| Location | NC |
At Accendra Health, we understand that healthcare is complex, and we're here to make it easier. We help deliver care beyond traditional settings, making essential products and services more accessible through every stage of life. As part of the care team, our teammates play a critical role in delivering personalized, long-term care for the patients we serve.
With deep expertise promoting health outside the hospital and a presence in communities nationwide through our Apria and Byram Healthcare brands, Accendra Health does more than just deliver the essentials.
If you're interested in meaningful work with impact, explore our career opportunities and join us in our purpose of Bringing Care To Life.
Role Summary
The L3 Security Incident Response Analyst is a technical investigator on the Security Operations team. You own incidents end to end: scoping, investigation, containment, eradication, recovery, and the communication that keeps leadership and business stakeholders informed while it happens. You are the escalation point for L1/L2 analysts, the person who decides "this is contained" or "this is bigger than it looks," and the one who turns each incident into detection, tooling, and process improvements so the same thing doesn't happen twice.
This is a hands-on role in a regulated healthcare environment. You will handle incidents involving PHI/PII, identity compromise, business email compromise, and third-party exposure, and you will be expected to make sound containment decisions under time pressure with incomplete information.
The anticipated salary for this position is up to $95,000 annually. Actual compensation may vary based on job-related factors such as experience, skills, education, and location.
What You'll Do
Investigation and containment
PHI/PII and data security incidents
Communication
Detection and improvement
Team leverage
What You Bring
Required
5+ years in security operations or incident response, with at least 2 years leading investigations independently on high-severity incidents.
Deep, practical expertise in:
SIEM / detection engineering - query languages (KQL, SPL, or equivalent), correlation logic, detection tuning, log source onboarding (e.g., Microsoft Sentinel, Rapid7 InsightIDR, Splunk).
Identity and access - Microsoft Entra ID / Active Directory, Conditional Access, MFA, OAuth/consent grants, token and session abuse, privileged access, offboarding controls.
Email security - BEC and phishing investigation, header/URL/attachment analysis, mail-flow rules, DMARC/DKIM/SPF, secure email gateway and API-based email security tools.
Endpoint - EDR investigation and response (Defender for Endpoint, CrowdStrike, or similar), persistence and lateral movement techniques.
Network security - firewall, proxy, VPN, and DNS log analysis; understanding of segmentation, C2 patterns, and data exfiltration indicators.
Fluency with MITRE ATT&CK and the ability to map observed activity to it.
Strong written communication: you can write an executive status update and a technical timeline in the same hour, and both are clear.
Judgment: you know when to contain immediately, when to watch, and when to escalate, and you can explain why.
Experience investigating incidents involving PHI/PII or other regulated data, including scoping data exposure and supporting breach risk assessments.
Preferred
Teammate Benefits
As an Accendra Health employee, you have choices to fit your life. Our comprehensive benefits program is designed to meet you where you are - through all of life's stages. We've got you and your family covered with benefits that support your health, finances, and overall wellness.
Our benefits program includes:
Medical, dental, and vision care coverage
Paid time off plan
401(k) Plan
Flexible Spending Accounts
Basic life insurance
Short-and long-term disability coverage
Accident insurance
Teammate Assistance Program
Paid parental leave
Domestic partner benefits
Mental, physical, and financial well-being programs
If you feel this opportunity could be the next step in your career, we encourage you to apply.
Accendra is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, sex, sexual orientation, genetic information, religion, disability, age, status as a veteran, or any other status prohibited by applicable national, federal, state or local law.
Note: Accendra is not accepting unsolicited assistance from search firms for this employment opportunity. Please, no phone calls or emails. All resumes submitted by search firms to any employee at our Company via email, the Internet, or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of our Company. No fee will be paid in the event the candidate is hired by our Company as a result of the referral or through other means.
#AccendraHealth