Job Closed

This listing is no longer active.

Children’s Minnesota logo
Children’s Minnesota

Children’s Minnesota is one of the largest pediatric health systems in the United States and the only health system in Minnesota to provide care exclusively to children, from before birth through young adulthood. An independent and not-for-profit system since 1924, Children’s Minnesota is one system serving kids throughout the Upper Midwest at two free-standing hospitals, nine primary care clinics, multiple specialty clinics and seven rehabilitation sites. As The Kids Experts™ in our region, Children’s Minnesota is regularly ranked by U.S. News & World Report as a top children’s hospital. Children’s Minnesota is proud to be recognized by Modern Healthcare as one of 2023’s Top Diversity Leaders. The national honor recognizes the top diverse healthcare executives and organizations influencing public policy, care delivery, and promoting diversity, equity and inclusion in their organizations and the industry.

Info Security Training Analyst

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 5,001-10,000

Location

United States

Posted

65 days ago

Salary

0

Seniority

Mid Level

Job Description

Info Security Training Analyst

Children’s Minnesota

About Children’s Minnesota Children’s Minnesota is one of the largest pediatric health systems in the United States and the only health system in Minnesota to provide care exclusively to children, from before birth through young adulthood. An independent and not-for-profit system since 1924, Children’s Minnesota is one system serving kids throughout the Upper Midwest at two free-standing hospitals, nine primary care clinics, multiple specialty clinics and seven rehabilitation sites. As The Kids Experts™ in our region, Children’s Minnesota is regularly ranked by U.S. News & World Report as a top children’s hospital. Find us on Facebook @childrensminnesota or on Twitter and Instagram @childrensmn. Please visit childrensMN.org. Children’s Minnesota is proud to be recognized by Modern Healthcare as one of 2023’s Top Diversity Leaders. The national honor recognizes the top diverse healthcare executives and organizations influencing public policy, care delivery, and promoting diversity, equity and inclusion in their organizations and the industry. Position Summary The Information Security Awareness Analyst is responsible for analyzing, implementing and maintaining security controls which enforce the information security policies and security best practice at Children's Minnesota. The analyst will focus on managing and utilizing our security awareness training tools and resources to train users and intensely raise security awareness across the organization. The analyst is also expected to have knowledge of security monitoring tools and responding to security threats and incidents to support SOC activities as needed. The ideal candidate should possess a combination of soft skills and technical skills and have experience training and communicating with users at all levels. License/Certification/Registration *CISSP, CompTIA Security+, GIAC certifications or similar preferred, but not required. Education: *Associate's degree is required in a computer field or equivalent Information Security work experience. *Bachelor's degree is preferred. Experience: *2 to 4 years of IT experience with responsibilities for Information Security. Knowledge/Skills/Abilities: *Knowledge and experience running and managing Security Awareness tools such as KnowBe4 to conduct phishing exercises as well as managing spam and phishing emails. *Knowledge and experience developing security awareness content, including newsletters, PowerPoints, security tips, guidelines and other materials. *Knowledge and experience training, presenting and communicating with users at all levels. *Knowledge and experience developing security awareness training initiatives that reduce the risk of user behavior / insider threat. *Knowledge and experience with threat intelligence, conducting threat research and documenting threat/vulnerability briefings for leadership. *Ability to identify security issues gaps or risks in People, Process and Technology, and recommending mitigation strategies to management. *Ability to utilize SOC tools and processes, preferably in M365 environment, which may include working with our MDR provider, incident response plans, SIEM, forensics, DLP and CASB tools. *Ability to work effectively as a team member and independently with minimal supervision (i.e., self- motivated and willing to stretch to meet important deadlines). *Excellent written and verbal communication skills. *Strong knowledge of Microsoft Office suite of products - Word, Excel, PowerPoint, Visio, etc. Physical Demands Please click here to view the Physical Demands The posted salary represents a market competitive range based on salary survey benchmark data for similar roles in the local or national market. Annual salaries displayed are based on full-time employment (40 standard hrs per week). Annual salaries for part-time positions will be prorated based on the employee’s scheduled weekly hours in relation to the full-time standard. When determining individual pay rates, we carefully consider a wide range of factors including but not limited to market indicators for the specific role, the skills, education, training, credentials and experience of the candidate, internal equity and organizational needs. In addition to your salary, this position may be eligible for medical, dental, vision, retirement, and other fringe benefits. Positions that require night, weekend or on-call work may be eligible for shift differentials or premium pay. All job offers are contingent upon successful completion of an occupational health assessment, drug screen, background investigation, and compliance with the U.S. Government Form I-9, Employment Eligibility Verification. Children’s Minnesota is proud to be an equal opportunity employer whose staff is representative of its community and considers qualified applicants for open positions without regard to race, color, creed, sex, religion, national origin, sexual orientation, genetic information, gender identity or expression, age, veteran status, disability, pregnancy, citizenship status, or any other characteristic protected under applicable federal, state, or local law.

Related Job Pages

More Security Analyst Jobs

Solo Network logo

Data and Information Security Analyst

Solo Network

Soluções que valorizam e impulsionam seu negócio

Security Analyst65 days ago
Full TimeRemoteTeam 201-500Since 2002H1B No Sponsor

• Work with Microsoft Information Protection, Microsoft Purview and Data Loss Prevention (DLP) to identify, classify and protect sensitive data across data estates, devices, e-mail, SharePoint, Teams, OneDrive, etc.; • Configure DLP policies based on financial, contractual and regulatory information (LGPD, SOX, PCI-DSS); • Continuously improve DLP policies based on events, false positives and exception cases; • Monitor DLP alerts, perform analyses and collaborate with incident response teams; • Support investigations led by other teams by providing technical inputs and context about DLP policies, classification rules and potential leakage vectors; • Collaborate with offensive and defensive security teams to ensure prevention use cases are integrated with detection and response mechanisms; • Support the development and maintenance of the Data Governance program aligned with frameworks such as DAMA-DMBOK; • Work together with Data Stewards — professionals designated within business areas who act as focal points to ensure data quality, proper use, security and correct classification; • Conduct mapping, categorization and classification of critical/sensitive data, aligning with the owners of each data domain (e.g., finance, legal, HR); • Implement and maintain taxonomies, glossaries and information labeling using Purview and MIP; • Ensure data is classified according to its value, criticality and sensitivity; • Promote formal classification and continuous updates as inputs for policies, audits and technical controls; • Define and maintain OKRs and maturity indicators related to the technical activities of data governance and leakage prevention, ensuring alignment with the area’s strategic objectives; • Assess the evolution of processes and controls based on maturity levels (e.g., NIST, ISO 27001, DAMA), proposing continuous improvements and prioritizing initiatives based on risk; • Participate in the development and tracking of information security and data protection maturity roadmaps, focusing on technical evolution and governance; • Lead periodic maturity reviews and propose strategic continuous improvement initiatives; • Demonstrate results through dashboards, executive reports and technical evidence; • Develop, review and maintain Information Classification, Acceptable Use, Retention and Data Security policies; • Ensure compliance with regulations and standards such as LGPD, GDPR, SOX, HIPAA, PCI-DSS, ISO 27001:2022 and NIST; • Support internal/external audits with evidence of compliance in DLP, classification and governance; • Conduct training, workshops and awareness campaigns on secure use and information classification; • Architect and support the implementation of technical and procedural governance and data protection controls; • Participate in sensitive data mapping projects and recommend strengthening preventive controls; • Integrate and enhance monitoring in SIEMs (e.g., Microsoft Sentinel), creating rules, use cases and effectiveness reports; • Propose and implement continuous improvement cycles based on incidents, recurring events and coverage gaps.

Brazil
Job Closed
Full TimeRemoteTeam 1,001-5,000Since 2017H1B No Sponsor

• Investigate and respond to alerts from vulnerability scanning, endpoint security, endpoint detection and response (EDR), and intrusion detection and response (IDR) tools • Monitor and manage identity security, MFA, and Conditional Access within Azure/Entra ID • Document security investigations, findings, and remediation actions • Collaborate with IT and cross-functional teams to resolve security issues and improve security controls

North Carolina
$80K - $95K / year
Job Closed
Veeva logo

Cyber Threat Intelligence Analyst

Veeva

Headquartered in Pleasanton, California, Veeva is a leading provider of cloud-based software and services for the life sciences industry. As an employer, Veeva has wanted experienc

Security Analyst65 days ago
Full TimeRemoteTeam 6,000Since 2007

Title: Cyber Threat Intelligence Analyst Location: United States Job Description: Veeva Systems is a mission-driven organization and pioneer in industry cloud, helping life sciences companies bring therapies to patients faster. As one of the fastest-growing SaaS companies in history, we surpassed $3B in revenue in our last fiscal year with extensive growth potential ahead. At the heart of Veeva are our values: Do the Right Thing, Customer Success, Employee Success, and Speed. We're not just any public company – we made history in 2021 by becoming a public benefit corporation (PBC), legally bound to balancing the interests of customers, employees, society, and investors. As a Work Anywhere company, we support your flexibility to work from home or in the office, so you can thrive in your ideal environment. Join us in transforming the life sciences industry, committed to making a positive impact on its customers, employees, and communities. The Role This position is responsible for discovering, analyzing, and vetting relevant cyber threat information to produce detection and defensive mechanisms for the SOC. Additionally, the CTI Analyst will author reports to Senior Leadership and other stakeholders to maintain excellent company situational awareness of emerging threats relevant to Veeva. The analyst will also evaluate internal behavioral telemetry and potential risk indicators to identify and mitigate insider threats, ensuring a comprehensive view of the organization's risk profile. A repository of IOCs will be maintained to correlate attack patterns to further predict and defend against adversary personas. Finally, the CTI analyst will aid in the preparation and execution of proactive defense measures. What You'll Do - Leverage a Collection Management Framework (CMF) that organizes all threat intelligence feeds, both internal and external, by indicators and data that can be ascertained as well as the methods in how data is collected - Report on potential areas of compromise and areas of concern through information provided by threat intelligence sources - Apply the indicator lifecycle (revealed, matured, utilized) to validate incoming indicators and determine relevance to Veeva - Detect patterns of ongoing intrusion and intrusion attempts across Veeva and the industry to predict future IOCs and suggest implementations - Utilize CTI tools to detect/report on trends to drive decisions influencing defensive operations - Report actionable metrics related to adversarial behavior to drive prioritized defensive actions - Support incident responders with relevant IOCs and historical data during ongoing investigations - Author intelligence reports that address intelligence requirements and RFIs from across the company - Support engineers in the preparation, design, and execution of threat hunt missions - Research and analyze adversarial threat behaviors to prepare for emulation exercises to assess controls - Apply threat intelligence methodologies to internal log data and User and Entity Behavior Analytics (UEBA) to detect anomalies indicative of insider compromise or collusion Requirements - Good understanding of the Kill Chain and Diamond models, and means to merge them - Ability to leverage MITRE ATT&CK in support of CTI reporting - Good familiarity with some OSINT and proprietary CTI tools, examples as: DomainTools, MISP, YARA, ISAC/ISAO feeds, CyberChef, DataSploit, FireHOL, Maltego, Shodan, ThreatQuotient, Recorded Future Anomali, etc. - Good familiarity with modern threats, top delivery vectors, and methods of exploitation - Experience in organizing, processing, analyzing, and vetting indicators using sorting/processing tools to maintain a current, relevant threat database - Experience in leveraging existing threat intelligence to augment investigations during incident response - 1+ years of experience in a cyber threat intelligence-related field, or 3+ years of experience in a cybersecurity operations field - Experience analyzing behavioral telemetry and system logs (e.g., SIEM, EDR, UEBA) to identify technical indicators of insider risk - Strong familiarity with different levels of CTI products (Strategic, Operational, Tactical/Technical) - Good understanding of the different phases of the CTI lifecycle (Planning, Collection, Analysis, Production, and dissemination/feedback) Nice to Have - Threat Intelligence or Intrusion Detection-related certification, such as GCTI, GOSI, CTIA, GCDA, GCIA, CCTIA, CTIP, CPTIA, CRTIA, etc. - Experience in enriching data of the four atomic indicators (domains, strings, IP addresses, accounts) to deliver additional context to incident responders - Solid background in cloud security principles - Experience in creating and maintaining a prioritized list of critical assets and understanding the top threats against them - Experience with threat hunting development - Experience in threat emulation or use of deceptive technologies Perks & Benefits - Medical, dental, vision, and basic life insurance - Flexible PTO and company paid holidays - Retirement programs - 1% charitable giving program Compensation - Base pay: $75,000 - $125,000 - The salary range listed here has been provided to comply with local regulations and represents a potential base salary range for this role. Please note that actual salaries may vary within the range above or below, depending on experience and location. We look at compensation for each individual and base our offer on your unique qualifications, experience, and expected contributions. This position may also be eligible for other types of compensation in addition to base salary, such as variable bonus and/or stock bonus. #LI-RemoteUS #LI-Associate Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world. Veeva is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin or ancestry, age, disability, marital status, pregnancy, protected veteran status, protected genetic information, political affiliation, or any other characteristics protected by local laws, regulations, or ordinances

Worldwide
$75K - $125K / year
Full TimeRemoteTeam 1,001-5,000Since 2002H1B No Sponsor

• Experiência sólida em Resposta a Incidentes, SOC/CSIRT ou funções correlatas, com atuação em incidentes de média/alta criticidade. • Domínio do ciclo de IR (preparação, detecção/análise, contenção, erradicação, recuperação e pós-incidente), com foco em execução consistente e auditável. • Vivência com SIEM e EDR/XDR, análise de logs/eventos, investigação de alertas e correlação de evidências. • Conhecimento aprofundado de Windows, Linux e macOS, incluindo análise de artefatos relevantes para IR. • Sólidos fundamentos de redes e protocolos, arquitetura de segurança e análise de comunicações suspeitas. • Conhecimento e aplicação de frameworks/padrões (ex.: MITRE ATT&CK, NIST SP 800-61, SANS IR). • Experiência em investigações em ambientes cloud (ex.: IAM, trilhas de auditoria, logs nativos, postura e respostas). • Automação e scripting (Python/PowerShell/Bash) para acelerar coleta, triagem e análise. • Experiência com integração e uso de threat intelligence (feeds, IOCs, enriquecimento e priorização).

Brazil
Job Closed