Jobs · Information Technology

Incident Response Analyst

Fortified Health Security · United States · 2 wk ago
RemoteRemoteInformation TechnologyFull-time

About the role

The Incident Response Analyst executes and delivers Incident Response Services for Fortified Health Security, primarily focusing on the Incident Response Retainer and Maturity Program (IR Retainer) for healthcare clients. This role includes a 90-day onboarding period with limited client-facing exposure before transitioning to supervised client participation. The IR Retainer program provides proactive managed services to enhance clients' incident response capabilities across people, processes, and technology.

During declared cybersecurity incidents, the analyst assists the IR Services team with tasks essential to the incident response cycle, such as gathering and organizing assessment documentation or supporting forensic evidence collection under direct supervision. Chain-of-custody procedures and forensic integrity standards must be followed. The role requires foundational knowledge of incident response plans, policies, and stakeholder roles, along with diligent documentation and reporting of areas for improvement. Extended hours, including nights, holidays, and weekends, may be required to support emergency situations.

Responsibilities

  • Work collaboratively with Fortified team members and clients.
  • Support proactive IR maturity services, including assessments, documentation, evidence collection, and tabletop exercises under close guidance from senior team members.
  • Deliver routine client status updates as assigned; all client communications are reviewed and validated by senior team members during the onboarding period.
  • Assist with evidence collection activities, including gathering and organizing assessment documentation or supporting forensic evidence collection under direct supervision during active incidents, while adhering to chain-of-custody procedures and forensic integrity standards.
  • Participate in client-facing engagements in a limited and supervised capacity during the initial 90-day onboarding period; transition to observational and supporting participation on client calls under senior team member oversight afterward.
  • Maintain awareness of various technologies and industry knowledge.
  • Maintain currency of existing certifications and pursue relevant industry certifications, such as CompTIA Security+ (baseline) and GCIH or SC-200 (near-term targets within 18 months of hire).
  • Develop foundational knowledge of Incident Response plans, frameworks (e.g., NIST, PICERL), and healthcare regulatory obligations, including HIPAA incident reporting requirements.
  • Deliver consultative and advisory services as defined by Fortified’s Incident Response Retainer and Maturity Program.
  • Assist in the detection, analysis, containment, eradication, and recovery phases of cybersecurity incidents and contribute to lessons learned/preparation processes.
  • Work effectively in a small team environment with strong communication skills.
  • Accurately enter and submit time by required deadlines.
  • Book travel in adherence to company/client travel policy.
  • Maintain documentation of customer interactions and detailed notes pertaining to actions taken during projects.
  • Familiarize with Fortified Core Services and make appropriate recommendations to clients.
  • Attend and participate in team and departmental meetings as needed.

Requirements

  • Bachelor's Degree in Computer Science, Information System Management, or a relevant combination of training and experience.
  • 0–2 years of work experience in Incident Response, security, or an IT-related field; academic or lab exposure to IR concepts is acceptable at entry.
  • Healthcare IT experience is a plus; foundational awareness of HIPAA and healthcare incident reporting obligations is expected.
  • Understanding of digital forensics and eDiscovery.
  • Solid understanding of hardware and networking terminology and devices.

Skills

  • Understanding and familiarity with EDR and Forensic Technologies (e.g., Cybereason, CrowdStrike, SentinelOne, FTK Imager, Velociraptor).
  • Foundational familiarity with scripting and automation concepts via PowerShell, command line, bash, or equivalent; awareness of how automation supports IR workflows.
  • Experience with network security and threat hunting.
  • Thorough understanding of the latest security principles, techniques, and protocols.
  • Familiarity with policy development, planning, and documentation.
  • Ability to work and communicate effectively with clients, third-party vendors, and other departments in a professional manner.
  • Strong interpersonal skills, including verbal and written communication.
  • Resourcefulness and ability to take initiative in development and completion of work projects.
  • Proven problem resolution and critical thinking skills.
  • Flexibility and ability to work with a high level of initiative.
  • Ability to retain and protect confidential material.
  • Ability to demonstrate supportive relationships with peers, clients, partners, and corporate executives.

Qualifications

  • Preferred entry-level certifications include CompTIA Security+ or equivalent; GCIH or SC-200 are identified as near-term targets. All certifications will be considered.
  • Time allotted for the pursuit and maintenance of certifications is coordinated at the team level.

Schedule

  • Evening and weekend hours should be anticipated to support emergency situations.

Travel

Travel as needed, up to 10% should be anticipated.

Similar jobs