Cyber Security Incident Response Specialist
Fort Myers, FL, United States
Millennium Physician Group
Millennium Physician Group is one of the largest physician groups with more than 550 healthcare providers in Florida.Mosaic Health is a national care delivery platform focused on expanding access to comprehensive primary care
for consumers with coverage across Commercial, Individual Exchange, Medicare, and Medicaid health plans.
The Business Units which comprise Mosaic Health are multi-payer and serve nearly one million consumers
across 19 states, providing them with access to high quality primary care, integrated care teams, personalized
navigation, expanded digital access, and specialized services for higher-need populations. Through Mosaic
Health, health plans and employers have an even stronger care provider partner that delivers affordability and
superior experiences for their members and employees, including value-based primary care capacity
integrated with digital patient engagement and navigation. Each of the companies within Mosaic Health
provide unique offerings that together promise to improve individuals' health and wellbeing, while helping
care providers deliver higher quality care. For more information, please visit www.mosaichealth.com or
follow Mosaic Health on LinkedIn.
Formed in 2008 and headquartered in Fort Myers, Florida, with offices in Florida, North Carolina, and Texas,
Millennium Healthcare is the largest independent physician group in the state of Florida and one of the largest
in the United States. At Millennium Physician Group, our employees are the foundation of our success. Our
promise is to provide you with the tools to do your job successfully, as well as providing a team atmosphere
that empowers you to seek better ways to deliver care to our patients and their families. We also promise to
care for you as an individual and help you grow in your role.
The Cyber Security Incident Response Specialist will support all business units within Mosaic Health and is responsible for
identifying, analyzing, and mitigating cyber security incidents within the organization. This role is responsible
for managing the day-to-day response to cyber threats, investigating incidents, performing digital forensics,
and ensuring that security incidents are addressed in compliance with established procedures. The Incident
Response Specialist is instrumental in ensuring that security breaches are contained, remediated, and
documented effectively while minimizing the impact on the organization's operations and data integrity.
This role requires expertise in cyber security operations, incident handling, and forensic analysis, and demands
the ability to work under pressure in high-stakes situations.
Responsibilities
• Lead incident response efforts for detected cyber security events, ensuring timely identification,
containment, remediation, and recovery from incidents.
• Perform forensic collections, intrusion correlation and tracking, threat analysis, and direct system
remediation as incidents evidence unfolds.
• Collaborate to ensure that incident response protocols and procedures are followed, maintaining
consistency across the organization.
• Support the development and improvement of incident response playbooks, ensuring effective and
efficient handling of different types of security incidents (e.g., ransomware, phishing, APTs).
• Document and report all incidents thoroughly, capturing detailed information regarding the event,
timeline, severity, and remediation actions taken.
• Coordinate communication between technical teams, business units, legal, compliance, and
stakeholders during and after an incident, ensuring clarity and alignment.
• Perform post-incident analysis to identify lessons learned, suggesting improvements to security
controls, processes, and response strategies to prevent recurrence.
• Monitor and analyze security data from various sources (e.g., SIEM, IDS/IPS, firewalls) to proactively
identify threats and anomalies that may indicate potential security incidents.
• Support threat hunting activities, working to identify hidden threats and vulnerabilities across the
organization's infrastructure before they result in active incidents.
• Collaborate with internal teams (e.g., network security, IT, DevOps) to ensure the continuous
improvement of defensive measures, including firewalls, endpoint protection, and security
monitoring tools.
• Assist in the development of security training and awareness programs for staff, ensuring they
understand the importance of cyber hygiene, phishing prevention, and early incident detection.
• Participate in tabletop exercises and simulations to test the organization's readiness for responding
to major security incidents.
• Stay up to date with the latest cyber threats, vulnerabilities, and incident trends to ensure that the
organization's defenses are adapted to emerging risks.
• Maintain documentation for regulatory compliance, ensuring that incident handling processes align
with applicable legal and industry requirements (e.g., HIPAA, NIST).
• Perform other related duties as assigned.
• Demonstrate excellent guest service to internal team members and patients.
• Perform other related duties as assigned.
Qualifications
• Bachelor's degree in cyber security, Information Technology, Computer Science, or a related field.
• 2+ years of experience in cyber security operations, incident response, or a related field.
• Hands-on experience with incident response tools, including SIEM platforms (e.g., Splunk, Sentinel),
IDS/IPS systems, and endpoint protection tools.
• Strong understanding of network protocols, system architecture, and common attack techniques
(e.g., phishing, ransomware, DDoS, advanced persistent threats (APTs)).
• Experience with digital forensics, including memory analysis, log correlation, and malware analysis to
investigate and determine the impact of security incidents.
• Knowledge of incident response frameworks (e.g., NIST, MITRE ATT&CK, SANS) and best practices for
managing and mitigating cyber incidents.
• Familiarity with cloud environments (e.g., AWS, Azure) and their security considerations in the
context of incident response.
• Ability to work under pressure, managing multiple incidents simultaneously while ensuring highquality documentation and timely resolution.
• Strong communication skills to articulate complex security concepts to both technical and nontechnical stakeholders.
• Certifications preferred: Certified Incident Handler (GCIH), Certified Information Systems Security
Professional (CISSP), Certified Ethical Hacker (CEH), Certified Forensic Computer Examiner (CFCE), or
similar.
• Ability to work independently in a fast-paced, cross-functional environment.
• A commitment to providing excellent service to internal team members and patients.
• High level of professionalism and integrity in all interactions.
• Ability to work independently in a fast-paced, cross-functional environment.
Physical Demands
• Sedentary work. Exerting up to 10 pounds of force occasionally and/or negligible amount of force
frequently or constantly to lift, carry, push, pull, or otherwise move objects. Repetitive motion.
Substantial movements (motions) of the wrists, hands, and/or fingers. The worker must have close
visual acuity to perform an activity such as: preparing and analyzing data and figures; transcribing;
viewing a computer terminal; extensive reading. Ability to lift to 15 lbs. independently not to exceed
50 lbs. without help.
Equal Employment Opportunity
• Mosaic Health is an Equal Employment Opportunity employer and all qualified applicants will receive
consideration for employment without regard to age, citizenship status, color, creed, disability,
ethnicity, genetic information, gender (including gender identity and gender expression), marital
status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or
condition protected by applicable federal, state, or local laws.
• If you require an accommodation for the application or interview process, please let us know and we
will work with you to meet your needs. Please contact HRbenefits@mpgus.com for assistance.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS Azure CEH CFCE CISSP Cloud Compliance Computer Science DDoS DevOps Firewalls Forensics GCIH HIPAA IDS Incident response IPS Malware MITRE ATT&CK Monitoring Network security NIST SANS Sentinel SIEM Splunk Vulnerabilities
Perks/benefits: Career development Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.