Security Analyst

Egis Systems, LLC
  • Brentwood, TN
  • Full-time
13 days ago

Job Description

Job Summary Fortified Health Security is seeking a hands-on Information Security Analyst to support a healthcare client through a full-time, staff augmentation engagement. This Security Analyst will work directly with the client's technology and operations teams as well as Fortified's vCISO and EOD team to assist with a variety of technical security tasks--focusing on email security, endpoint protection, firewall administration, and user access governance. This role involves day-to-day operational support and project work across several security platforms and tools. Client-Specific Responsibilities The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required. · Email & Messaging Security: Understand O365 environment; knowledge of Abnormal (or other email security tools), and Exchange routing. Assist with email spoofing/spam reviews and graymail analysis. · Phishing Defense: Conduct second-pass reviews via Abnormal or KnowBe4 PhishER. · Endpoint Security: Knowledge of SentinelOne other endpoint security tools. Address endpoint alerts and incident response. · Firewall Rule Review and Recommendations: Review N/S and E/W rules using Palo Alto and server-to-web or rule-based filtering. · MFA/SSO: Understanding of various MFA tools and Entra SSO scenarios as needed. · Policy & Procedure Support: Contribute to documentation and configuration standards for tools in use. · Incident Handling: Triage detections escalated from the SOC or abnormal activity in O365 or other security platforms. Investigate security breaches and other cybersecurity incidents. · Help standardize control operations across cloud (M365), endpoint, and perimeter defense systems. · Collaborate with Client's teams, Client's third parties, and Fortified departments, to ensure a holistic approach to cybersecurity. Essential Job Functions The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required. · Have an understanding of healthcare business operations, the healthcare cybersecurity landscape, and the healthcare regulatory environment. · Collaborate with Fortified's vCISO to mature the client's security posture and close documented gaps. · Assist vCISO in the identification and proposal of key information security priorities, initiatives, plans, practices, and tools. · Research potential and emerging information security threats, vulnerabilities, and potential control techniques and communicate this information to vCISO. · Develop necessary policies / procedures / processes pertaining to Cybersecurity Risk Management. · Install security measures and operate software to protect systems and information infrastructure · Develop security policies, procedures, standards, and runbooks. · Document security incidents/breaches and assess the damage they cause. · Work with the Client's teams to perform tests and uncover vulnerabilities. · Develop company-wide best practices for IT security. · Document and communicate recurring patterns or systemic issues requiring escalation or strategic remediation. · Help clients install security software and understand information security management. · Research security enhancements and make recommendations to vCISOs/client leadership. · Stay current on evolving cybersecurity threats and how they impact email, endpoint, and identity systems. · Analyzing security incidents/breaches to identify the root cause. · Verifying the security of third-party vendors and collaborating with them to meet security requirements. · Ability to multitask and prioritize daily workload. · Resourcefulness and ability to take the initiative in development and completion of work projects. Knowledge & Skills Education & Experience · 3+ years in IT or information security in a hospital environment · Bachelor's degree from a four-year college or university or combination of education and experience. · Working knowledge of: o Microsoft 365 (O365), Exchange hybrid environments o Palo Alto firewalls other next gen firewall o Endpoint Detection and Response (EDR) tools such as SentinelOne o Web gateways and DLP tools o MFA solutions (DUO, Entra SSO) · Strong understanding of network security concepts, firewalls, intrusion detection/prevention systems (IDS/IPS), MFA, Asset Management, DLP, Application Control, etc. · Experience with SIEM tools and security information and event management (SIEM) principles. · Experience with cloud security concepts (AWS, Azure, GCP). · Scripting experience (PowerShell or Python) is a plus but not required. · Three years or more general network (WAN) experience a plus. Special Skills & Knowledge · Demonstrate strong problem-solving skills and a desire to learn; be a self-starter with a can-do attitude; excellent customer relationships skills; excellent communication skills; ability to handle sensitive information; good verbal and written skills, team player. · Analytical mindset, and critical thinking abilities; data driven. · Self-motivated individual capable of working in a fast-paced, dynamic environment. · Detail and results oriented, skilled at both planning and hands-on execution. · Ability to excel in a team-oriented, collaborative, and fast-paced environment. · Excellent written, verbal, and presentation skills. · Working knowledge concerning all network technology including LAN, WAN concepts, wireless technology, and VOIP concepts a plus. · Troubleshooting skills. · Must have strong analytical and problem-solving skills, as well as excellent interpersonal and communication skills and abilities. · Ability to effectively communicate with a wide range of individuals and constituencies in a diverse healthcare setting. Licenses, Certifications, etc. · One or more of the following certifications are preferred: Security+, CISSP, any GIAC or cloud security certification Requirements Supervisory Responsibility · N/A Working Conditions & Travel Requirements · Minimal travel as needed. · Pacific Time working hours Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.

Numbers & Facts

LocationBrentwood, TN
Job TypeFull-time

Skills

  • Amazon Web Services (AWS)unmatched
  • Americans with Disabilities Act (ADA)unmatched
  • Analysis Skillsunmatched
  • Asset Managementunmatched
  • Best Practicesunmatched
  • Business Operationsunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Securityunmatched
  • Customer Relationsunmatched
  • Customer Support/Serviceunmatched
  • Detail Orientedunmatched
  • Documentation Standardsunmatched
  • Email Securityunmatched
  • Email Spoofingunmatched
  • Endpoint Securityunmatched
  • Establish Prioritiesunmatched
  • Firewall Administrationunmatched
  • Firewallsunmatched
  • GCP (Good Clinical Practices)unmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • Healthcareunmatched
  • Hospitalunmatched
  • Identify Issuesunmatched
  • Incident Managementunmatched
  • Incident Responseunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Interpersonal Skillsunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Detection and Prevention (IDP)unmatched
  • Intrusion Prevention Systemsunmatched
  • Leadershipunmatched
  • Local Area Network (LAN)unmatched
  • Microsoft Exchange Serverunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • Multiplatform/Cross-Platformunmatched
  • Multitaskingunmatched
  • Network Securityunmatched
  • Operational Supportunmatched
  • Phishingunmatched
  • Policy Developmentunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Procedure Developmentunmatched
  • Python Programming/Scripting Languageunmatched
  • Regulationsunmatched
  • Risk Managementunmatched
  • Root Cause Analysisunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Security Softwareunmatched
  • Single Sign-On (SSO)unmatched
  • Software Installationunmatched
  • Systems Analysisunmatched
  • Team Playerunmatched
  • Technical Operationsunmatched
  • Testingunmatched
  • VoIP (Voice over IP)unmatched
  • Wide Area Network (WAN)unmatched
  • Willing to Travelunmatched
  • Windows PowerShellunmatched
  • Wireless Communicationsunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder