Senior Security Analyst

JobgetherUnited StatesOn-siteFull-timeMid level, 2–5 yearsListed 4 hours ago

Apply now

About this role

Accountabilities:

- Monitor and analyze security events and alerts across networks, endpoints, cloud platforms, and applications.

- Investigate suspicious activity and lead incident response activities, including triage, containment, eradication, and recovery.

- Serve as an escalation point for complex security incidents and coordinate cross-functional response efforts.

- Maintain and optimize SIEM, EDR, and other security tools to improve detection capabilities and reduce false positives.

- Conduct root cause analysis and document incidents, remediation activities, and lessons learned.

- Ensure security practices align with HIPAA, HITECH, and other applicable healthcare privacy and regulatory requirements.

- Participate in security risk assessments, gap analyses, internal and external audits, and third-party assessments.

- Develop and maintain security policies, standards, and procedures aligned with regulatory and industry expectations.

- Monitor controls designed to protect PHI, manage data access, and prevent security breaches.

- Support audit readiness and remediation of compliance findings.

- Conduct vulnerability scans and coordinate remediation with infrastructure and application teams.

- Prioritize vulnerabilities based on business impact, exploitability, and regulatory exposure, and track progress toward risk reduction.

- Perform risk assessments for new systems, vendors, and technology implementations.

- Contribute to third-party risk management and vendor security reviews.

- Collaborate with infrastructure and application teams on secure configurations, security controls, and system implementations.

- Evaluate and recommend security technologies and solutions that strengthen the organization's protection capabilities.

- Support secure design reviews for applications, systems, and integrations and validate security controls across network, endpoint, and cloud environments.

- Review and monitor access to systems containing PHI and sensitive information, supporting provisioning, deprovisioning, and periodic access reviews.

- Investigate access anomalies and promote least-privilege access principles.

- Support security awareness and training initiatives focused on healthcare threats such as phishing and ransomware.

- Advise IT and business teams on security best practices and risk mitigation.

- Identify opportunities to improve security processes, tools, monitoring, and response capabilities.

- Mentor junior security analysts and contribute to the growth and development of the security function.

Requirements:

- Bachelor's degree in Cybersecurity, Information Technology, or a related field preferred; equivalent professional experience may be considered.

- 5+ years of experience in cybersecurity, information security, or a related field.

- At least 2 years of experience in healthcare IT, cybersecurity, or another regulated environment.

- Demonstrated experience with incident response, threat detection, vulnerability management, and security operations.

- Experience supporting security audits and compliance programs in regulated industries.

- Strong knowledge of SIEM, EDR, security monitoring, and log analysis.

- Strong understanding of network security concepts, including firewalls, IDS/IPS, and network segmentation.

- Experience with endpoint security and device hardening.

- Understanding of cloud security principles across Azure, AWS, or comparable platforms.

- Experience with vulnerability scanning and remediation tools.

- Knowledge of HIPAA Security and Privacy Rules and familiarity with NIST Cybersecurity Framework and/or NIST 800-53.

- Familiarity with HITRUST CSF is preferred.

- Knowledge of identity and access management practices and least-privilege principles.

- Understanding of secure system and application design principles.

- Strong analytical and problem-solving skills, with the ability to assess complex security threats and determine appropriate responses.

- Ability to lead incident response activities with urgency, sound judgment, and composure.

- Excellent written and verbal communication skills, including security documentation and reporting.

- Strong attention to detail and ability to manage multiple priorities in a fast-paced environment.

- Ability to collaborate effectively with IT, compliance, legal, business, and external stakeholders.

- High level of integrity and discretion when working with sensitive and confidential information.

- CISSP, CISM, or CISA certification is strongly preferred; CEH, Security+, or GIAC certifications are beneficial.

- Experience with healthcare systems such as EHR/EMR platforms, including Epic or Cerner, is a plus.

- Experience with ransomware preparedness and response in healthcare environments is desirable.

- Familiarity with Microsoft security technologies such as Defender, Sentinel, and Entra ID, or comparable platforms, is preferred.

- Experience supporting HITRUST certification or attestation is a plus.

Benefits:

- Annual salary range of $110,000–$120,000 USD.

- Fully remote position within the United States.

- Purpose-driven work supporting the protection of sensitive healthcare information and systems.

- Patient-focused, collaborative work environment.

- Opportunities to contribute to cybersecurity strategy, compliance, and continuous improvement.

- Opportunity to mentor and develop junior security professionals.

- Supportive environment focused on collaboration, accountability, and professional growth.

- Comprehensive benefits and employee support programs.

- Reasonable accommodations available throughout the application and employment process.

How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1