> Markdown version of [/jobs/ext/3000458-senior-cyber-incident-responder](https://www.wearedevelopers.com/jobs/ext/3000458-senior-cyber-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Incident Responder - **Company:** LabCorp - **Location:** Burlington, NC, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Cerner, Microsoft Windows, Apple IOS, Bash Shell, Health Informatics, Cloud Computing, Communications Protocols, Cyber Security, Linux, Electronic Data Interchange (EDI), Imaging Technology, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Open Source Intelligence, Windows PowerShell, Security Information and Event Management, Fast Healthcare Interoperability Resources, System Availability, Mitre Att&ck, Electronic Medical Records, Backend, Cybercrime, Health Level Seven International, Dart, Splunk, SentinelOne Expertise - **Published:** September 19, 2026 - **Apply:** https://labcorp.wd1.myworkdayjobs.com/External/job/Durham-NC/Senior-Cyber-Incident-Responder_261785 ## About the Role * Bachelor's Degree. * 3 or more years of experience in cybersecurity. * 5 or more years of experience in Windows and Linux OS investigations, network protocol analysis, and EDR telemetry. * 2 or more years of experience with incident response frameworks (NIST 800-61, HITRUST IRM, etc.) and adversary models (MITRE ATT&CK, Cyber Kill Chain). * 2 or more years of experience in SIEM (e.g., Splunk, Anvilogic), EDR platforms (e.g., CrowdStrike, SentinelOne), and forensic tools. ADDITIONAL JOB STANDARDS * Hands-on incident response experience in large enterprise environments (30K+ users, multiple business units or hospitals). * Strong understanding of HIPAA security rule, HITECH, and how regulatory requirements intersect with incident handling. * Familiarity with common healthcare systems such as Epic, Cerner, HL7/FHIR interfaces, or IoMT devices. * Proficient in writing detection rules and custom signatures to identify malicious activity. * PowerShell, Python, or Bash scripting skills. * Clear communicator with experience handling sensitive incidents in regulated industries. * Ability to lead investigations that involve patient data and coordinate with privacy and compliance officers. * Exposure to healthcare IT, hospital systems, or regulated environments. As a core member of the Office of Information Security's Detection and Response Team (DaRT), the Senior Incident Responder plays a mission-critical role in protecting patient care, safeguarding sensitive health information, ensuring clinical continuity, and enabling diagnostic and genetic innovation. This position leads the investigation, containment, and resolution of cybersecurity incidents that could impact the confidentiality, integrity, or availability of systems across the enterprise. ## Description This is a full-time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible., Applicants who live within 35 miles of either the Burlington, NC or Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in-office days per week at an assigned location, either Burlington or Durham, supporting both collaboration and flexibility., * Serve as the lead responder for validated cyber incidents-prioritizing threats that could impact clinical operations, electronic health records (EHR), connected medical devices, or protected health information (PHI). * Coordinate with technical and clinical stakeholders to contain and remediate threats across hospitals, clinics, and remote care environments. * Drive improvements to the Incident Response Plan-ensuring readiness for ransomware, business email compromise, and other threats. * Lead triage, containment, and root cause analysis of events affecting clinical applications, patient portals, imaging systems, and backend infrastructure. * Analyze logs and EDR telemetry from a wide range of systems-medical devices, cloud applications, employee workstations, and data exchange platforms * Perform investigations across Windows, Linux, iOS, and cloud platforms, using SIEM and manual log analysis where required. * Lead stakeholder briefings during high-severity incidents. * Enrich investigations using internal threat intel, OSINT, and health sector-specific sources (e.g., H-ISAC, HC3 bulletins). * Contribute to detection engineering and playbook development aligned with healthcare-specific threat vectors. * Write post-incident reports with clear insights for operational, risk, and compliance teams., You'll collaborate across clinical, IT, and compliance teams to respond to security threats. You'll handle escalated events from the SOC, perform technical investigations, and lead recovery efforts while maintaining compliance with requirements associated with HIPAA, HITRUST, GDPR, etc. If you're driven by purpose, technically sharp, and thrive in fast-paced environments where security meets patient care-this is the role for you. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Dart - a language believed dead, experiences a new bloom](https://www.wearedevelopers.com/videos/442-dart-a-language-believed-dead-experiences-a-new-bloom) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Dart - a language believed dead, experiences a new bloom](https://www.wearedevelopers.com/videos/955-dart-a-language-believed-dead-experiences-a-new-bloom) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)