> Markdown version of [/jobs/ext/3005519-security-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/3005519-security-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Incident Response Analyst - **Company:** Accendra Health - **Location:** Richmond, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $95,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Data Security, Query Languages, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Domain Name System (DNS), Multi-Factor Authentication, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Log Analysis, OAuth, Windows PowerShell, Azure Active Directory, Phishing, Kusto Query Language, Security Information and Event Management, EndPointSecurity, Scripting, Data Classification, Office365, Mitre Att&ck, Firewalls (Computer Science), Microsoft Sentinel, Api Design, Splunk - **Published:** September 19, 2026 - **Apply:** https://dejobs.org/x/x/7DDE135B179D4B4AB99B77F73BCA8418/job/ ## About the Role * 5+ years in security operations or incident response, with at least 2 years leading investigations independently on high-severity incidents. * Deep, practical expertise in: * SIEM / detection engineering - query languages (KQL, SPL, or equivalent), correlation logic, detection tuning, log source onboarding (e.g., Microsoft Sentinel, Rapid7 InsightIDR, Splunk). * Identity and access - Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, offboarding controls. * Email security - BEC and phishing investigation, header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateway and API-based email security tools. * Endpoint - EDR investigation and response (Defender for Endpoint, CrowdStrike, or similar), persistence and lateral movement techniques. * Network security - firewall, proxy, VPN, and DNS log analysis; understanding of segmentation, C2 patterns, and data exfiltration indicators. * Fluency with MITRE ATT&CK and the ability to map observed activity to it. * Strong written communication: you can write an executive status update and a technical timeline in the same hour, and both are clear. * Judgment: you know when to contain immediately, when to watch, and when to escalate, and you can explain why. * Experience investigating incidents involving PHI/PII or other regulated data, including scoping data exposure and supporting breach risk assessments. Preferred * Healthcare industry experience and working knowledge of HIPAA Privacy/Security Rules, breach notification requirements, and state privacy laws. * Cloud incident response experience (Azure, M365, AWS, or GCP) including SaaS/OAuth-based compromises. * Scripting for investigation and automation (PowerShell, Python, KQL). * Experience with SOAR platforms and automating response actions. * Certifications such as GCIH, GCFA, GCIA, CISSP, or Microsoft SC-200. * Experience handling incidents involving third parties, vendors, or divested/carved-out business units with shared infrastructure. ## Description * Lead high-severity investigations across endpoint, identity, email, network, cloud, and SaaS telemetry; build and defend a timeline and root cause, not just a list of alerts. * Make and execute containment decisions: session revocation, credential resets, token invalidation, host isolation, mailbox rule removal, conditional access changes, and network blocks - weighing business impact against risk. * Run eradication and recovery, verify the adversary is actually out, and confirm persistence mechanisms (OAuth grants, inbox rules, MFA device registrations, scheduled tasks, service principals) are removed. * Perform log analysis and light forensics (memory, disk, M365/Entra audit logs, proxy/firewall/VPN logs) and preserve evidence to a standard that survives legal and regulatory review. PHI/PII and data security incidents * Lead investigations involving protected health information (PHI) and personally identifiable information (PII): unauthorized access, misdirected or exposed data, insider misuse, lost or compromised devices, and third-party or vendor exposures. * Determine what data was involved, who had access, for how long, and whether it was actually viewed or exfiltrated - and document that determination to a standard that supports HIPAA breach risk assessments and regulatory response. * Work directly with Privacy, Compliance, and Legal to feed incident facts into breach determination and notification decisions, and coordinate takedown or remediation of exposed data (public sites, file-sharing platforms, misconfigured storage, email). * Contribute to data protection controls (DLP, access reviews, data classification, secure file-transfer) based on what incidents reveal. Communication * Own incident communications: concise, accurate status updates to the CISO and security leadership, plain-language briefings to business owners, and clear handoffs to IT, Legal, Privacy, and HR. * Write incident reports and post-incident reviews that a non-technical executive can read and that an engineer can act on. * Coordinate with external parties as needed: MDR/MSSP, forensic retainers, cyber insurance, vendors, and third-party partners involved in an incident. Detection and improvement * Tune and build SIEM detections and response playbooks from what you learn in incidents; measure and reduce false positives, dwell time, and time to contain. * Threat hunt proactively using current intelligence, and convert findings into detections or hardening recommendations. * Identify control gaps (offboarding, SSO/MFA coverage, mail-flow protections, privileged access) and drive them to closure with the owning teams. Team leverage * Serve as escalation point and mentor for L1/L2 analysts; review their investigations and raise the quality bar. * Maintain and improve runbooks, severity definitions, and escalation criteria. * Participate in the on-call rotation and lead tabletop exercises. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) ## Related Articles - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)