Job Information
HCA Healthcare Security Threat Engineer I in Nashville, Tennessee
Do you have the career opportunities as a(an) Security Threat Engineer I you want with your current employer? We have an exciting opportunity for you to join HCA Healthcare which is part of the nation's leading provider of healthcare services, HCA Healthcare.
Job Summary
The Threat Response Engineer 1 – serving as the last line of defense between HCA and the threat actors that wish to bring harm to HCA and the patients we serve – is a critical member of the 24/7 CDC team. They will use state of the art technologies to detect threats on our network and eradicate them as a member of our Cyber Defense Center (CDC). As a member of the CDC, they will operate along with a small team of like-minded individuals with a passion for cyber security.
This role will provide Tier 1 and Tier 2 analysis and response to cyber security threats. Threat Response Engineers will be expected to detect malicious activity and support the business through the Incident Response process for both routine and major events. Successful candidates will have a passion for cybersecurity and be naturally curious and self-motivated to investigate and discover root causes of events while working in a fast-paced and sometimes stressful environment. Good teamwork and communication skills are also vital. Our team operates as a close-knit group serving a noble purpose – to win the fight against evil every day.
Major Responsibilities:
Monitor security alert queue – investigate and triage events based on criticality. Provide recommendations on how to mitigate the threats. Use analytic techniques and critical thinking to determine if and when to escalate threats to larger Cyber Security team.
Provide guidance to field resources on how to properly remediate a threat.
Work closely with other CDC team members to improve tools, techniques, and procedures for CDC operation.
Continuously improve documentation of work products and processes.
Participate in red/blue team exercises.
Execute HCA’s Incident Response plan as part of an incident response team. Serve as Incident Commander, Task Lead, or Scribe during incidents.
Routinely collaborate with individuals and teams from across the enterprise.
Education and Experience
Bachelor's degree preferred
1+ years of relevant experience
Desired Experience:
Experience as a member of a Cyber Incident Response Team (CIRT) or comparable team.
Experience executing an Incident Response plan, preferably based on recognized industry standards (e.g. – NIST, SANS, etc).
Experience in Windows Artifact Analysis and Initial Forensic Analysis (e.g. – Program Execution, File/Folder opening, Account Usage, pulling memory, following proper evidence handling procedures, etc) using industry standard tools and available logs (e.g. – Endpoint Detection and Response (EDR) tools).
Experience in Memory Analysis using tools such as Volatility
Experience in network forensic analysis to determine validity of detected events using available network logs collected via SEIM.
Experience in DFIR (Digital Forensics Incident Response).
Experience with an event/information analysis framework such as Analysis of Competing Hypotheses (ACH). Rev Date 07152025
Experience in performing security analysis or reporting utilizing Security Incident and Event Management (SIEM) Technologies. Preferably Splunk and SPL experience.
Experience with document management and sustaining Security Operations Center (SOC) policies and run book procedures for incident response.
Experience with documenting root cause analysis and lessons learned.
Experience consuming and generating cybersecurity threat intelligence.
Experience across the technology stack. Familiarity with all OSI layers and expertise in some.
Experiencing using the following types of security tools:
SIEM o Firewalls o Web Proxy o Anti-Virus (AV)
Next Gen Anti-Virus (NGAV) o Endpoint Detection and Response (EDR)
Sandboxing
Virtual Machines o Netflow analysis
Malware Repositories
Threat Intelligence o Deception Stack
Intrusion Detection/Prevention System (IDS/IPS)
Security Orchestration Automation Response (SOAR)
Phishing Triage o User Behavior Analytics (UBA)
Email Hygiene and Filtering
Experience interfacing with peer support teams (Security Engineering, Vulnerability and Patching Teams, Networking, Access Management, Legal, Risk/Governance, etc.)
Experience working in a high-tempo, dynamic environment with a high-performance team.
Experience with work ticketing systems (e.g. – ServiceNow, JIRA).
Experience with Threat Modeling and Kill Chain analysis.
Additional Information
Candidate must be located in or willing to relocate to the greater Nashville, TN area.
12 hour rotating work schedule shifts.
Nights and weekend shifts are included.
Recruiter will talk further with you about the work schedule details.
Benefits
HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services
Wellbeing support, including free counseling and referral services
Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence
Savings and retirement resources , including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling
Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing
Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts
Learn more about Employee Benefits (https://careers.hcahealthcare.com/pages/employee-benefits-and-rewards)
Note: Eligibility for benefits may vary by location.
HCA Healthcare has been recognized as one of the World's Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"Bricks and mortar do not make a hospital. People do."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
If you are looking for an opportunity that provides satisfaction and personal growth, we encourage you to apply for our Security Threat Engineer I opening. We promptly review all applications. Highly qualified candidates will be contacted for interviews. Unlock the possibilities and apply today!
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.