Security Analyst

Egis Systems, LLC
Brentwood, TN, United States
17 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Application Firewall Microsoft Azure VoIP Cloud Computing Security Cyber Security Identity and Access Management Information Security Management Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language)
+14 more
Network Security Windows PowerShell Phishing Runbook Security Software Security Information and Event Management Scripting Google Cloud Computer Network Technologies Office365 Firewalls (Computer Science) Information Technology Wireless Technologies SentinelOne Expertise

Job description

Job Summary Fortified Health Security is seeking a hands-on Information Security Analyst to support a healthcare client through a full-time, staff augmentation engagement. This Security Analyst will work directly with the client’s technology and operations teams as well as Fortified’s vCISO and EOD team to assist with a variety of technical security tasks–focusing on email security, endpoint protection, firewall administration, and user access governance. This role involves day-to-day operational support and project work across several security platforms and tools. Client-Specific Responsibilities The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required. · Email & Messaging Security: Understand O365 environment; knowledge of Abnormal (or other email security tools), and Exchange routing. Assist with email spoofing/spam reviews and graymail analysis. · Phishing Defense: Conduct second-pass reviews via Abnormal or KnowBe4 PhishER. · Endpoint Security: Knowledge of SentinelOne other endpoint security tools. Address endpoint alerts and incident response. · Firewall Rule Review and Recommendations: Review N/S and E/W rules using Palo Alto and server-to-web or rule-based filtering. · MFA/SSO: Understanding of various MFA tools and Entra SSO scenarios as needed. · Policy & Procedure Support: Contribute to documentation and configuration standards for tools in use. · Incident Handling: Triage detections escalated from the SOC or abnormal activity in O365 or other security platforms. Investigate security breaches and other cybersecurity incidents. · Help standardize control operations across cloud (M365), endpoint, and perimeter defense systems. · Collaborate with Client’s teams, Client’s third parties, and Fortified departments, to ensure a holistic approach to cybersecurity. Essential Job Functions The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required. · Have an understanding of healthcare business operations, the healthcare cybersecurity landscape, and the healthcare regulatory environment. · Collaborate with Fortified’s vCISO to mature the client’s security posture and close documented gaps. · Assist vCISO in the identification and proposal of key information security priorities, initiatives, plans, practices, and tools. · Research potential and emerging information security threats, vulnerabilities, and potential control techniques and communicate this information to vCISO. · Develop necessary policies / procedures / processes pertaining to Cybersecurity Risk Management. · Install security measures and operate software

Requirements

to protect systems and information infrastructure · Develop security policies, procedures, standards, and runbooks. · Document security incidents/breaches and assess the damage they cause. · Work with the Client’s teams to perform tests and uncover vulnerabilities. · Develop company-wide best practices for IT security. · Document and communicate recurring patterns or systemic issues requiring escalation or strategic remediation. · Help clients install security software and understand information security management. · Research security enhancements and make recommendations to vCISOs/client leadership. · Stay current on evolving cybersecurity threats and how they impact email, endpoint, and identity systems. · Analyzing security incidents/breaches to identify the root cause. · Verifying the security of third-party vendors and collaborating with them to meet security requirements. · Ability to multitask and prioritize daily workload. · Resourcefulness and ability to take the initiative in development and completion of work projects. Knowledge & Skills Education & Experience · 3+ years in IT or information security in a hospital environment · Bachelor’s degree from a four-year college or university or combination of education and experience. · Working knowledge of: o Microsoft 365 (O365), Exchange hybrid environments o Palo Alto firewalls other next gen firewall o Endpoint Detection and Response (EDR) tools such as SentinelOne o Web gateways and DLP tools o MFA solutions (DUO, Entra SSO) · Strong understanding of network security concepts, firewalls, intrusion detection/prevention systems (IDS/IPS), MFA, Asset Management, DLP, Application Control, etc. · Experience with SIEM tools and security information and event management (SIEM) principles. · Experience with cloud security concepts (AWS, Azure, GCP). · Scripting experience (PowerShell or Python) is a plus but not required. · Three years or more general network (WAN) experience a plus. Special Skills & Knowledge · Demonstrate strong problem-solving skills and a desire to learn; be a self-starter with a can-do attitude; excellent customer relationships skills; excellent communication skills; ability to handle sensitive information; good verbal and written skills, team player. · Analytical mindset, and critical thinking abilities; data driven. · Self-motivated individual capable of working in a fast-paced, dynamic environment. · Detail and results oriented, skilled at both planning and hands-on execution. · Ability to excel in a team-oriented, collaborative, and fast-paced environment. · Excellent written, verbal, and presentation skills. · Working knowledge concerning all network technology including LAN, WAN concepts, wireless technology, and VOIP concepts a plus. · Troubleshooting skills. · Must have strong analytical and problem-solving skills, as well as excellent interpersonal and communication skills and abilities. · Ability to effectively communicate with a wide range of individuals and constituencies in a diverse healthcare setting. Licenses, Certifications, etc. · One or more of the following certifications are preferred: Security+, CISSP, any GIAC or cloud security certification Requirements Supervisory Responsibility · N/A Working Conditions & Travel Requirements · Minimal travel as needed. · Pacific Time working hours Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all