Incident Response Manager - Remote

Posted:
8/18/2024, 5:00:00 PM

Location(s):
Illinois, United States ⋅ Chicago, Illinois, United States

Experience Level(s):
Senior

Field(s):
IT & Security

Ann & Robert H. Lurie Children’s Hospital of Chicago provides superior pediatric care in a setting that offers the latest benefits and innovations in medical technology, research and family-friendly design. As the largest pediatric provider in the region with a 140-year legacy of excellence, kids and their families are at the center of all we do. Ann & Robert H. Lurie Children’s Hospital of Chicago is ranked in all 10 specialties by the U.S. News & World Report.

Location

Ann & Robert H. Lurie Children's Hospital of Chicago

Job Description

General Summary:

The Information Security Incident Response Manager will guide resources to prepare for, coordinate, and respond to incidents, including, but not limited to, computer security vulnerabilities, malware, phishing, social engineering, and forensic investigations. This position is responsible for maintaining industry standard security incident response procedures, frequent monitoring of incident detection control effectiveness, and coordinating preparedness exercises. This position will regularly interact with third-party security operations center, incident assistance, and security forensics partners. This position will coordinate with internal Emergency Preparedness teams and contribute to the business continuity posture.

Essential Job Functions:

•    Overall responsibility for Security Incident Response (SIR) policies and procedures in alignment with operations, strategy, staff, tools, technologies, and systems Business Continuity criticality tiers.
•    Conduct and coordinate Information Security Compliance (First Responder) and Organizational (Crisis Manager) preparedness exercises.
•    Oversee administration of Managed Security Service Provider (MSSP) services to include Security Operations Center, Incident Assistance, and Data Forensics firms.
•    Lead security investigations, resolution of system detected anomalies, and major incident avoidance response measures. Formulate standard investigation documentation. 
•    Manages all aspects of technical security incident response to include assessment, containment and reporting. 
•    Overall responsibility for security event monitoring and alerting systems design effectiveness.
•    Overall responsibility for measuring and improving key performance indicators (KPI), such as mean time to detection (MTTD) and mean time to response (MTTR).
•    Continuously review incident reporting requirements and data collection methods to ensure efficiency. Work with management and technical teams to collaborate on data collection and reporting optimization.
•    Participate in projects as required.
•    Perform other duties as assigned.

Knowledge, Skills, and Abilities:


•    Bachelor’s degree, preferably in Computer Science or related information security expertise.
•    5+ years of experience in information security incident response required.
•    CISSP (Certified Information Systems Security Professional), CISA (Certified Information Security Auditor), or equivalent related certification highly desired.
•    Strong knowledge of information security forensics, security operations, security monitoring, technology implementation, risk analysis strategy, and NIST incident response life cycle.
•    Experience and knowledge with information security frameworks, regulatory compliance, and reporting bodies (HITRUST, NIST, HIPAA, DHHS, etc.).
•    Demonstrated team coordination capabilities.

•    Goal oriented with the ability to lead team achievements toward desired results utilizing both internal and external resources.
•    Proficient at professional communication and documentation of processes and procedures.
•    Familiarity and experience with crisis management, disaster recovery, and business availability programs and procedures.

Education

Benefit Statement

For full time and part time employees who work 20 or more hours per week we offer a generous benefits package that includes:

Medical, dental and vision insurance

Employer paid group term life and disability

Employer contribution toward Health Savings Account

Flexible Spending Accounts

Paid Time Off (PTO), Paid Holidays and Paid Parental Leave

403(b) with a 5% employer match

Various voluntary benefits:

  • Supplemental Life, AD&D and Disability

  • Critical Illness, Accident and Hospital Indemnity coverage

  • Tuition assistance

  • Student loan servicing and support

  • Adoption benefits

  • Backup Childcare and Eldercare

  • Employee Assistance Program, and other specialized behavioral health services and resources for employees and family members

  • Discount on services at Lurie Children’s facilities

  • Discount purchasing program

There’s a Place for You with Us

At Lurie Children’s we embrace and celebrate diversity and equity in a serious way. We are committed to building a team with a variety of backgrounds, skills, and viewpoints — recognizing that diverse identities strengthen our workplace and the care we can provide to the Chicago community and beyond. We treat everyone fairly, appreciate differences, and make meaningful connections that foster belonging and allyship. This is a place where you can be your best, so we can give our best to the patients and families who trust us with their care.  

Lurie Children’s and its affiliates are equal employment opportunity employers.  We value diversity and are committed to creating an inclusive environment for all employees.  All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin, ancestry, age, disability, marital status, pregnancy, protected veteran status, order of protection status, protected genetic information, or any other characteristic protected by law.

Support email: [email protected]