Loading jobs…
Loading jobs…
Datavant — Galway, Connacht
Datavant is the data collaboration platform trusted for healthcare. Guided by our mission to make the world’s health data secure, accessible and actionable, we provide critical data solutions for organizations across the healthcare ecosystem - including providers, health plans, researchers, and life sciences companies. From fulfilling a single patient’s request for their medical records to powering the AI revolution in healthcare, Datavanters are building the future of how data is connected and used to improve health.
By joining Datavant today, you’re stepping onto a driven and highly collaborative team that is passionate about creating transformative change in healthcare. Become a vital defender of our digital landscape as a SOC/SIRT Engineer. You’ll monitor and analyze security alerts, swiftly respond to incidents, and collaborate with top IT and security teams to fortify our defenses.
If you’re passionate about cybersecurity and ready to make a significant impact, join us and elevate your career. You will: Respond to and investigate security incidents across the environment, taking ownership of moderate to complex incidents from triage through resolution. Execute and contribute to the development of incident response playbooks, supporting continuous improvement of SOC/SIRT processes.
Monitor and analyze security alerts from SIEM, EDR, DLP and cloud platforms, escalating appropriately and documenting findings. Collaborate with Detection Engineering, IT, and cross-functional teams to coordinate response efforts and share threat intelligence. Support M A security integrations by assessing acquired entity environments and ensuring alignment with Datavant security standards.
Assist in mentoring junior analysts, sharing knowledge and providing guidance on investigations and best practices. Contribute to SOC training and tabletop exercises to strengthen team readiness and incident response capabilities. Identify opportunities to improve and automate manual SOC processes, reducing response times and manual intervention.
Communicate security incidents and findings clearly to technical peers and, when needed, to non-technical stakeholders. Create and maintain security documentation including incident response playbooks, SOPs, and runbooks, ensuring procedures are current and accessible to the team. What you will bring to the table: 3+ years of experience in Security Operations, with hands-on experience in incident response and security investigations.
Proven experience investigating and triaging alerts within a SIEM platform, including correlating events, identifying anomalies, and documenting findings. Hands-on experience with EDR platforms for endpoint investigation, threat hunting, and containment. Hands-on experience with DLP tools and data exfiltration investigation, including identifying and responding to policy violations and insider threat indicators.
Experience with cloud incident response across one or more major cloud providers, including investigating IAM anomalies, API activity, and cloud-native security alerts. Strong understanding of Windows event logs, authentication artifacts, and other investigation-relevant data sources. Proven experience executing the full incident response lifecycle — triage, containment, eradication, recovery, and lessons learned — across a range of incident types and severities.
Ability to communicate security findings clearly to both technical peers and non-technical stakeholders. Experience creating and maintaining security documentation including SOPs, runbooks, and incident response playbooks. Availability for on-call duties including nights, weekends, and holidays to respond to high-priority incidents Exceptional critical thinking, analytical skills, and attention to detail.
Excellent written and oral communication skills, with the ability to convey complex information clearly and persuasively.