IT - Analyst II, Security Systems

ArchWell Health
  • Nashville, TN
    5 days ago

    Job Description

    Analyst II, IT Security

    Job Summary:

    The IT Security Analyst II is responsible for supporting the organization's cybersecurity program through continuous monitoring, incident response, vulnerability management, identity and access governance, security assessments, and administration of security technologies. This role helps protect organizational systems, networks, cloud services, and data assets while supporting security operations, compliance requirements, and risk reduction initiatives.The Analyst II partners with infrastructure, support, application, and business teams to investigate security events, implement security controls, improve security posture, and promote cybersecurity awareness across the organization.

    Duties/Responsibilities:

    Protect organizational systems, identities, networks, cloud platforms, and data from unauthorized access, modification, disclosure, disruption, or destruction.Monitor compliance with endpoint, mobile device, and cloud security standards including encryption, endpoint protection, vulnerability remediation, and secure configuration baselines.Administer and review identity and access management processes including provisioning, deprovisioning, entitlement reviews, privileged access governance, and periodic access certification reviews.Coordinate and support the vendor risk assessment process, including security reviews, documentation collection, risk evaluations, and remediation tracking.Monitor, investigate, and respond to security alerts, log events, suspicious activity, and anomalies across endpoint, network, cloud, email, and identity platforms. Provide operational reporting and coordinate remediation activities as appropriate.Participate in incident response activities including triage, investigation, containment, remediation, documentation, escalation, and post-incident reporting.Perform vulnerability assessments, track remediation efforts, validate corrective actions, and report on organizational risk exposure.Support, maintain, evaluate, and improve cybersecurity technologies including SIEM, EDR/XDR, vulnerability management, email security, endpoint protection, firewall, identity security, and cloud security platforms.Implement and review security controls including application security, access control, data protection, and security configuration standards.Collaborate with infrastructure, network, and cloud teams to design, implement, and support security controls across servers, endpoints, applications, and cloud services.Develop, update, and maintain cybersecurity policies, standards, procedures, and technical security guidance.Adhere and participate in change management.Contribute recommendations for improving security operations, monitoring capabilities, threat detection, and overall cybersecurity maturity.Organize and lead internal phishing campaign efforts, including reporting and presenting to IT and business leadership,Manage and resolve security-related tickets, incidents, service requests, and escalations through internal and vendor-managed ticketing systems. Report on SLA or other service issues as required as they relate to our strategic security business partners,Participate in cybersecurity projects, operational meetings, security reviews, assessments, and cross-functional initiatives.Primary contributor for creating or gathering content for the annual security assessment report.

    Required Skills/Abilities:

    Experience reviewing SIEM alerts, escalations, and security events, including coordinating response activities with internal and external stakeholders.Experience conducting threat hunting activities using SIEM, EDR/XDR, threat intelligence, endpoint telemetry, and log analysis to identify suspicious behavior and potential threats.Strong knowledge of network protocols, attack techniques, attack surface analysis, threat detection methodologies, and mitigation strategies.Strong understanding of DNS, DHCP, TCP/IP, Active Directory, Entra ID, authentication protocols, and enterprise networking fundamentals.Solid understanding of Windows 10, Windows 11, Windows Server, endpoint security management, and Microsoft enterprise productivity environments.Ability to evaluate technologies, identify security risks, and recommend practical mitigation strategies.Ability to produce clear technical documentation, procedures, reports, security findings, and recommendations for both technical and non-technical audiences.Proactive self-starter able to manage multiple priorities while maintaining a stewarding heart and team-oriented attitude.Experience working in a fast-paced environment with multiple concurrent projects and initiatives.Effective interpersonal skills with the ability to interact effectively with technical, non-technical, support, and business stakeholders at all levels.Strong oral and written communication skills.Sound working knowledge of LAN/WAN topologies and architecture. Multi-site WAN experience required; Meraki experience preferred.Ability to build effective working relationships with customers, co-workers, leadership, vendors, and business stakeholders while maintaining a strong customer service orientation.

    Minimum Qualifications:

    Bachelor's degree in information security, Computer Science, Information Systems, or a related field; equivalent experience considered.Minimum 4 years of experience in cybersecurity, security operations, incident response, vulnerability management, threat hunting, or related information security functions.Experience supporting Microsoft cloud and security technologies including Microsoft 365, Azure, Entra ID, Defender, Sentinel, Intune, Conditional Access, MDM, or related security platforms.Experience investigating security events and incidents, including documentation of findings, remediation activities, and incident response actions.Experience supporting enterprise security technologies and security monitoring activities

    Embodies and serves as a role model of ArchWell Health's Values:

    Be compassionateStrive for excellenceEarn trustShow respectStay resilientAlways do the right thing

    Preferred Qualifications:

    Experience supporting healthcare, regulated, or highly compliant environments.Familiarity with HIPAA, NIST Cybersecurity Framework, CIS Controls, HITRUST, or similar security and compliance frameworks.Experience conducting proactive threat hunting activities using SIEM, EDR/XDR, threat intelligence, and endpoint telemetry.Experience with Microsoft Defender XDR, Defender for Cloud, Sentinel automation, advanced hunting, KQL, and security orchestration capabilities.Experience with SIEM, EDR/XDR, vulnerability management, identity protection, cloud security, and security monitoring platforms.Security certifications such as Security+, SC-200, SC-300, AZ-500, CySA+, CISSP, GCIH, or equivalent.

    About ArchWell Health:

    At ArchWell Health, we're creating a community of caring designed to help our members stay healthy and engaged. By focusing on a strong provider-patient relationship, routine wellness, and staying active, our members enjoy a higher level of care and better quality of life after the age of 60. Everything we do is for seniors. We believe seniors should be heard, listened to, and given ample time by their physicians to live well later in life.Our value-based care model is designed to prevent illnesses while keeping members healthy and happy in every aspect of their life. We deliver best-in-class primary care at comfortable, accessible neighborhood centers where older adults can feel at home and become part of a vibrant, wellness-focused community. We're passionate about caring for older adults and united by the belief that caring has the power to change everything for our members.

    ArchWell Health is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to their race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected classification.

    Numbers & Facts

    LocationNashville, TN

    Skills

    • Access Controlunmatched
    • Analysis Skillsunmatched
    • Applications Securityunmatched
    • Authenticationunmatched
    • Automationunmatched
    • Business Supportunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Campaignsunmatched
    • Change Managementunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Content Developmentunmatched
    • Corrective Actionunmatched
    • Cross-Functionalunmatched
    • Cryptographyunmatched
    • Customer Relationsunmatched
    • Customer Support/Serviceunmatched
    • DHCP (Dynamic Host Configuration Protocol)unmatched
    • DNS (Domain Name System)unmatched
    • Documentationunmatched
    • Email Securityunmatched
    • Endpoint Securityunmatched
    • Enterprise Protectionunmatched
    • Firewallsunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • Healthcareunmatched
    • Huntingunmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Interpersonal Skillsunmatched
    • Leadershipunmatched
    • Local Area Network (LAN)unmatched
    • Maintain Complianceunmatched
    • Maintenance Servicesunmatched
    • Manufacturing Data Managementunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Operating Systemunmatched
    • Microsoft Windows Serverunmatched
    • Mobile Devicesunmatched
    • Multitaskingunmatched
    • Network Protocolsunmatched
    • Operational Improvementunmatched
    • Operational Supportunmatched
    • Operations Security (OPSEC)unmatched
    • Phishingunmatched
    • Presentation/Verbal Skillsunmatched
    • Primary Careunmatched
    • Quality of Careunmatched
    • Regulatory Complianceunmatched
    • Reporting Skillsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Service Level Agreement (SLA)unmatched
    • Systems Administration/Managementunmatched
    • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
    • Team Playerunmatched
    • Technical Supportunmatched
    • Technical Writingunmatched
    • Telemetryunmatched
    • Topologyunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Wide Area Network (WAN)unmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder