Jobs · Information Technology · Illinois

Lead IT Security Analyst

Shirley Ryan AbilityLab · Chicago, IL · Yesterday
Information TechnologyFull-time

About the role

The Lead IT Security Analyst administers IT and OT systems relevant to security operations for all on-premises, hosted, and cloud infrastructure, storage, applications, systems, and networks. Cultivates knowledge of organizational policy and standards as they pertain to security and works to ensure that security operations are rooted in and aligned with policy, as well as promoting awareness of and adherence to policy among their own team and others. Where gaps in policy and standards are identified, the lead security analyst drafts proposed additions based on industry frameworks and best practices.

Responsibilities

  • Performs continuous monitoring of security solutions including but not limited to antivirus, encryption, endpoint detection and response, Security Incident and Event Management (SIEM), privileged access management, vulnerability management, threat intelligence, data loss prevention (DLP), and intrusion detection & prevention. Where gaps in detection or response capabilities are identified, the lead security analyst researches, evaluates, deploys or develops, and operationalizes new technologies to address them.
  • Identifies security incidents in the course of monitoring; collaborates with internal and external teams to execute incident response procedures related to containment and eradication; and provides guidance to internal teams to recover from such incidents.
  • Provides emergency, after-hours and weekend support on a rotational basis to respond to priority issues that occur outside of the normal business hours.
  • Executes and proposes improvements to detailed and accurate documentation and procedures related to operational security practices and processes. Ensures users, service delivery and systems will adhere to documented standards. Where gaps in process are identified, the lead security analyst develops, implements, and trains team members on new solutions.
  • Takes a leading role in conducting security awareness training and phishing simulations, and remains informed on industry trends and threat intelligence to ensure the organization is prepared to confront relevant threats.
  • Provides direction to and collaborates with other teams regarding strategic and tactical operational security initiatives relating to identity and access management. Works closely with team members from IT, other business units, and vendors to ensure new systems, applications, subscriptions, services, and processes meet secure configuration and vulnerability management requirements.
  • Evaluates vendor security assessments, coordinates periodic internal and external security audits and assists in the development and implementation of post-audit mitigation plans.
  • Builds formal and informal relationships within SRAlab and among business partners and customers to improve the effectiveness of IT Security Operations. Collaborates with all IT teams and promotes ongoing and continuous security improvements, and serves as a primary point of contact for security concerns.
  • Performs all other duties that may be assigned in the best interest of the Shirley Ryan AbilityLab.

Reporting Relationships

Reports to Manager of IT Security Operations.

Qualifications

  • A minimum of seven (7) years progressive experience working in Information Technology with at least five (5) years of direct experience in systems security administration, systems audit, or security compliance.
  • Knowledge of security for operational technology a plus.
  • Robust and hands-on experience administering various security solutions, including antivirus, Security Incident and Event Management (SIEM), encryption, endpoint detection and response, data loss prevention (DLP), intrusion detection & prevention, systems patching, vulnerability management, and threat intelligence.
  • Advanced knowledge and understanding of security configurations and monitoring for Microsoft directory services (on-premise and cloud); Windows, Mac, and Linux OS; logging and monitoring; user access management; principles of perimeter-based and zero-trust architecture; network communication protocols; etc.
  • Must understand information security concepts, protocols, industry best practices and strategies.
  • Knowledge of industry regulatory requirements and experience working with internal and external security audit staff as well as remediation practices is required.
  • High degree of initiative and commitment to ongoing and continuous security improvements, a professional demeanor and collaborative spirit to execute projects and complete tasks proficiently.
  • Effective communication and meticulous documentation skills required with a strong ability to develop and present comprehensive security reports to different audiences.
  • Familiarity and knowledge of core security frameworks: HIPAA (Healthcare Insurance Portability and Accountability Act), NIST (National Institute of Standards and Technology), HITRUST (Health Information Trust Alliance), ISO 27000 Series (International Organization of Standardization), etc.
  • Active CISSP certification and maintenance required. Additional healthcare environment experience and IT security certifications are a plus.
  • Skillful in delivery of superior customer service.
  • General understanding of Cerner and Financial Systems and their integration a plus.
  • Ability to transport and move PCs, printers, and related hardware weighing up to 30 pounds.

Working Conditions

  • Normal office environment with little or no exposure to dust or extreme temperature.
  • Remote work within Chicagoland area.

Similar jobs