Security Analyst - Advisory
Fortified Health Security · Exton, PA · 3 days ago
HybridFull-time
About the role
Under the general direction of the Manager, Risk Assessment, the Security Analyst will support the Risk Assessment team in delivery of assigned projects and engagements. The role requires a working knowledge of the support elements which comprise an effective information security program, inclusive of common industry frameworks, standards and best practices, and select laws and regulations. Key responsibilities for this role include supporting and conducting information security risk assessments while maintaining a consultative mindset when providing thoughts and guidance to clients.
Responsibilities
- Support senior team members and project leads when assigned client projects in a way which helps ensure clear communication, managed client expectations, and timely delivery
- Provide assessment services to clients in both in-person and virtual settings
- Support the creation and delivery of risk assessment reports based on evaluations of observed controls and workflows
- Deliver high-quality, professional, and consistent services when providing guidance and support to clients
- Contribute to the maintenance and continuous improvement of Fortified services and deliverables
- Maintain a working knowledge of healthcare information security and privacy laws and regulations alongside industry frameworks including, but not limited to: HIPAA, CISA CPGs, and the NIST CSF 2.0
- Possess a working understanding of how technical controls (e.g., EDR/XDR/MDR, SIEM, firewalls) operate within an organization’s environment and what level of security coverage they provide
Requirements
- Bachelor's degree from a four-year college or university or combination of education and experience
- 2+ years’ experience in all or most of the following:
- Information security consulting, preferably with a healthcare background
- Performing risk assessments in the context of information security
- Supporting an organization’s information security program creation or maturation
- Information security frameworks and/or standards such as the HITRUST CSF, the NIST CSF 2.0, and/or ISO 27001
- Information security experience in a hospital setting highly preferred
Skills
- Ability to be flexible and manage tasks across multiple engagements simultaneously
- Analytical skillset which enables the individual to efficiently and accurately gain an understanding of how effectively a control or process operates within an environment
- Consultative mindset which enables the individual to provide recommendations and solutions for clients as they apply to that specific client’s organization
- Detail and results oriented, skilled at both planning and hands-on execution
- Ability to excel in a team-oriented, collaborative office environment
- Intermediate understanding of network infrastructure (both cloud and on-premises) and security concepts
- Intermediate understanding of what elements comprise an effective information security program
- Intermediate understanding of information security frameworks and how framework content applies to an individual system or an organizational program
- Exceptional problem-solving abilities alongside a desire to continually learn new concepts related to the field
- Exceptional written, verbal, and presentation skills
Licenses, Certifications, etc.
- Preferred certifications include: Security+, AWS Certified Security, Azure Security Engineer Associate
Schedule
Hybrid in our Exton, PA office