> Markdown version of [/jobs/ext/173587-senior-security-threat-engineer](https://www.wearedevelopers.com/jobs/ext/173587-senior-security-threat-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Threat Engineer - **Company:** HCA Healthcare Inc. - **Location:** Nashville, TN, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Data Analysis, Proxy Servers, Antivirus Softwares, JIRA, Cyber Security, Document Management Systems, Identity and Access Management, Issue Tracking Systems, Intrusion Detection and Prevention, Intrusion Detection Systems, OSI Models, NetFlow, Network Forensics, Phishing, Security Information and Event Management, Malware, Cyber Threat Analysis, Cybercrime, 3-tier Architectures, Cts+, Cyber Warfare, Blue Team (Cyber Security), Security Orchestration, Automation & Response, Service Stack, Servicenow - **Published:** May 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d2f7bfa32dbe6e16 ## About the Role Do you have experience in Communication skills?, * Bachelor's degree Preferred * 5+ years of experience in a relevant field Required *Experience as a member of a Cyber Incident Response Team (CIRT) or comparable * Experience executing an Incident Response plan, preferably based on recognized industry standards (e.g. - NIST, SANS, etc) * Experience in Windows Artifact Analysis and Forensic Analysis (e.g. - Program Execution, File/Folder opening, Account Usage, pulling memory, following proper evidence handling procedures, etc) using industry standard tools and available logs (e.g. - Endpoint Detection and Response (EDR) tools such as Microsoft Defender Endpoint). * Experience in Memory Analysis using tools such as Volatility * Experience in network forensic analysis to determine validity of detected events using available network logs collected via SEIM. * Experience with an event/information analysis framework such as Analysis of Competing Hypotheses (ACH). * Experience in performing security analysis or reporting utilizing Security Incident and Event Management (SIEM) Technologies. * Experience with document management and sustaining Security Operations Center (SOC) policies and run book procedures for incident response. * Experience with documenting root cause analysis and lessons learned. * Experience consuming and generating cybersecurity threat intelligence. * Experience across the technology stack. Familiarity with all OSI layers and expertise in some. * Experiencing using the following types of security tools: * + SIEM oFirewalls + Web Proxy + Anti-Virus (AV) + Next Gen Anti-Virus (NGAV) + Endpoint Detection and Response (EDR) + Sandboxing oVirtual Machines + Netflow analysis + Malware Repositories + Threat Intelligence + Deception Stack + Intrusion Detection/Prevention System (IDS/IPS) + Security Orchestration Automation Response (SOAR) + Phishing Triage oUser Behavior Analytics (UBA) + Email Hygiene and Filtering * Experience interfacing with peer support teams (Security Engineering, Vulnerability and Patching Teams, Networking, Access Management, Legal, Risk/Governance, etc.) * Experience working in a high-tempo, dynamic environment with a high performance team. * Experience with work ticketing systems (e.g. - ServiceNow, JIRA) * Experience with Threat Modeling and Kill Chain analysis, + Leadership ability to independently lead and direct Major Incident Response efforts as well as projects. + Excellent critical thinking skills to understand available data and use it to support or refute potential hypothesis that explain the data. Use available data to develop and communicate conclusions and recommendations. + An ability to work and thrive in stressful situations. A demeanor that conveys calm professionalism in stressful situations. + An ability to maintain confidentiality of sensitive data and to follow proper ethical practices for using tools and accessing data. + A strong desire to determine root cause of events. A willingness to fully investigate all alternatives exhaustively until a conclusion can be supported. + Ability to self-prioritize tasks based on criticality and threat level. The following certifications and courses are helpful, but, not required: * GIAC: GSEC, GCIH, GCFA, GCIA, GCED, GMON, GCDA, GDAT or comparable ## Description You will be a Cyber Defender - serving as the last line of defense between HCA and the threat actors that wish to bring harm to HCA and the patients we serve. You will use state of the art technologies to respond to threats on our network and eradicate them as a member of our Critical Threat Services (CTS) team. As a member of CTS, you will operate along with a small team of like-minded individuals with a passion for cyber security operations. The Senior Threat Engineer will provide Tier 2, and Tier 3 analysis to cyber security threats and potential incidents. In addition to serving as a Subject Matter Expert on all routine cyber threats, the Senior Threat Response Engineer will be capable of independently leading Major Incident Response teams composed of resources from across the enterprise throughout the cyber incident response process. Successful candidates will have a passion for cybersecurity and be naturally curious and self-motivated to investigate and discover root cause of events while working in a fast-paced and sometimes stressful environment. Good teamwork and communication skills are also vital. Our team operates as a close-knit group serving a noble purpose - to win the fight against evil every day. Note: This position requires rotating on-call coverage/availability for after-hours and holidays as needed. Major Responsibilities * Major Incident Response - serve as the lead cyber resource in Major Incident response to execute the IR process and advise the business. * Provide guidance to field resources on how to properly remediate a threat. * Work closely with other Cyber Defense Center (CDC) team members to improve tools, techniques, and procedures for CDC operation. * Continuously improve documentation of work products and processes. * Participate in red/blue team exercises. * Routinely collaborate with individuals and teams from across the enterprise. Serve as a Subject Matter Expert in all domains related to the CDC ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)