Senior Security Operations Analyst

Penn Medicine
Philadelphia, PA, United States
27 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
0 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Information Systems Kali Linux Nmap PCI Data Security Standards Phishing Wireshark Software Vulnerability Management Cyber Threat Analysis Information Technology

Job description

Working under limited supervision, the Senior Information Security Analyst is responsible for ensuring that key security operations tasks are completed. Security Operations involves end user security service escalation, security incident response, data forensics, technical research, threat intelligence, vulnerability management, and supporting other Information Security initiatives as necessary. The analyst performs security incident response, understands threats and vulnerabilities affecting information systems, and participates in risk assessment, management, and remediation., * Monitoring security incident and event management systems, along with responding to alerts and notifications as appropriate

  • Initiate escalation procedures to counteract potential threats and/or vulnerabilities.
  • Investigation of suspicious network and endpoint activity
  • Support end-user security issues including phishing, encryption, infected computer systems and more
  • Partners with information security engineers to implement and maintain security technologies
  • Collaborates with information assurance advisors to address network and endpoint security risks
  • Participates in vulnerability management, including scanning and remediation
  • Prepare system security reports by collecting, analyzing and summarizing data trends

Requirements

  • Bachelor of Arts or Science (Required)
  • And 5+ years Experience in information technologies, especially information security, such as security operations and incident response, regulatory compliance or audit, vulnerability management, security engineering or similar experience (Required)
  • And 0-1 years Familiarity with security standards and frameworks such as: HIPAA, PCI DSS, HITRUST, NIST, ISO, etc. (Required)
  • And 0-1 years Experience with penetration testing tools, such as Kali Linux, Responder, NMAP, Wireshark, Aircrack-ng, Maltego, Nikto, etc. (Required)
  • And 0-1 years Experience in healthcare and academia (Preferred)
  • And 0-1 years Information security certifications, such as Security+, Network+, CCNA Security, GSEC, GCIA, GCFA, GPEN, CEH (Preferred)

About the company

Penn Medicine is dedicated to our tripartite mission of providing the highest level of care to patients, conducting innovative research, and educating future leaders in the field of medicine. Working for this leading academic medical center means collaboration with top clinical, technical and business professionals across all disciplines.

Today at Penn Medicine, someone will make a breakthrough. Someone will heal a heart, deliver hopeful news, and give comfort and reassurance. Our employees shape our future each day. Are you living your life’s work?

  • Entity: Corporate, We believe that the best care for our patients starts with the best care for our employees. Our employee benefits programs help our employees get healthy and stay healthy. We offer a comprehensive compensation and benefits program that includes one of the finest prepaid tuition assistance programs in the region. Penn Medicine employees are actively engaged and committed to our mission. Together we will continue to make medical advances that help people live longer, healthier lives.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · World Congress 2026 Europe

Videos

See all

Related articles

See all