Senior Cyber Incident Responder
Laboratory Corp of America
- Location
- Durham NC
- Work model
- On-Site
- Level
- Senior
- Posted
- Sep 17, 2026
Skills
About this role
Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data, technology and laboratory network, we advance diagnostics, accelerate innovation and help address some of the world’s most important health challenges. As we shape the future of healthcare, we are leveraging advanced technologies, intelligent digital solutions and data-driven innovation across our operations to enhance how work gets done and deliver greater value to customers and patients. With our global scale and deep expertise, you’ll have the opportunity to do meaningful work, grow your career and make a real impact on people’s health around the world. Together, we’re improving health and improving lives. Labcorp is a global leader in diagnostic testing and drug development solutions, helping healthcare providers, researchers, and patients make informed decisions that advance care. Join us in our mission to improve health and improve lives. Work Schedule This is a full‑time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible. Applicants who live within 35 miles of either the Burlington, NC or Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in-office days per week at an assigned location, either Burlington or Durham, supporting both collaboration and flexibility.
RESPONSIBILITIES
Serve as the lead responder for validated cyber incidents—prioritizing threats that could impact clinical operations, electronic health records (EHR), connected medical devices, or protected health information (PHI). Coordinate with technical and clinical stakeholders to contain and remediate threats across hospitals, clinics, and remote care environments. Drive improvements to the Incident Response Plan—ensuring readiness for ransomware, business email compromise, and other threats. Lead triage, containment, and root cause analysis of events affecting clinical applications, patient portals, imaging systems, and backend infrastructure. Analyze logs and EDR telemetry from a wide range of systems—medical devices, cloud applications, employee workstations, and data exchange platforms Perform investigations across Windows, Linux, iOS, and cloud platforms, using SIEM and manual log analysis where required. Lead stakeholder briefings during high-severity incidents. Enrich investigations using internal threat intel, OSINT, and health sector-specific sources (e.g., H-ISAC, HC3 bulletins). Contribute to detection engineering and playbook development aligned with healthcare-specific threat vectors. Write post-incident reports with clear insights for operational, risk, and compliance teams.
MINIMUM REQUIREMENTS
Bachelor's Degree. 3 or more years of experience in cybersecurity. 5 or more years of experience in Windows and Linux OS investigations, network protocol analysis, and EDR telemetry. 2 or more years of experience with incident response frameworks (NIST 800-61, HITRUST IRM, etc.) and adversary models (MITRE ATT&CK, Cyber Kill Chain). 2 or more years of experience in SIEM (e.g., Splunk, Anvilogic), EDR platforms (e.g., CrowdStrike, SentinelOne), and forensic tools. ADDITIONAL JOB STANDARDS Hands-on incident response experience in large enterprise environments (30K+ users, multiple business units or hospitals). Strong understanding of HIPAA security rule, HITECH, and how regulatory requirements intersect with incident handling. Familiarity with common healthcare systems such as Epic, Cerner, HL7/FHIR interfaces, or IoMT devices. Proficient in writing detection rules and custom