🌍 Global Remote Network: Over 120,135+ verified remote jobs with transparent salaries & visa sponsorship. Browse Remote Jobs →
N

Incident Response (IR) Tier III Lead (Senior Consultant MIS Lvl B), EITS Security & Risk Management

πŸ“ Manhattan, NY πŸ’° 130,000 – 150,000 USD / yr πŸ•’
Work Model
πŸ“ Manhattan, NY
Employment
πŸ’Ό Full-Time Direct
Recruitment Type
πŸ›‘οΈ Direct to HR Pipeline
πŸ›‘οΈ
Human-Verified Opening: Inspected by Sarah Jenkins, CIPD • RemoteVault Editorial Team. Authenticated directly from NYC Health + Hospitals's hiring pipeline • Zero recruiter markups or candidate fees. Verification Standards →

πŸ“‹ Role Overview & Responsibilities

About NYC Health + Hospitals

Empower Every New Yorker β€” Without Exception β€” to Live the Healthiest Life Possible

NYC Health + Hospitals is the largest public health care system in the United States. We provide essential outpatient, inpatient and home-based services to more than one million New Yorkers every year across the city’s five boroughs. Our large health system consists of ambulatory centers, acute care centers, post-acute care/long-term care, rehabilitation programs, Home Care, and Correctional Health Services. Our diverse workforce is uniquely focused on empowering New Yorkers, without exception, to live the healthiest life possible.

Job Description

The Senior Management Consultant, EITS Security Incident Response (IR) Tier III will lead incident handling and perform in-depth forensic investigations, investigate alerts escalated by lower tiers, perform malware analysis, help review and enhance the current IR program, develop and lead threat hunting program, as well as help building a Security Operations Center. This position will collaborate and work closely with members of the ISRM team to develop innovative and effective procedures for incident response operations, collaborate on incident response efforts with multiple city agencies and external partners, coordinate table top exercises and oversee training for lower tiers.

The EITS Security Incident Response (Tier III) is part of the Enterprise Information Technology Services, Information Security and Risk Management team and will work at an enterprise level to ensure a consistent delivery of information security and risk management services with focus on digital forensics and incident response (DFIR). This individual will act as a subject matter expert in DFIR - digital forensics and incident response (DFIR) and serve as escalation point for lower tiers.

Duties & Responsibilities

Develop and lead threat hunting programLead and mature the current incident response programConduct in-depth malware analysis, host and network forensics, log analysis, and be able to triage alertsUtilize Security Incident & Event Management (SIEM) technologies; ArcSight preferred, host forensics tools (e.g. Autopsy, Forensic Toolkit (FTK), F-Response), Endpoint Detection & Response tools, and network forensics (full packet capture solution) to perform threat hunting and investigative activityAttend regular team meetings and facilitate meetings between stakeholders, project leaders, and the Information Technology teams to help implement (where applicable) remediation plans in response to incidentsEffectively investigative and identify root cause findings then communicate findings to stakeholders including technical staff, and leadershipImprove security monitoring, analysis and incident response process by recognizing APT activities, indicators of compromise (IOCs), ingestion of additional log sources into the SIEMIdentify, develop and build scripts, tools, security content to enhance the incident investigation processes, automate where applicableAssist in developing, updating Standard Operating Procedures (SOPs), playbooks, incident response plan and training documentation when neededStay current with vulnerability information across all the products in H+H environment, maintain knowledge of the threat landscapeKeep informed on current threats and industry regulationsAttend regular team, management, and project meetings and provide both verbal and written reports to the Leadership Team as required.Develop a strong working relationship within the ISRM team to develop and implement controls and configurations aligned with security policies and legal, regulatory and audit requirementsBe able to justify blocking requests for IOCs or additional security controls to staff within the ISRM team and other Enterprise IT teams

Minimum Qualifications

A Baccalaureate Degree from an accredited college or university with a major in Computer Science, Systems Engineering, applied Mathematics, Business Administration, Economics/Statistics, Telecommunications, Data Communications, or a related field of study; andFive (5) years of progressive, responsible experience in the field of data processing, computer systems and applications.

Operations Specialty requires supervisory experience (5 years).

Network Services requires a telecommunications background and experience.

Broad knowledge and expertise in the characteristics of computers, peripheral devices, communications systems and hardware capabilities, programming languages, E.D.P. applications, systems analysis methodology, data management and retrieval techniques; orA satisfactory equivalent combination of training, education and experience.

Department Preferences

CISSP, GSEC, CEH, GCFA or other relevant security qualificationShould have at least five years of experience dedicated to IT/Cyber Security, including Incident ResponseCyber Threat Intelligence and analysisForensic and Malware AnalysisDeep packet and log analysisUnderstanding of Windows and Linux forensic artifactsStrong knowledge of Security Incident & Event Management (SIEM) technologies; ArcSight preferredFull understanding of Tier 1/2 responsibilities/duties and how these feed into Tier 3.Ability to take lead on incident research and mentor junior analystsUnderstanding vulnerability and patch managementStrong knowledge of vulnerability scoring systems (CVSS/CMSS), and security frameworks like OWASP (Open Web Application Security Project), MITRE ATT&CKGood understanding of Windows and Linux patchingExcellent writing and communication skillsKnowledge of network and operating system securityKnowledge of encryption algorithms, known vulnerabilities from alerts, advisories, errata and bulletinsUtilize/understand the use of open source tools such as Nmap, Shodan, and Metasploit to identify and confirm vulnerabilities and attack surfaceBe able to create or modify scripts using frameworks such as PowerShell or PythonMust possess a high degree of integrity and trust along with the ability to work independently as well as work as part of a fast-moving teamStrong Knowledge of infrastructure, application and security protocols in addition to configuration management techniquesKnowledge of network security architecture concepts, including topology, protocols, components, traffic flows across the network (e.g. TCP/IP, OSI, etc.)Experience working with operating systems (Microsoft Windows, Linux, UNIX, etc)Must possess a high degree of integrity and trust along with the ability to work independentlyParticipate in special projects as needed and perform other duties as assignedMust be able to work independently as well as work as part of a fast moving teamMust be able to work at various locations when necessary along with working various shiftsDetail oriented, organized, methodical, follow up skills with an analytical thought processAbility to learn new technologies

How To Apply

Please be advised that proof of Covid-19 vaccination is required prior to hire.

If you wish to apply for this position, please apply online by clicking the "Apply Now" button.

If applying online, please include your cover letter in the same file attachment with your uploaded resume.

NYC Health and Hospitals offers a competitive benefits package that includes:

Comprehensive Health Benefits for employees hired to work 20+ hrs. per weekRetirement Savings and Pension PlansLoan Forgiveness Programs for eligible employeesPaid Holidays and Vacation in accordance with employees' Collectively bargained contractsCollege tuition discounts and professional development opportunitiesMultiple employee discounts programs

Frequently Asked Questions

How do I apply for the Incident Response (IR) Tier III Lead (Senior Consultant MIS Lvl B), EITS Security & Risk Management position at NYC Health + Hospitals? β–Ό

Click the “Apply for this Position” button on this page to submit your application directly to NYC Health + Hospitals without recruitment intermediary fees.

Is this position eligible for remote work or visa sponsorship? β–Ό

This position is located in Manhattan, NY with potential relocation and sponsorship assistance depending on candidate qualifications.

Are there any candidate fees on Hirely? β–Ό

No. Hirely is completely free for candidates. We never charge registration fees or placement fees.

πŸ›‘οΈ Job Seeker Safety Advisory

Legitimate employers will never ask you to transfer funds, purchase equipment from unauthorized vendors, or pay application/visa fees. Hirely rigorously monitors listings, but always verify communication is from official corporate email domains.

Learn how to protect yourself against employment fraud →
← Explore Other Roles