Job Closed

This listing is no longer active.

Kettering Health Network

Based in Kettering, Ohio, Kettering Health Network is a faith-based health care organization that provides comprehensive medical care to residents of greater Dayton and northern Ci

Security Analyst II

Location

Ohio

Posted

49 days ago

Salary

0

Seniority

Senior

Job Description

Security Analyst II

Kettering Health Network

Title: Security Analyst II - IS Info Security Location: Miamisburg United States Job Description: Job ID 2026-57764 Job Category Information Technology Job Type Full-Time Shift First Shift Department 936893 - IS INFO SECURITY FTE 80 Hours Per Pay Period/FTE 1.0 Job Code 126050 Responsibilities & Requirements The Information Security Analyst II supports the protection of sensitive healthcare information, clinical systems, and technology infrastructure. This role focuses on threat detection, incident response, vulnerability management, and compliance with healthcare regulations such as HIPAA. The analyst collaborates with IT, clinical, and business stakeholders to reduce risk and ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI). Job Requirements: - Associate's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience). - 3-5 years of experience in information security, security operations, or related IT roles - Hands‑on experience with: - Security monitoring and incident response - Vulnerability management tools and processes - Endpoint, network, and identity security controls - Working knowledge of: - HIPAA Security Rule requirements - Windows and Linux operating systems - Networking fundamentals (TCP/IP, DNS, firewalls) - Common attack techniques targeting healthcare environments - Strong analytical, documentation, and communication skills - Ability to work effectively in a regulated, patient‑care‑focused environment Job Responsibilities: - - Monitor security events and alerts using SIEM, EDR, and other security tools to detect potential threats impacting healthcare systems and data - Investigate, respond to, and document security incidents involving ePHI, clinical applications, and enterprise infrastructure - Support incident response activities including containment, recovery, root‑cause analysis, and post‑incident reporting - Conduct vulnerability scanning and risk assessments of servers, endpoints, medical devices, and healthcare applications - Assist with remediation efforts and validate security control effectiveness in collaboration with IT, clinical engineering, and application teams - Support compliance with healthcare regulatory requirements including HIPAA, HITECH, and organizational security policies - Participate in audits, risk assessments, and third‑party security reviews - Maintain and update security documentation, incident response playbooks, and standard operating procedures - Contribute to security awareness initiatives and provide guidance to staff on protecting patient information - Server as a mentor for junior analysts, coaching and growing their skills capabilities - Stay informed of emerging healthcare cybersecurity threats, ransomware trends, and industry best practices Preferred Qualifications - Experience in healthcare, hospital, payer, or clinical environments - Familiarity with electronic health record (EHR) platforms and clinical systems - Experience securing cloud‑based healthcare workloads (Azure, AWS, or GCP) - Scripting or automation experience (PowerShell, Python, or similar) - Certifications such as: - CompTIA Security+ or CySA+ - CISSP, HCISPP, SSCP, GCIH, or similar Overview Kettering Health is a not-for-profit system of 14 medical centers and more than 120 outpatient facilities serving southwest Ohio. Our mission is to live God's love by promoting and restoring health. Our commitment to our patients is to help individuals be their best. With that context, safety is our top priority. We provide an integrated system of healthcare experts committed to providing exceptional care.

Related Job Pages

More Security Analyst Jobs

Government of Alberta logo

Information Security Officers (Detection & Response / Log Management)

Government of Alberta

Bringing you information about government news and services. Comment rules: http://alberta.ca/SMComments

Security Analyst49 days ago
Full TimeRemoteTeam 10,001+Since 1905H1B No Sponsor

Job Information Job Title: Information Security Officers (Detection & Response / Log Management) Job Requisition ID: 82206 Ministry: Technology and Innovation Location: Remote across Alberta Full or Part-Time: Full Time Hours of Work: 36.25 hours per week Permanent/Temporary: Permanent Scope: Open Competition Closing Date: April 28, 2026 Classifications: - Systems Analyst Level 2 - Systems Analyst Level 3 Salary range: - Systems Analyst Level 2: $3,115.21 - $4,277.30/ Biweekly ($81,306 - $111,637/ per year) - Systems Analyst Level 3: $3,756.86 - $4,976.09/ Biweekly ($98,054 - $129,875/ per year) Every member of Technology and Innovation strives to enable the success of our Ministry partners and Albertans through providing exceptional client focused services that meet and exceed our clients’ expectations. We are looking for collaborative, agile, solutions focused individuals with strong communication skills and strong service orientation. If that describes you, please read on! To learn more about us, please visit our ministry’s web page (https://www.alberta.ca/technology-and-innovation.aspx) and Cybersecurity in Alberta (https://www.alberta.ca/cybersecurity-in-alberta.aspx). The passionate and solutions focused people that we hire help us to drive vital programs and services that affect Albertans. Whatever your position is here, you will be a part of something great. Join us! Role Responsibilities The Government of Alberta (GoA) is expanding its cybersecurity force and is actively recruiting talented professionals to join our Detection and Response Team (DART), and our newly established Log Management Team. We’re seeking strategic and forward thinking Information Security Officers at both the ISO2 and ISO3 levels. Multiple permanent positions are available across the following specialized areas within the Cybersecurity Division: - Detection and Response Team - Log Management Team As an Information Security Officer, you are tasked with protecting the confidentiality, integrity and availability of the Government of Alberta's (GoA) information assets. You are responsible for identifying, assessing, monitoring, detecting, investigating, researching, and responding to vulnerabilities, threats and incidents impacting the security of information assets. Role & Responsibilities: 1- Detection and Response Team This position supports protection of government information assets by monitoring security events, investigating threats, and responding to incidents. Analyzes security data, coordinates response, and supports containment and recovery per policy, collaborating with technical teams to reduce risk and ensure system availability and integrity. Responsibilities: - - Provide information security advice to stakeholders and communicate cyber threat information - Participate in projects as an information security subject matter expert - Identify security requirements and develop strategies and solutions to address them - Identify, assess, and treat risks; document them in the IT Security Risk Register; and perform cybersecurity research as requested 2- Log Management Team This position, working with the Detection and Response team, protects Government of Alberta's information assets by collecting, monitoring, and analyzing logs for SIEM ingestion to support detection, investigation, and compliance. They ensure proper logging, retention, and protection, while enabling event correlation, anomaly detection, incident response, troubleshooting, audit readiness, and actionable insights. Responsibilities: - - Collect, monitor, and analyze system, application, and security logs for SIEM ingestion - Provide security advice, communicate cyber threats, and participate in projects as an SME - Identify security requirements and develop strategies and solutions to address them - Identify, assess, and treat vulnerabilities, threats, and risks; document in the IT Security Risk Register; and perform related research as requested Role Responsibilities Continued To be successful in these positions, you will demonstrate: - Ability to lead and remain calm in times of crisis. - Excellent verbal and written communication skills for executive briefings and technical discussions. - Demonstrated ability to collaborate effectively and secure alignment across multiple stakeholders. - A sense of curiosity to investigate root cause and identify options and a recommendation. - Analytical and problem-solving skills for complex environments. AI-First Mindset These roles are designed with an AI-first approach to help you work smarter, not harder. You will leverage AI tools to: - Automate insights and personalize stakeholder engagement. - Create tailored, high-impact materials using AI-assisted content generation. - Develop and track KPIs using AI to surface trends and predict outcomes. - Demonstrate proficiency in utilizing AI to address complex problems and automate analysis of extensive datasets. If you’re passionate about safeguarding Alberta’s digital landscape and ready to contribute to high impact, mission critical work, this is an exciting opportunity to make a meaningful difference! - Please click on this link to view the job description for the ISO2 position. - Please click on this link to view the job description for the ISO3 position. APS Competencies Competencies are behaviors that are essential to reach our goals in serving Albertans. We encourage you to have an in depth understanding of the competencies that are required for this opportunity and to be prepared to demonstrate them during the recruitment process. This link will assist you with understanding competencies: https://www.alberta.ca/system/files/custom_downloaded_images/psc-alberta-public-service-competency-model.pdf. Some of the competencies critical for this position include: - Systems Thinking: You will consider the whole system when developing, evaluating and implementing process and technology change. - Creative Problem Solving: You will assess options and implications in new ways to achieve outcomes and solutions. - Agility: You will need to provide results in a complex, diverse and changing environment. - Develop self and others: A commitment to lifelong learning and the desire to invest in the development of the long-term capability of yourself and others. - Drive for Results: Knowing what outcomes are important and maximizing resources to achieve results that are aligned with the goals of the organization, while maintaining accountability to each other and external stakeholders. - Build Collaborative Environments: Leads and contributes to the conditions and environments that allow people to work collaboratively and productively to achieve outcomes. - Develop Networks: Proactively building networks, connecting, and building trust in relationships with different stakeholders. Qualifications Required: Information Security Officer 3 (ISO3) - A university degree in Computer Science, Information Technology, or a related field. - Minimum of 4 years of related experience. Equivalencies for ISO3 Position: - - A related two-year diploma from a recognized post-secondary institution and a minimum of six (6) years related experience; or - A related one-year certificate from a recognized post-secondary institution and a minimum of seven (7) years related experience. Information Security Officer 2 (ISO2) - A university degree in Computer Science, Information Technology, or a related field. - Minimum of 2 years of related experience. Equivalencies for ISO2 Position: - - A Related two-year diploma from a recognized post secondary institution and a minimum of four (4) years related experience; or - A related one-year certificate from a recognized post secondary institution and minimum of five (5) years related experience. Additional required experience for both positions: - Experience in Information Systems Security, IT Infrastructure Planning, and/or IT Architecture. - Experience in Information Technology or related role with an emphasis in Security Management Operations (Incident Response) or Log Monitoring. - Security certification such as CISSP, CISM, CISA, CRISC, SANS, CEH, GPEN, or equivalent, and it is expected that incumbents would be working towards multiple certifications. - Cover Letter - Please include a cover letter that clearly outlines your relevant experience along with the years of experience that you possess in your preferred specialized area/areas in Cybersecurity. Qualifications Continued Assets: - Experience with AI-powered cybersecurity tools and techniques. - Proven experience delivering information security services in operational environments. - Hands-on experience using cybersecurity tools and technologies to support information security functions. - Experience conducting research using open sources. - Knowledge of network protocols and how adversaries utilize them to facilitate intrusions. - Experience attributing malicious activity to known threat actors and uncovering their motivations, affiliations, and any further context. - Proficient in one or more programming language (e.g., Python, C, C++), and one or more query language (e.g., KQL, SQL). - Strong critical thinking, analytical and problem-solving skills, including the ability to deal with large amounts of information in a limited time. - Excellent communication skills, both written and verbal. Ability to communicate technical information to diverse audiences – both technical and non-technical – in a clear and concise manner. - Experience translating complex information into clear, high-quality briefings for executive management. - Familiarity with Microsoft Azure suite of products, including Microsoft Sentinel and Microsoft 365 Defender. *** Applications will be evaluated, and candidates will be considered for the position/classification, that is most closely aligned with their skills, qualifications, and relevant experience. (Minimum recruitment standards outline the minimum education and experience required for appointment to a job classification. Refer to https://www.alberta.ca/alberta-public-service-minimum-recruitment-standards. Notes Term of Employment: Multiple Permanent Full-time positions Hours of Work: 36.25hrs/ week – Monday to Friday Location: Remote across Alberta These positions are eligible for remote work. You must reside in Alberta to work remotely. A written assessment may be required as part of the interview process. Depending on the project, on-call rotation and overtime may be required. Final candidates will be required to undergo enhanced security screening. This competition may be used to fill future vacancies, across the Government of Alberta, at the same or lower classification level. Applicants are advised to provide a cover letter summarizing information that clearly and concisely demonstrates how their qualifications meet the advertised requirements, including education, experience, and relevant examples of required competencies. Any costs associated with obtaining the required documents/checks as noted or interview travel expenses, will be the responsibility of the candidate. Out-of-province applicants can obtain the required documents/checks from the province they currently reside in. Links and information on what the GoA have to offer to prospective employees. - Working for the Alberta Public Service - https://www.alberta.ca/advantages-working-for-alberta-public-service.aspx. - Public Service Pension Plan (PSPP) - https://www.pspp.ca. - Alberta Public Service Benefit Information - https://www.alberta.ca/alberta-public-service-benefits. - Professional learning and development - https://www.alberta.ca/professional-development-support-directive. - Research Alberta Public Service Careers tool – https://researchapscareers.alberta.ca. - Cybersecurity in Alberta - https://www.alberta.ca/cybersecurity-in-alberta - Positive workplace culture and work-life balance. - Leadership and mentorship programs How To Apply Applicants are advised to provide information that clearly and concisely demonstrates how their qualifications meet the advertised requirements, including education, experience, and relevant examples of required competencies. Candidates are required to apply for a job online. Please visit https://www.alberta.ca/job-application-resources#before for more information. Please visit Recruitment Principles, for more information. It is recommended applicants who have completed post-secondary studies from outside of Canada obtain an evaluation of their credentials from the International Qualifications Assessment Service (IQAS)(https://www.alberta.ca/international-qualifications-assessment.aspx) or from a recognized Canadian Credential Evaluator; please visit the Alliance of Credential Evaluation Services of Canada for more information (https://canalliance.org/en/default.html). It is recommended that applicants include the assessment certificate from IQAS or any other educational assessment service as part of their application. Closing Statement This competition may be used to fill future vacancies, across the Government of Alberta, at the same or lower classification level. We thank all applicants for their interest. All applications will be reviewed to determine which candidates' qualifications most closely match the advertised requirements. Only individuals selected for interviews will be contacted. If you require any further information on this job posting or require an accommodation during the recruitment process, please contact Michelle Elliott at Michelle.Elliott@gov.ab.ca.

Canada
81.3K - 129K / year
Fresenius Medical Care logo

Principal Cyber Security Analyst - Digital Forensics

Fresenius Medical Care

Fresenius Medical Care provides dialysis treatments, products, and services for individuals living with chronic kidney diseases (CKD). Founded as a result of the 1996 merger of Fre

Security Analyst49 days ago

Role Description The Principal Cyber Security Analyst specializing in Digital Forensics serves as the senior technical authority for forensic investigations across the enterprise. This role leads complex incident response cases, conducts advanced forensic analysis of endpoints, servers, cloud environments, and networks, and provides strategic insight to reduce organizational risk. The Principal Analyst acts as the highest level escalation point for investigative matters and mentors other analysts in evidence handling, methodology, and tooling. This is a U.S.-based remote position supporting Fresenius Medical Care’s global Cyber Security Operations Center. Principal Duties and Responsibilities - Lead enterprise level forensic investigations involving malware, insider threats, credential compromise, data exfiltration, fraud, and targeted attacks. - Act as technical commander during priority incidents, directing scoping, containment, eradication, and root cause analysis in partnership with IR, IT, and Cloud teams. - Conduct root cause, impact, and attribution analysis for major cyber events; drive corrective and preventive actions. - Lead post incident reviews and oversee closure of remediation tasks, translating findings into hardening and control improvements. - Develop and maintain forensic methodologies, chain of custody procedures, and evidence handling standards. - Serve as the primary liaison with Legal, Privacy, HR, and external law enforcement during escalated or sensitive investigations. - Correlate forensic artifacts with threat intelligence insights to identify adversaries, campaigns, and TTPs. - Establish and maintain forensic readiness strategies, including tooling optimization, logging enhancements, and data retention standards. - Develop lightweight tools and scripts (Python/PowerShell) for artifact parsing, timeline generation, triage capabilities, and cloud log normalization. Physical Demands and Working Conditions The physical demands and work environment characteristics represent those typically encountered while performing essential duties. Reasonable accommodation may be made as needed. This is a remote role with availability expected during core hours and during escalations as required. Supervision Provides technical leadership and mentorship to threat engineers and SOC analysts globally. Does not directly manage staff. Education - Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent professional experience). Experience and Required Skills - 10+ years in Incident Response/DFIR, including leadership of complex, enterprise scale investigations. - Cloud & Identity: Sentinel/Splunk, Microsoft 365/Azure logs, AWS/GCP logging, Entra/Okta audit trails. - Network: Zeek, Suricata, Brim/Wireshark, PCAP/flow analytics. - Experience in evidence handling, legal hold/eDiscovery coordination, and working with Legal/HR/Privacy. - Mastery of Windows and Linux internals, authentication flows, common persistence/mechanisms, and lateral movement TTPs. - Proficient in Python or PowerShell for automation and artifact analysis. - Excellent written and verbal communication—able to brief executives clearly under time pressure. Preferred - Industry certifications (one or more): GCFA, GCFE, GNFA, GREM, GCIH, CISA, CISSP, Azure Security, AWS Security. - Experience with Zero Trust controls, identity threat detection, and SaaS forensics (O365, Google Workspace). - Familiarity with EPSS/SSVC, threat modeling, and purple team/ATT&CK evaluation practices. - Background in regulated environments (e.g., healthcare, financial services, manufacturing) and associated audit expectations. Compensation and Benefits - Annual Rate: $117,700.00 - $196,200.00 for Waltham, MA location. - Comprehensive benefits package including medical, dental, and vision insurance. - 401(k) with company match. - Paid time off. - Parental leave. - Potential for performance-based bonuses depending on company and individual performance. Company Description Fresenius Medical Care maintains a drug-free workplace in accordance with applicable federal and state laws. Fresenius Medical Care is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sexual orientation, gender identity, parental status, national origin, age, disability, military service, or other non-merit-based factors.

United States
$117.7K - $196.2K / year
Job Closed
Capgemini logo

Senior Information Security Analyst - DLP (Data Loss Prevention)

Capgemini

Founded in 1967, Capgemini is revered as one of the world's leading consulting, technology, and outsourcing agencies. In 2016 alone, the company reported global

Security Analyst49 days ago

Role Description Você é apaixonado(a) por tecnologia, inovação e quer fazer parte de um ambiente inclusivo, colaborativo e em constante evolução? Então essa oportunidade é para você! Na Capgemini, valorizamos o equilíbrio entre vida pessoal e profissional. Por isso, oferecemos modelos de trabalho flexíveis. Nosso objetivo é proporcionar a melhor experiência para você, respeitando seu estilo de vida e promovendo bem-estar. Qualifications - Experiência com Prevenção de Vazamento de Dados (Data Loss Prevention – DLP) - Conhecimento em mapeamento de fluxos de dados e identificação de informações sensíveis - Capacidade de definir e implementar políticas de DLP alinhadas a normas de segurança da informação - Vivência na configuração, parametrização e administração de soluções DLP, como: - Microsoft Purview - Netskope (ou ferramentas equivalentes) - Experiência no monitoramento de alertas, análise de incidentes e ajuste de regras para redução de falsos positivos - Conhecimento em controles de acesso, classificação da informação e proteção de dados - Apoio a auditorias internas e externas, elaboração de relatórios e evidências de conformidade - Familiaridade com requisitos regulatórios e boas práticas de segurança da informação Requirements - Experiência prévia em ambientes corporativos de grande porte - Atuação em projetos de compliance, governança ou privacidade de dados - Conhecimento em frameworks e normas como LGPD, ISO 27001, SOC, PCI-DSS Benefits Na Capgemini, liberamos a energia humana por meio da tecnologia para construir um futuro mais inclusivo, sustentável e inovador. Se você compartilha desses valores, venha transformar o mundo com a gente!

Brazil
Mastercard logo

Senior Security Monitoring and Response Analyst

Mastercard

Founded in 1966, Mastercard is a worldwide transaction, payment-processing, and consulting company best known for its line of personal and business credit cards. As an employer, Ma

Security Analyst49 days ago
Full TimeRemoteTeam 38,800Since 1966

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Senior Security Monitoring and Response Analyst Who is Mastercard? Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all. Overview The Security Operations Center Incident Response (SOCIR) is a high-performance team responsible for security monitoring and response using advanced toolsets. The team is available 24/7 though a globally distributed operational team. The Security Monitoring and Response Senior Analyst is an integral member of the SOC's Incident Response team, providing direct support for security incidents and general security operations. • Do you want to be part of the team handling complex technical monitoring and response functions during a security incident?• Have you provided technical leadership or oversight to junior analysts?• Do you want to improve security operations through technical projects and data analysis? Core Skills: • Takes ownership of Incidents reported to the Incident Response Team end to end. • Performs technical analysis for security Incidents, including for cases of malware, web attacks, lateral movement, and other ad hoc issues as they arise. • Communicate INC updates and engage necessary stakeholders while responding to incidents • Maintain on-call hours to handle escalated events after hours and maintain the ability to provide rare emergency coverage in the SOC if needed. • Conduct After action review (AAR) sessions and share lesson learnt with stakeholders. • Lead and conduct threat hunting activities. • Understand and utilize scripting skills to automate investigation and analysis. Incident Response Process: • Understand NIST and other IR standards such as CIS, ISO/IEC 27305 and SANS • Able to implement IR Playbook in unknown situations and improve the playbook while acting with urgency on ongoing incident • Review existing playbooks and runbooks and make improvements and suggest changes • Develop new runbooks and identify automation scenarios Technology and Growth: • Identify and lead projects with the focus of making technological improvements to SOC operations. • Participate in SOC metric and reporting improvements • Mentor and coach SOC Tier 1 staff members to assist with improving operations and increasing their capabilities. • Master and become subject matter expert on key security concepts such as Cloud monitoring and response, Identify and Access Management, Malware and Forensics, Incident response and communications Requirements • Proven experience in a Security Operations Center (SOC) or Incident Response role• End-to-end ownership of security incidents, from detection through containment, resolution, and post-incident review• Strong technical investigation and analysis skills with hands-on experience investigating malware incidents, web attacks, lateral movement and suspicious network activity• Ability to work regular hours including on-call and after-hours incident escalation• Working knowledge of incident response frameworks and standards (e.g. NIST, SANS, CIS, ISO/IEC)• Experience using IR playbooks and runbooks during live incidents, including adapting them to unfamiliar scenarios• Solid understanding of core security concepts i.e. incident response and communications, malware analysis and digital forensics and Identity and Access Management (IAM)• Ability to clearly communicate incident status, risks, and actions to technical and non-technical stakeholders• Experience leading or contributing to After Action Reviews (AARs) and documenting lessons learned• Strong sense of ownership, urgency, and accountability during high-impact incidents Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: - Abide by Mastercard's security policies and practices; - Ensure the confidentiality and integrity of the information being accessed; - Report any suspected information security violation or breach, and - Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Australia