Role OverviewThe IT Security Analyst is a member of the IT Security Operations team who works closely with other members of the team to deliver a comprehensive information security program and safeguards Shirley Ryan AbilityLab's valuable information assets. The analyst works with other IT teams to effectively manage, monitor, and deploy technical controls to meet specific security requirements and follows defined processes and standards to ensure that security configurations are enforced and maintained.
What You Will Do
Performs administration relevant to security operations for all on-premises, hosted, and cloud infrastructure, storage, applications, systems, and networks. Performs continuous monitoring of security solutions, identifies security incidents, collaborates with internal and external teams to execute incident response procedures, and provides guidance to internal teams to recover from such incidents.
Why It Might Be a Fit
The IT Security Analyst will demonstrate Shirley Ryan AbilityLab Core Attributes (Communication, Accountability, Flexibility/Adaptability, Judgment/Problem Solving, Customer Service) and Core Values (Hope, Compassion, Discovery, Collaboration, and Commitment to Excellence) while fulfilling job duties.
Requirements
- A minimum of five (5) years progressive experience working in Information Technology with at least three (3) years of direct experience in systems security administration, systems audit, or security compliance.
- Robust and hands-on experience with various security solutions, including antivirus, Security Incident and Event Management (SIEM), encryption, endpoint detection and response, data loss prevention (DLP), intrusion detection & prevention, systems patching, vulnerability management, and threat intelligence.
- Advanced knowledge and understanding of security configurations and monitoring for Microsoft Active Directory Domain Services, Windows and Linux OS, AWS/Azure cloud, logging and monitoring, user access, perimeter protection principles, network communication protocols, etc.
- Must understand information security concepts, protocols, industry best practices and strategies. Knowledge of industry regulatory requirements and experience working with internal and external security audit staff as well as remediation practices is required.
- High degree of initiative and commitment to ongoing and continuous security improvements, a professional demeanor and collaborative spirit to execute projects and complete tasks proficiently.
- Effective communication and meticulous documentation skills required with a strong ability to develop and present comprehensive security reports to different audiences.
- Familiarity and knowledge of core security frameworks: HIPAA (Healthcare Insurance Portability and Accountability Act), NIST (National Institute of Standards and Technology), HITRUST (Health Information Trust Alliance), ISO 27000 Series (International Organization of Standardization), etc.
- Healthcare environment experience and IT security certifications are a plus.
- Familiarity with the Secure Software Development Lifecycle, Developing code or scripts to grow integration, automation and orchestration capacity, Cloud application security or a strong understanding of the OWASP Top 10, API Governance, integration and behavior monitoring, AI Governance, Risk and Compliance, Skillful in delivery of superior customer service.
- General understanding of Cerner and Financial Systems and their integration a plus.
- Ability to transport and move PCs, printers, and related hardware weighing up to 30 pounds.
Benefits
- Comprehensive benefits program
- Competitive pay
- Paid time off
- Health insurance
- Retirement plan
- Learning budget
- Parental leave
- Wellness programs
- Visa/relocation assistance
- Remote flexibility
- Stipends
- Bonus/commission
- Paid holidays
]]>