Cyber Security Specialist Lead

Franciscan Alliance, Inc.
•$96,732 - $133,006•Remote

About The Position

The Cyber Security Specialist Lead investigates and analyzes all response activities related to cyber incidents within the network environment or enclave. Collects data from a variety of Computer Network Defense (CND) tools, including intrusion detection system alerts, firewall and network traffic logs, and host system logs to analyze events that occur within their environment. Provides operations for persistent monitoring of all designated networks, enclaves, and systems. Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events. Acts as of the highest level of escalation point. Distributes directives, vulnerability, and threat advisories to identified consumers.

Requirements

  • Associate's Degree
  • 8 years Information Technology or Information Security Department Required

Nice To Haves

  • SPLUNK CLOUD / ON PREMISE EXPERIENCE PREFERRED.
  • Bachelor's Degree
  • Certificate
  • 5 years Healthcare industry; experience in security operations activities aligning with Essential Job Functions Preferred

Responsibilities

  • Work with Security Architects to develop roadmaps and implementation plans for upgrading, enhancing or replacing security technologies for which the Cyber Security Operations team is responsible.
  • Demonstrate advanced proficiency to write and optimize complex SPL queries to identify and investigate suspicious activity, correlate events, identify attack patterns, and perform proactive threat hunting across security data.
  • Create, test, tune, and maintain high-fidelity detections; reduce false positives; utilize risk-based alerting; and establish detection thresholds and governance.
  • Stay abreast of current artificial intelligence capabilities of the SIEM and other deployed security tools, develop and implement these capabilities to improve SOC performance.
  • Lead the SOC efforts during investigation of high-severity security incidents, participate in the cyber security incident response team, and guide analysts through the incident response lifecycle.
  • Develop, maintain, and safely execute SOAR playbooks; automate enrichment and response tasks; and identify opportunities to reduce repetitive analyst work.
  • Understand security data sources, field extractions, data models, and the common information model (CIM), troubleshoot data quality issues, and validate detections are operating against reliable data.
  • Serve as a technical escalation point, coach analysts, review investigations, establish investigation standards, and communicate clearly with SOC management and other security teams.
  • Build Splunk dashboards and reports to measure data sources, alert volume, detection performance, investigation quality, and SOC effectiveness.
  • Build detections for anomalous user and entity behavior, create procedures to investigate compromised accounts and lateral movement, use risk context to prioritize investigations.
  • Work with internal resources and external 3rd parties to design and conduct penetration tests, including ones designed as “stimulus-response” for the centralized log management system.
  • Create and review cyber security policies, procedures, and standards related to Security Operations Center, Vulnerability Management, and Incident Response processes.

Benefits

  • Comprehensive benefit offerings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service