> Markdown version of [/jobs/ext/2848703-consulting-security-analyst](https://www.wearedevelopers.com/jobs/ext/2848703-consulting-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Consulting Security Analyst - **Company:** HCA Healthcare Inc. - **Location:** Louisville, KY, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Communications Protocols, Cyber Security, Information Leak Prevention, Data Loss, Disaster Recovery, Network Security, Performance Tuning, Remote Infrastructure Management, Systems Architecture, Software Vulnerability Management, Cyber Threat Analysis, Information Technology, Hardware Infrastructure, Cyber Warfare - **Published:** September 11, 2026 - **Apply:** https://dejobs.org/x/x/139F4B77ECEA49D89F722A4D7D2B7686/job/ ## About the Role * Bachelors Degree and seven or more years of experience in a relevant field required * High School Graduate/Equivalent and 14+ years of experience in a relevant fieldRequired * Seven or more years experience in security, risk management, information security domains. infrastructure/security engineering ptrfrttrf * Master's Degree preferred Licenses, Certifications, & Training: * Advanced ISC(2), ISACA, GIAC, EC-Council, Offensive Security or other relevant certification types in information security, or cyber risk management preferred * Up to 25% travel Knowledge, Skills, Abilities, Behaviors: * Experience in developing and assessing technical and process-based controls, managing risk assessments/investigations, and working with organization management to integrate controls into the scope of existing business practices. Required * Working knowledge of information security concepts, including risk management, engineering, networking, and cloud. Required * Understanding of cloud fundamentals and concepts, as well as experience with a popular cloud provider, like Microsoft, Google, or Amazon. Required * Knowledge of information security regulations (FERPA, HIPAA Privacy/Security, SOX IT, PCI) Required * Experience in some combination of audit, risk management, information security, privacy, and information technology. Required * Knowledge of supported operating systems, utilities, vendor products, applicable communications protocols, and hardware configurations. Required * Experience supporting implementation, configuration, or tuning of technically complex infrastructure or security solutions across platforms and components. Required * Excellent written and oral skills. Required * Possesses the ability to build and maintain positive team relationships at all levels of the facility, market, and corporate levels. Required * Possesses a sense of responsibility and accountability and takes ownership and initiative. Required * Creative thinker, always looking for a "better way" to deliver value; not stopped or discouraged by adversity. Required * Demonstrates respect for diversity of experience, characteristics, viewpoints, and opinions. Required * Maintains professional demeanor, appearance, and positive attitude. Required * Adaptable and flexible, with the ability to handle ambiguity and sometimes changing priorities. Required ## Description Consulting Security Analysts are responsible for performing a wide range of tasks that support the ongoing maturation of the IPS program, including: driving consistency and visibility of IPS risk management activities; working with business owners to protect customers and prevent data loss; providing guidance and consultation to colleagues at every level to reduce or eliminate risky behaviors; and consult and support IT teams to implement, validate, and tune security controls in alignment with company standards. They are responsible for helping workforce members appropriately comply with the company's IPS requirements while balancing customer care, business objectives, and technical realities. This role requires extensive focus on building and expanding relationships with key stakeholders who support IPS objectives and activities. IPS Consulting Security Analysts are tasked with complex work efforts, requiring them to leverage their IT, security, risk management, and business experience to address IPS program deficiencies while meeting customer care and business needs. This position blends cybersecurity consulting and risk management with system, infrastructure, and security engineering support to help business and IT teams reduce risk and improve control maturity. The IPS Consulting Security Analyst must have a combination of written and verbal communication skills, interpersonal skills, the ability to influence, guide, and/or lead others necessary to accomplish IPS goals, and the technical capability to assist IT teams with the implementation, configuration, and tuning of security controls. Risk Management and Security Consulting * Coordinate and perform risk assessments using corporate-provided tools and templates. * Work with local leaders to assess, submit and approve exceptions to IPS standards while working with them to implement controls to mitigate risk and remediate as able. * Drive and manage execution of corrective and risk treatment plans in concert with Cyber Issues Management to address deficiencies identified during risk assessments. * Assist the DISA in ensuring that designated committees (e.g., Security Committee, Ethics & Compliance Committee) receive, document, track, investigate, and sponsor remediation of security control deficiencies, suspected IPS incidents, and complaints. * At the direction of the DISA, provide education and guidance to ensure designated committees make informed, risk-based decisions necessary to balance business needs and security objectives. * Perform Security Risk Analysis (SRA) to validate that required security controls are in place to drive ongoing compliance with IPS policies, standards, and operational procedures. * Lead audit response activities to address IPS issues identified by internal or external auditors. * Serve as an internal security consultant across business units to provide technical security consultation on appropriate controls that balance business and security requirements. * Translate security standards and regulatory requirements into actionable technical and business requirements. * Evaluate and recommend security solutions that balance risk mitigation with business functionality. Security Engineering and Control Enablement * Work with Corporate IPS / Centralized Architect Team to identify appropriate security controls as part of the field intake process and provide assurance that the required security controls are implemented, configured, and working as designed. * Assist IT teams in the implementation, configuration, validation, and tuning of security controls. * Evaluate new and proposed security technologies and assist in their integration. * Assist in the design and implementation of secure network, application, and system architectures. * Partner with IT colleagues to assure ongoing maturity of IT operational security controls. * Partner with appropriate stakeholders on vulnerability remediation. * Lead and support the IPS program by assessing new applications and technologies and ensuring they are implemented in accordance with company standards. * Engage in Architecture Review Committee discussions to identify and address Third Party solution variance from company standards. * Provide hands-on support for corporate-driven security efforts, as appropriate. * Participate in the development, documentation, and testing of Disaster Recovery (DR) and contingency plans. Issues Tracking and Resolution * Support, coordinate, and manage non-technical cyber security event/incident response investigation activities (i.e., Lost/Stolen Devices, Privacy RI, E&C). * Investigate information leaving the organization with appropriate leadership (i.e. Manager, ECO, HR, Legal) in support of Data Loss Prevention (DLP). * Coordinate with HR Director, Facility Privacy Official and Ethics & Compliance Officer to ensure that sanctions related to IPS issues are applied appropriately and consistently. * Perform follow-up education and consultation with workforce members exhibiting risky behaviors and/or behaviors that violate Company IPS policies and standards. * Partner with corporate and local departments as required to facilitate rapid response to cybersecurity events and determine appropriate technical mitigations as necessary. * Coordinate Cyber Defense Center (CDC), MSSP, and Cyber Problem Effort and Resiliency (CPER) response efforts and report on progress. * Augment IT response capabilities by providing hands-on technical support and remediation guidance, where appropriate. * Manage operational processes that monitor and respond to potential security threats. Execution * Provide ad hoc IPS guidance and consultation to all types and levels of workforce members and colleagues that balances business and security requirements. * Educate ITG colleagues on security policies and standards to help ensure compliance. * Facilitate, and lead where appropriate, proactive IPS communication and awareness activities including coordinating with HR and training departments to ensure that periodic workforce training includes company-required IPS content. * Coordinate development, documentation and testing of Disaster Recovery (DR) plans. * Assist the Division DISA in supporting and driving enterprise and division IPS projects and security efforts to a successful end and ensure that required processes are adopted and maintained. * Lead and coordinate implementation and adoption of technology and process changes. * Maintain awareness of emerging threats, vulnerabilities, and mitigation techniques. * Drive targeted security risk reduction within IT. Vendor Systems Security * Collaborates with system business owners to ensure vendor contracts are in place for department and IT systems and services. * Work with appropriate business, IT, supply chain, and corporate IPS stakeholders to help ensure specific systems, services, and devices receive proper security assessments and remediation. * Work with business, purchasing, and IT stakeholders to ensure proper controls are in place for existing vendor-maintained solutions. * Support IT, system business owners, and vendors to document system vulnerabilities and document mitigation controls or remediation actions. * Support IT to ensure vendor systems use approved connectivity, remote management and monitoring. * Support IT to remediate security vulnerabilities in response to vendor security events. * Performs other duties as assigned * Practices and adheres to the "Code of Conduct" philosophy and "Mission and Value Statement." ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland)