Jobs · Information Technology

Security Analyst

Fortified Health Security · United States · 2 wk ago
RemoteRemoteInformation TechnologyFull-time

Fortified Health Security is seeking a hands-on Information Security Analyst to support a healthcare client through a full-time, staff augmentation engagement. This role will work directly with the client’s technology and operations teams as well as Fortified’s vCISO and EOD team to assist with a variety of technical security tasks.

Responsibilities

  • Email & Messaging Security: Understand O365 environment; knowledge of Abnormal (or other email security tools), and Exchange routing. Assist with email spoofing/spam reviews and graymail analysis.
  • Phishing Defense: Conduct second-pass reviews via Abnormal or KnowBe4 PhishER.
  • Endpoint Security: Knowledge of SentinelOne or other endpoint security tools. Address endpoint alerts and incident response.
  • Firewall Rule Review and Recommendations: Review N/S and E/W rules using Palo Alto and server-to-web or rule-based filtering.
  • MFA/SSO: Understanding of various MFA tools and Entra SSO scenarios as needed.
  • Policy & Procedure Support: Contribute to documentation and configuration standards for tools in use.
  • Incident Handling: Triage detections escalated from the SOC or abnormal activity in O365 or other security platforms. Investigate security breaches and other cybersecurity incidents.
  • Help standardize control operations across cloud (M365), endpoint, and perimeter defense systems.
  • Collaborate with client’s teams, client’s third parties, and Fortified departments to ensure a holistic approach to cybersecurity.
  • Understand healthcare business operations, the healthcare cybersecurity landscape, and the healthcare regulatory environment.
  • Collaborate with Fortified’s vCISO to mature the client’s security posture and close documented gaps.
  • Assist vCISO in the identification and proposal of key information security priorities, initiatives, plans, practices, and tools.
  • Research potential and emerging information security threats, vulnerabilities, and potential control techniques and communicate this information to vCISO.
  • Develop necessary policies, procedures, and processes pertaining to Cybersecurity Risk Management.
  • Install security measures and operate software to protect systems and information infrastructure.
  • Develop security policies, procedures, standards, and runbooks.
  • Document security incidents/breaches and assess the damage they cause.
  • Work with the client’s teams to perform tests and uncover vulnerabilities.
  • Develop company-wide best practices for IT security.
  • Document and communicate recurring patterns or systemic issues requiring escalation or strategic remediation.
  • Help clients install security software and understand information security management.
  • Research security enhancements and make recommendations to vCISOs/client leadership.
  • Stay current on evolving cybersecurity threats and how they impact email, endpoint, and identity systems.
  • Analyze security incidents/breaches to identify the root cause.
  • Verify the security of third-party vendors and collaborate with them to meet security requirements.

Requirements

  • 3+ years in IT or information security in a hospital environment.
  • Bachelor's degree from a four-year college or university or combination of education and experience.
  • Working knowledge of:
    • Microsoft 365 (O365), Exchange hybrid environments
    • Palo Alto firewalls or other next-gen firewalls
    • Endpoint Detection and Response (EDR) tools such as SentinelOne
    • Web gateways and DLP tools
    • MFA solutions (DUO, Entra SSO)
  • Strong understanding of network security concepts, firewalls, intrusion detection/prevention systems (IDS/IPS), MFA, Asset Management, DLP, Application Control.
  • Experience with SIEM tools and security information and event management (SIEM) principles.
  • Experience with cloud security concepts (AWS, Azure, GCP).
  • Scripting experience (PowerShell or Python) is a plus but not required.
  • Three years or more general network (WAN) experience is a plus.

Skills

  • Strong problem-solving skills and a desire to learn; self-starter with a can-do attitude.
  • Excellent customer relationship skills and communication skills.
  • Ability to handle sensitive information.
  • Analytical mindset and critical thinking abilities; data-driven.
  • Self-motivated individual capable of working in a fast-paced, dynamic environment.
  • Detail and results-oriented, skilled at both planning and hands-on execution.
  • Ability to excel in a team-oriented, collaborative, and fast-paced environment.
  • Excellent written, verbal, and presentation skills.
  • Working knowledge of all network technology including LAN, WAN concepts, wireless technology, and VOIP concepts is a plus.
  • Troubleshooting skills.
  • Strong analytical and problem-solving skills, as well as excellent interpersonal and communication skills.
  • Ability to effectively communicate with a wide range of individuals in a diverse healthcare setting.

Qualifications

  • One or more of the following certifications are preferred: Security+, CISSP, any GIAC or cloud security certification.

Schedule

Pacific Time working hours.

Similar jobs

Security Analyst

Credit Control, LLC.Earth City, MO· 2 mo ago
Information Technologyapply on creditcontrolllc.bamboohr.com

Security Analyst

TALENT Software ServicesColumbia, SC· 1 mo ago
OTHRapply on www2.jobdiva.com

Security Analyst

VimoMountain View, CA· 2 mo ago
RemoteEngineeringapply on paycomonline.net

Security Analyst

Arista NetworksSanta Clara, CA· 2 mo ago
Engineering$103k–$154k/yrapply on jobs.smartrecruiters.com

Security Analyst

Target HospitalityThe Woodlands, TX· 1 mo ago
Information Technologyapply on recruiting2.ultipro.com