Staff Incident Responder
GE HealthCare
This listing was originally posted on GE HealthCare's careers page. Formulate is an equal opportunity job aggregator and is not involved in the hiring process. Where salary information is estimated, it is derived from BLS industry benchmarks and may differ from actual compensation.
Upgrade to Pro to access the AI-generated 'Read before applying' briefing and other premium pharma intelligence.
Upgrade to Pro — $25/moResponsibilities
In this role, you will:
Conducting incident response across incidents of varying types and severities, using EDR, SIEM, cloud security, identity, email, network, and other investigative tooling throughout triage, containment, eradication, and recovery.
Producing clear, timely investigation records, technical findings, incident reports, and stakeholder updates that document scope, impact, decisions, actions, and remaining risk.
Serving as a technical escalation point and, when assigned, incident commander for high-severity and complex incidents, driving investigation strategy and coordinating technical and nontechnical stakeholders.
Performing deep technical analysis to reconstruct attacker activity, identify tactics, techniques, and procedures, determine root cause and impact, and assess attribution when supported by sufficient evidence.
Developing containment, eradication, and recovery strategies in partnership with IT, Cloud, Application, Identity, Legal, Privacy, Communications, and business leaders, restoring operations without unnecessarily destroying evidence or leaving the adversary with continued access.
Conducting threat hunts and translate findings from incidents and emerging threats into new or improved detections, reduced false positives, stronger controls, and more effective response workflows.
Driving security-hardening initiatives based on incident root-cause analysis and track corrective actions through validation and closure.
Evaluating and responsibly apply AI-assisted and agentic capabilities to improve incident triage, investigation, detection, and response workflows, with appropriate human oversight and validation.
Continuously improving incident-response playbooks, procedures, tooling, automation, and forensic capabilities using lessons learned from incidents, exercises, and post-incident reviews.
Mentoring responders, share technical knowledge, and promote consistent investigative practices and decision-making across the global CIRT.
Participating in a rotating on-call schedule, including response outside normal business hours during significant incidents, and provide complete follow-the-sun handoffs across regions.
Required Qualifications
Bachelor’s degree in Computer Science, Cybersecurity, a related field, or equivalent practical experience.
Demonstrable hands-on experience in security operations or incident response, with a track record of owning high-impact incidents end to end and coordinating across technical and business stakeholders.
Demonstrated ability to independently prioritize and complete multiple tasks with little to no supervision.
Willingness and ability to participate in a rotating on-call schedule, including occasional after-hours, weekend, and holiday response during significant incidents.
Strong verbal and written communication skills, including the ability to explain technical risk to non-technical stakeholders.
What Will Help You Succeed?
You apply critical thinking and analytical rigor: forming hypotheses, seeking disconfirming evidence, distinguishing facts from assumptions, and resisting premature conclusions when information is incomplete or contradictory.
You bring deep technical curiosity and continually develop your understanding of attacker techniques, emerging technologies, and how systems fail at a mechanical level.
You work effectively both independently and within an incident-command structure, taking ownership with minimal direction while managing competing priorities and recognizing when to seek guidance or escalate.
You remain composed and methodical during high-severity incidents, making defensible decisions under pressure and adapting as new evidence emerges.
You communicate effectively with diverse technical and nontechnical audiences and influence outcomes across organizational, cultural, and functional boundaries.
You practice sustainable teamwork by supporting colleagues through on-call rotations and high-tempo incidents, documenting work clearly, and enabling clean follow-the-sun handoffs.
#LI-MT1
#LI-Hybrid
Relocation Assistance Provided: No
Explore related positions you might be interested in
We'll notify you when matching roles are posted.
Interviewed at GE HealthCare?
Help others prepare — share your experience anonymously.
Upgrade to Pro to access AI interview prep brief and other premium pharma intelligence.
Upgrade to Pro — $25/moUpgrade to Pro to access salary benchmarks and market rate data and other premium pharma intelligence.
Upgrade to Pro — $25/mo