Senior Security Analyst
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Analyst based in the United States.
This role is responsible for protecting sensitive information systems, technology assets, and healthcare data across a distributed environment. You will play a key role in strengthening cybersecurity operations while ensuring alignment with healthcare regulations and industry standards. The position combines security monitoring, incident response, vulnerability management, risk assessment, compliance, and identity and access management. You will collaborate closely with IT, infrastructure, application, compliance, legal, and external teams to identify and address security risks. As a senior member of the security function, you will help improve processes, tooling, controls, and incident response capabilities while mentoring junior analysts. This is an opportunity to contribute to a mission-driven environment where protecting sensitive patient information has a direct and meaningful impact.
Accountabilities:
- Monitor and analyze security events and alerts across networks, endpoints, cloud platforms, and applications.
- Investigate suspicious activity and lead incident response activities, including triage, containment, eradication, and recovery.
- Serve as an escalation point for complex security incidents and coordinate cross-functional response efforts.
- Maintain and optimize SIEM, EDR, and other security tools to improve detection capabilities and reduce false positives.
- Conduct root cause analysis and document incidents, remediation activities, and lessons learned.
- Ensure security practices align with HIPAA, HITECH, and other applicable healthcare privacy and regulatory requirements.
- Participate in security risk assessments, gap analyses, internal and external audits, and third-party assessments.
- Develop and maintain security policies, standards, and procedures aligned with regulatory and industry expectations.
- Monitor controls designed to protect PHI, manage data access, and prevent security breaches.
- Support audit readiness and remediation of compliance findings.
- Conduct vulnerability scans and coordinate remediation with infrastructure and application teams.
- Prioritize vulnerabilities based on business impact, exploitability, and regulatory exposure, and track progress toward risk reduction.
- Perform risk assessments for new systems, vendors, and technology implementations.
- Contribute to third-party risk management and vendor security reviews.
- Collaborate with infrastructure and application teams on secure configurations, security controls, and system implementations.
- Evaluate and recommend security technologies and solutions that strengthen the organization's protection capabilities.
- Support secure design reviews for applications, systems, and integrations and validate security controls across network, endpoint, and cloud environments.
- Review and monitor access to systems containing PHI and sensitive information, supporting provisioning, deprovisioning, and periodic access reviews.
- Investigate access anomalies and promote least-privilege access principles.
- Support security awareness and training initiatives focused on healthcare threats such as phishing and ransomware.
- Advise IT and business teams on security best practices and risk mitigation.
- Identify opportunities to improve security processes, tools, monitoring, and response capabilities.
- Mentor junior security analysts and contribute to the growth and development of the security function.
Requirements:
- Bachelor's degree in Cybersecurity, Information Technology, or a related field preferred; equivalent professional experience may be considered.
- 5+ years of experience in cybersecurity, information security, or a related field.
- At least 2 years of experience in healthcare IT, cybersecurity, or another regulated env
This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels βGet remote analyst jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks β continue to the application β