Security Analyst
Fortified Health Security · United States · 2 wk ago
RemoteRemoteInformation TechnologyFull-time
Fortified Health Security is seeking a hands-on Information Security Analyst to support a healthcare client through a full-time, staff augmentation engagement. This role will work directly with the client’s technology and operations teams as well as Fortified’s vCISO and EOD team to assist with a variety of technical security tasks.
Responsibilities
- Email & Messaging Security: Understand O365 environment; knowledge of Abnormal (or other email security tools), and Exchange routing. Assist with email spoofing/spam reviews and graymail analysis.
- Phishing Defense: Conduct second-pass reviews via Abnormal or KnowBe4 PhishER.
- Endpoint Security: Knowledge of SentinelOne or other endpoint security tools. Address endpoint alerts and incident response.
- Firewall Rule Review and Recommendations: Review N/S and E/W rules using Palo Alto and server-to-web or rule-based filtering.
- MFA/SSO: Understanding of various MFA tools and Entra SSO scenarios as needed.
- Policy & Procedure Support: Contribute to documentation and configuration standards for tools in use.
- Incident Handling: Triage detections escalated from the SOC or abnormal activity in O365 or other security platforms. Investigate security breaches and other cybersecurity incidents.
- Help standardize control operations across cloud (M365), endpoint, and perimeter defense systems.
- Collaborate with client’s teams, client’s third parties, and Fortified departments to ensure a holistic approach to cybersecurity.
- Understand healthcare business operations, the healthcare cybersecurity landscape, and the healthcare regulatory environment.
- Collaborate with Fortified’s vCISO to mature the client’s security posture and close documented gaps.
- Assist vCISO in the identification and proposal of key information security priorities, initiatives, plans, practices, and tools.
- Research potential and emerging information security threats, vulnerabilities, and potential control techniques and communicate this information to vCISO.
- Develop necessary policies, procedures, and processes pertaining to Cybersecurity Risk Management.
- Install security measures and operate software to protect systems and information infrastructure.
- Develop security policies, procedures, standards, and runbooks.
- Document security incidents/breaches and assess the damage they cause.
- Work with the client’s teams to perform tests and uncover vulnerabilities.
- Develop company-wide best practices for IT security.
- Document and communicate recurring patterns or systemic issues requiring escalation or strategic remediation.
- Help clients install security software and understand information security management.
- Research security enhancements and make recommendations to vCISOs/client leadership.
- Stay current on evolving cybersecurity threats and how they impact email, endpoint, and identity systems.
- Analyze security incidents/breaches to identify the root cause.
- Verify the security of third-party vendors and collaborate with them to meet security requirements.
Requirements
- 3+ years in IT or information security in a hospital environment.
- Bachelor's degree from a four-year college or university or combination of education and experience.
- Working knowledge of:
- Microsoft 365 (O365), Exchange hybrid environments
- Palo Alto firewalls or other next-gen firewalls
- Endpoint Detection and Response (EDR) tools such as SentinelOne
- Web gateways and DLP tools
- MFA solutions (DUO, Entra SSO)
- Strong understanding of network security concepts, firewalls, intrusion detection/prevention systems (IDS/IPS), MFA, Asset Management, DLP, Application Control.
- Experience with SIEM tools and security information and event management (SIEM) principles.
- Experience with cloud security concepts (AWS, Azure, GCP).
- Scripting experience (PowerShell or Python) is a plus but not required.
- Three years or more general network (WAN) experience is a plus.
Skills
- Strong problem-solving skills and a desire to learn; self-starter with a can-do attitude.
- Excellent customer relationship skills and communication skills.
- Ability to handle sensitive information.
- Analytical mindset and critical thinking abilities; data-driven.
- Self-motivated individual capable of working in a fast-paced, dynamic environment.
- Detail and results-oriented, skilled at both planning and hands-on execution.
- Ability to excel in a team-oriented, collaborative, and fast-paced environment.
- Excellent written, verbal, and presentation skills.
- Working knowledge of all network technology including LAN, WAN concepts, wireless technology, and VOIP concepts is a plus.
- Troubleshooting skills.
- Strong analytical and problem-solving skills, as well as excellent interpersonal and communication skills.
- Ability to effectively communicate with a wide range of individuals in a diverse healthcare setting.
Qualifications
- One or more of the following certifications are preferred: Security+, CISSP, any GIAC or cloud security certification.
Schedule
Pacific Time working hours.