStrike, SentinelOne), and forensic tools
Strong skills in Windows and Linux OS investigations, network protocol analysis, and EDR telemetry
Proficient in writing detection rules and custom signatures to identify malicious activity
Clear communicator with experience handling sensitive incidents in regulated industries
Ability to lead investigations that involve patient data and coordinate with privacy and compliance officers
Bachelor's degree in Cybersecurity, Information Systems, or a related field—or equivalent experience in a regulated enterprise
Preferred
PowerShell, Python, or Bash scripting skills are a plus
Preferred certifications include: GCIH, GCFA, GCFE, GNFA, GCTI, CISSP, or HCISPP (Healthcare Certified Information Security and Privacy Practitioner)
Benefits
Medical
Dental
Vision
Life
STD/LTD
401(k)
Paid Time Off (PTO)
Flexible Time Off (FTO)
Tuition Reimbursement
Employee Stock Purchase Plan
Company
Labcorp
Labcorp specializes in providing physicians with laboratory tests.
H1B Sponsorship
Labcorp has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2021 (1)
Funding
Current Stage
Public CompanyTotal Funding
$2.85B2024-09-16Post Ipo Debt· $2B
2019-06-04Post Ipo Debt· $850M
1988-07-15IPO
Leadership Team
Recent News
2026-02-03
2026-01-22
Company data provided by crunchbase