> Markdown version of [/jobs/ext/612352-security-analyst](https://www.wearedevelopers.com/jobs/ext/612352-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** Charter Communications, Inc. - **Location:** Orchard Park, NY, United States - **Experience:** Experienced - **Salary:** $68,000.0 - $85,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, JIRA, Microsoft Azure, BASIC (Programming Language), Health Informatics, Cloud Computing, Cloud Computing Security, Cyber Security, Data Loss, Linux, Domain Name System (DNS), Identity and Access Management, Issue Tracking Systems, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Network Security, Network Troubleshooting, Log Analysis, Routing, Phishing, Security Information and Event Management, TCP/IP, Software Vulnerability Management, Data Logging, Google Cloud, QRadar, Electronic Medical Records, Firewalls (Computer Science), Azure Security Center, Falcon Platform, Information Technology, Cybercrime, Microsoft Sentinel, CIS Benchmarks, Splunk, SentinelOne Expertise, Servicenow, Vulnerability Analysis - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a8b94bb4ec37d8cf ## About the Role Do you have a valid Driver's License license?, Do you have experience in Windows?, Do you have a Bachelor's degree?, Spectrum Health & Human Services is seeking a detail-oriented Security Analyst to help protect our healthcare organization's systems, data, and patient information. This role is responsible for monitoring security events, investigating potential threats, supporting compliance initiatives, and helping maintain a strong cybersecurity posture across clinical, administrative, and technology environments. The ideal candidate understands cybersecurity fundamentals, healthcare data privacy requirements, and the importance of protecting sensitive patient information in accordance with HIPAA and other applicable regulations., * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent experience., * 3 - 5+ years of experience in cybersecurity, information security, IT risk, or security operations. * Familiarity with security tools such as SIEM, EDR/XDR, vulnerability scanners, firewalls, IDS/IPS, ethical hacking techniques, and ticketing systems. * 3- 5+ years of experience and understanding of cybersecurity concepts, including threat detection, incident response, vulnerability management, network security, and access control. * Knowledge of HIPAA, healthcare privacy/security requirements, or other regulated environments. * Strong analytical, troubleshooting, and documentation skills. * Ability to communicate security risks clearly to technical and non-technical stakeholders., * Experience working in a healthcare, clinical, and remote office environment. * Familiarity with frameworks such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or HITRUST. * Certifications such as Security+, CySA+, SSCP, GSEC, CEH, and similar. * Experience with cloud security concepts across AWS, Azure, or Google Cloud. * Experience supporting audits, risk assessments, or third-party vendor security reviews. * Familiarity with electronic health record systems, medical device security, or healthcare IT environments. OTHER: * Must possess a valid Driver's License with a satisfactory driving record ## Description * Monitor security alerts, logs, and events from systems such as SIEM, EDR, firewalls, email security, and vulnerability management tools. * Investigate and respond to potential security incidents, escalating issues as appropriate. * Support incident response activities, including documentation, evidence collection, root cause analysis, and remediation tracking. * Assist with vulnerability scanning, risk assessment, patch validation, and security control testing. * Help maintain compliance with HIPAA, HITECH, HITRUST, NIST, and internal security policies. * Review access controls and support identity and access management processes. * Partner with IT, compliance, legal, and clinical teams to identify and reduce security risks. * Assist in developing and maintaining security policies, procedures, standards, and awareness materials. * Support phishing investigations, security awareness campaigns, and user education efforts. * Prepare reports and metrics related to threats, vulnerabilities, incidents, and compliance activities. * Stay current on emerging cybersecurity threats, especially those affecting healthcare organizations. * Security monitoring and incident response tools: SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar; EDR/XDR tools such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or Carbon Black; IDS/IPS; SOAR workflows; and case management or ticketing systems such as ServiceNow or Jira. * Network and infrastructure security: firewalls, VPNs, secure web gateways, DNS filtering, email security gateways, vulnerability scanners, endpoint hardening, Active Directory, Windows and Linux systems, and basic TCP/IP, routing, and network troubleshooting. * Cloud and SaaS security: Azure, AWS, or Google Cloud security controls; Microsoft 365 security and compliance tools; identity providers; MFA; conditional access; cloud logging; and secure configuration reviews. * Healthcare security environment: HIPAA-regulated data, electronic health record platforms, clinical applications, medical device networks, third-party vendor access, and protection of protected health information across clinical and administrative workflows. * Hands-on security operations: alert triage, log analysis, phishing investigation, malware containment, account compromise investigation, vulnerability validation, threat hunting, evidence collection, and remediation follow-up. Core Competencies * Hands-on threat detection and alert triage using SIEM, EDR/XDR, firewall, identity, endpoint, email, and cloud logs. * Practical incident response experience, including containment, eradication, recovery coordination, root cause analysis, and post-incident documentation. * Ability to investigate phishing, malware, suspicious authentication activity, data loss indicators, endpoint anomalies, and network-based threats. * Working knowledge of vulnerability management, including scan review, risk prioritization, remediation tracking, patch validation, and exception documentation. * Strong understanding of identity and access controls, including Active Directory, role-based access, privileged access, MFA, conditional access, and access reviews. * Experience translating technical findings into clear risk statements, executive summaries, tickets, and remediation plans for IT, compliance, and clinical stakeholders. * Ability to work independently during investigations while collaborating with infrastructure, application, compliance, privacy, and vendor teams. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)