ActiveJobs
GE Healthcare

Staff Incident Responder

GE Healthcare · HUN02-01-Budapest-Vaci Greens C

Full-timeOn-sitePosted 14 September 2026
Apply on Company Site →

Job description

Job Description SummaryAs a Staff Incident Responder, you will be a senior technical member of a global, follow-the-sun incident response team, accountable for investigating and responding to cybersecurity incidents across endpoint, network, identity, cloud, and SaaS environments. You will handle incidents from initial triage through containment, eradication, recovery, and lessons learned, and participate in on-call and major-incident rotations. In this role, you will operate with minimal direction, exercise sound judgment under time pressure and with incomplete information and recognize when escalation is required. You will also be a visible partner to teams outside Security, clearly explaining risks and influencing outcomes. As a Staff Incident Responder, you will serve as a technical escalation point, mentor other responders, and maintain proficiency in modern adversary tradecraft, including the malicious use of AI and automation. You will apply that expertise to strengthen detections, improve playbooks and response tooling, automate repeatable tasks, and translate lessons learned into measurable improvements in the organization’s detection and response capabilities.tex Job Description Responsibilities In this role, you will: Conducting incident response across incidents of varying types and severities, using EDR, SIEM, cloud security, identity, email, network, and other investigative tooling throughout triage, containment, eradication, and recovery. Producing clear, timely investigation records, technical findings, incident reports, and stakeholder updates that document scope, impact, decisions, actions, and remaining risk. Serving as a technical escalation point and, when assigned, incident commander for high-severity and complex incidents, driving investigation strategy and coordinating technical and nontechnical stakeholders. Performing deep technical analysis to reconstruct attacker activity, identify tactics, techniques, and procedures, determine root cause and impact, and assess attribution when supported by sufficient evidence. Developing containment, eradication, and recovery strategies in partnership with IT, Cloud, Application, Identity, Legal, Privacy, Communications, and business leaders, restoring operations without unnecessarily destroying evidence or leaving the adversary with continued access. Conducting threat hunts and translate findings from incidents and emerging threats into new or improved detections, reduced false positives, stronger controls, and more effective response workflows. Driving security-hardening initiatives based on incident root-cause analysis and track corrective actions through validation and closure. Evaluating and responsibly apply AI-assisted and agentic capabilities to improve incident triage, investigation, detection, and response workflows, with appropriate human oversight and validation. Continuously improving incident-response playbooks, procedures, tooling, automation, and forensic capabilities using lessons learned from incidents, exercises, and post-incident reviews. Mentoring responders, share technical knowledge, and promote consistent investigative practices and decision-making across the global CIRT. Participating in a rotating on-call schedule, including response outside normal business hours during significant incidents, and provide complete follow-the-sun handoffs across regions. Required Qualifications Bachelor’s degree in Computer Science, Cybersecurity, a related field, or equivalent practical experience. Demonstrable hands-on experience in security operations or incident response, with a track record of owning high-impact incidents end to end and coordinating across technical and business stakeholders. Demonstrated ability to independently prioritize and complete multiple tasks with little to no supervision. Willingness and ability to participate in a rotating on-call schedule, including occasional after-hours, weekend, and holiday response during significant incidents. Strong verbal and written communication skills, including the ability to explain technical risk to non-technical stakeholders. What Will Help You Succeed? You apply critical thinking and analytical rigor: forming hypotheses, seeking disconfirming evidence, distinguishing facts from assumptions, and resisting premature conclusions when information is incomplete or contradictory. You bring deep technical curiosity and continually develop your understanding of attacker techniques, emerging technologies, and how systems fail at a mechanical level. You work effectively both independently and within an incident-command structure, taking ownership with minimal direction while managing competing priorities and recognizing when to seek guidance or escalate. You remain composed and methodical during high-severity incidents, making defensible decisions under pressure and adapting as new evidence emerges. You communicate effectively with diverse technical and nontechnical audiences and influence outcomes across organizational, cultural, and functional boundaries. You practice sustainable teamwork by supporting colleagues through on-call rotations and high-tempo incidents, documenting work clearly, and enabling clean follow-the-sun handoffs. #LI-MT1 #LI-Hybrid

Verified and listed by ActiveJobs. Applications are made directly on GE Healthcare's own career page — we never sit in the middle.