> Markdown version of [/jobs/ext/623475-security-analyst](https://www.wearedevelopers.com/jobs/ext/623475-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** Metro Vein Centers - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $75,000.0 - $85,000.0 - **Contract:** Permanent contract - **Skills:** Audit Trail, BigQuery, Health Informatics, Cloud Computing Security, Cyber Security, Disaster Recovery, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Multi-Factor Authentication, Email Filtering, Identity and Access Management, Microsoft Security Essentials, OAuth, Role-Based Access Control, Phishing, Zero Trust Network Access, Security Information and Event Management, User Provisioning Software, Enterprise Software Applications, Microsoft InTune, Azure Security Center, Sender Policy Framework (SPF), Gsuite, CIS Benchmarks - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=24551b0ef6a25560 ## About the Role Do you have experience in Security audits?, * 3-5 years of experience in an information security, security analyst, or IT security operations role * Hands-on experience administering Google Workspace security features (admin console, audit logs, DLP, OAuth app controls) * Experience with endpoint security platforms; CrowdStrike Falcon preferred, Microsoft Defender for Endpoint also considered * Familiarity with Microsoft security products including Intune, Microsoft Defender, and Entra ID * Solid understanding of identity and access management concepts: SSO, MFA, RBAC, least privilege * Experience conducting access reviews, user provisioning audits, and policy enforcement * Working knowledge of email security protocols (SPF, DKIM, DMARC) and email threat landscape * Strong analytical skills with the ability to investigate alerts and identify indicators of compromise * Excellent written and verbal communication skills; ability to explain security concepts to non-technical users * Familiarity with HIPAA Security Rule requirements and healthcare data protection obligations Preferred Skills * CrowdStrike certification (CCFA, CCFH, or equivalent) preferred * Microsoft security certifications (SC-200, MS-500, or equivalent) a strong plus * Experience with Zscaler ZIA security policy management or cloud-native security platforms * Familiarity with SIEM platforms and log management tools * Experience running security awareness programs and phishing simulations (KnowBe4, Proofpoint, or similar) * Prior experience in healthcare IT security or compliance roles * Knowledge of NIST CSF or CIS Controls frameworks ## Description Metro Vein Centers is hiring a Security Analyst to own and mature our information security program across a 70+ clinic, cloud-first healthcare environment. This is a newly created role that reflects our commitment to proactive security, HIPAA compliance, and a zero trust approach to identity and access management. You will be responsible for day-to-day security operations, including alert monitoring, access reviews, endpoint security, email security, MDM policy enforcement, MFA administration, phishing simulation programs, and more. The ideal candidate is both technically proficient and operationally focused, with the ability to drive security initiatives while partnering with clinical and corporate teams. What You'll Do * Monitor security alerts and events across the environment; investigate, triage, and respond to incidents in a timely manner * Administer and maintain Google Workspace security controls, including DLP policies, Gmail security settings, Drive sharing policies, and audit log review * Manage endpoint detection and response operations * Oversee device compliance policies, conditional access rules, and endpoint security baselines * Administer and enforce MFA policies and password complexity standards across all user populations * Conduct quarterly role-based access audits across critical systems including Athena, Luma, Google Workspace, and BigQuery * Own and maintain least-privilege access model across enterprise applications and identity platforms * Manage email security controls including phishing protection, spam filtering, and DMARC/DKIM configuration * Design and execute phishing simulation campaigns; deliver user security awareness training * Support HIPAA security compliance, including contributing to risk assessments, policy updates, and audit readiness * Assist with identity and access management (IAM) administration, including SSO, Google Identity * Collaborate with the network team on ZTNA policy enforcement and Zscaler security configurations * Contribute to incident response plans, disaster recovery documentation, and security runbooks * Track and report on key security KPIs including MFA adoption, device compliance rates, open vulnerabilities, and audit findings * Other related security duties as assigned * Occasional travel for critical issues or growth * Being on call rotation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Making Data Warehouses fast. A developer's story.](https://www.wearedevelopers.com/videos/302-making-data-warehouses-fast-a-developer-s-story) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)