Overview
Skills
Job Details
Job Description
Here at the client, we are passionate about building and improving the community we live in. Devoted healthcare professionals and application specialists
The Opportunity:
The Office of Application and Technology Services (OATS) is seeking a highly motivated candidate for the role of Security Analyst for the client reporting to the Chief Information Security Officer. The Security
Required Experience
- Monitor network resources for
security issues. - Monitor a Security Information and Event
Management (SIEM)system to enhance the overall cybersecurity of CHFS: Data Collection, Event Correlations, Incident Detection, Investigation and Analysis, Response and Mitigation, Tuning and Optimization, Compliance Monitoring - Investigate security breaches
and other cybersecurity incidents. - Develop an audit to determine
whether information systems are protected, controlled, and provide value to the organization. - Conduct audit follow-up to evaluate whether
risks have been sufficiently addressed. - Install security measures and operate software to
protect systems and information infrastructure, including firewalls and data encryption programs. - Communicate audit progress,
findings, results, and recommendations to stakeholders. - Document security breaches and assess the damage they cause.
- Work with the security team to perform tests and uncover network vulnerabilities.
- Fix detected vulnerabilities
to maintain a high-security standard - Develop cabinet-wide best
practices for IT security. - Help colleagues install security software and understand information
security management. - Research security
enhancements and make recommendations to management. - Stay up to date on
information technology trends and security standards. - Maintain and update relevant
system and process documentation and develop ad- hoc reports as needed. - Assist in the development of security tool requirements, trials,
and evaluations, as well as security operations procedures and processes. - Provide off-hours support on
an infrequent, but as-needed basis. - Work trouble tickets in the ticketing
system - Conduct meetings and work
closely with system owners and departmental leads in all business areas where ePHI and other confidential system data is found. - Assist with continuous
monitoring activities documenting within the eGRC tool whether security and other related activities are consistently performed. - Perform various support
activities for other projects including obtaining information and documentation to demonstrate policies, procedures, and operational processes that adhere to various regulations, policies, standards, and other compliance requirements.
· Collaborate with
· Lead and coordinate
· Prepare reports for management.
Preferred Education &
Bachelor’s degree in computer
Candidates with one or more
· Offensive Security
· Offensive Security
· Cybersecurity
· CompTIA Security+
· CompTIA Advanced Security Practitioner (CASP+
· CompTIA Pen Test+
· Certified Network
· GIAC Security
· System Security Certified
This is a partial listing of
- Ability to set the tone for
the organization and motivate management and team. - Understanding of information
security regulations, including the Federal Information Security Management Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), ISO 27001, COBIT NIST, and ITIL. - Maintaining security,
assessing and evaluating security, and doing security incident forensic work. Knowledge of vendors and their products including: - Experience with Government
agencies, particularly the Department of Defense (DoD) on information security matters. Experience with Government Classified systems and the associated security requirements. - Updates job knowledge by tracking and understanding
emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; and participating in professional organizations. - Proficiency in Microsoft
Office Suite (Word, Excel, Outlook, etc.) - Innovative and creative
mindset - Basic network security
knowledge (general principles) - Excellent documentation and
communication skills. - Ability to organize tasks
into milestones and successfully execute to project completion. - Can work independently with
little direct supervision. - General cyber-security
understanding