Athena logo
Athena

Athena is a community mental health clinic serving clients from all walks of life throughout New York State.

Security Analyst

Location

Kenya

Posted

6 days ago

Salary

0

Seniority

Mid Level

Job Description

Security Analyst

Athena

Role Description We are looking for a Security Analyst – Client Trust & Support to serve as a trusted security and compliance partner for customers, prospects, and cross-functional internal teams. This is a client-facing role focused on helping customers understand, evaluate, and successfully navigate our security, privacy, and compliance environment. This role bridges Security, Operations, and Sales. The ideal candidate can communicate security concepts clearly, manage customer-facing security reviews, and help drive confidence in our platform, operations, and control environment. You will support customer security reviews, vendor risk assessments, security questionnaires, evidence coordination, incident communications, and ongoing client trust initiatives. Responsibilities - Customer Security Engagement - Serve as a primary support contact for enterprise customer and prospect security inquiries. - Support customer-facing discussions related to security controls, compliance posture, privacy practices, and operational security processes. - Partner with Sales, Customer Success, Legal, IT, and Security teams during enterprise reviews and escalations. - Assist with security-related onboarding activities for enterprise customers. - Help customers and prospects understand how security and compliance are managed in practice. - Security Reviews & Assessments - Complete and manage customer security questionnaires, vendor risk assessments, and due diligence reviews. - Support customer audits and evidence requests. - Translate internal security controls into clear, customer-friendly documentation. - Maintain reusable security documentation, FAQs, and knowledge resources. - Coordinate with internal engineering, infrastructure, and security teams to validate responses and technical details. - Client Trust Operations - Help maintain scalable workflows for client security reviews, trust requests, and evidence coordination. - Track customer security commitments, follow-ups, and open questions through resolution. - Identify recurring customer concerns and partner internally on documentation or process improvements. - Support trust center, customer assurance, and compliance documentation initiatives where applicable. - Incident & Operational Support - Coordinate with internal teams on customer-facing communication during security incidents or operational disruptions. - Assist with customer-facing summaries, status updates, and post-incident follow-up materials. - Partner with Security and Infrastructure teams on remediation tracking and customer updates. - Contribute to post-incident reviews and customer-facing reporting. - Program & Process Improvement - Improve workflows for customer trust operations and security assurance. - Standardize customer response templates, security artifacts, and operational procedures. - Assist with maintaining compliance-related customer documentation. - Track trends in customer security concerns and partner internally on remediation or roadmap improvements. Qualifications - 3+ years of experience in security, GRC, compliance operations, customer trust, technical support, security operations, or related roles. - Experience supporting customer security reviews, questionnaires, audits, or evidence requests. - Strong written and verbal communication skills. - Ability to explain security and compliance concepts clearly to customers and internal stakeholders. - Strong organizational skills and ability to manage multiple customer requests at once. - Experience working cross-functionally with Sales, Legal, Product, Customer Success, Infrastructure, or Security teams. - Good judgment around sensitive information, customer communications, and security documentation. Requirements - Experience in B2B SaaS, enterprise technology, or regulated customer environments. - Familiarity with compliance frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, or similar. - Familiarity with identity providers, endpoint security, logging/monitoring, cloud security, and SaaS security concepts. - Experience supporting enterprise customers during procurement or security review processes. - Experience handling customer-facing incident communications. - Background in AI, data protection, or privacy-related security discussions. - Security or compliance certifications such as Security+, CISSP, CISA, CISM, GIAC, or equivalent are a plus.

Related Job Pages

More Security Analyst Jobs

ConnectWise logo

Security Analyst II

ConnectWise

ConnectWise is a software managed services platform designed to support technology solution providers. The unified ConnectWise platform helps clients secure cus

• The Security Analyst II is responsible for performing necessary operations activities, including assisting with the notification, identification, escalation, and remediation of security related threats and breaches. • This role works in partnership with cross-functional teams to provide timely support on threats, vulnerabilities, and exploits across the industry.

United States
Job Closed

Senior Cybersecurity Analyst

UnitedHealth Group

UnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of

Title: Senior Cybersecurity Analyst Location: Eden Prairie United States Requisition number: 2352925 Job category: Technology Primary location: Eden Prairie, MN Overtime status: Exempt Travel: No Job Description: Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. Purpose of Job: This role is an individual contributor for the Security Incident Response Team. As the team has developed into a 24/7 365 operation, we require strong individual contributors that will investigate, analyze and contain security incidents. Schedule: This role is Wednesday to Saturday 8am CST to 6pm CST If you are located in MN or DC, you will have the flexibility to work remotely* as you take on some tough challenges. Primary Responsibilities: - Critical severity security incident management - Monitor security intake technologies for reports of security incidents - Perform analysis on cybersecurity alerts in both On-Premises or Cloud environments - Provide engineering consulting and implementation expertise in support of new initiatives - Solid ability to collaborate, delegate tasks and drive deadline compliance in a highly regulated, time sensitive environment - Identify deficiencies in processes and tools, recommend security controls and/or corrective actions for mitigating technical and business risk. Contribute to Lessons Learned Meetings - Review security tools for opportunities to improve alerting for the SOC team - Produce detailed incident reports and security recommendations - Mentor analysts, providing training and guidance through complex incidents - Lead security, policy and privacy related events and incidents - Manage containment and remediation efforts of affected assets, IOCs, and TTPs - Produce detailed incident reports and security recommendations - Hold stakeholders accountable for remediation actions - Providing training and guidance through complex incidents - Integrate and collaborate with other subject matter experts throughout the organization - Liaison with Cyber Defense, Privacy, Compliance, Legal, and Architecture teams - Influence the creation and/or adoption of new standards and procedures - On-Call duties may be required You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - High School Diploma/GED (or higher) - Information Technology Industry Certification: Willingness to obtain information/cybersecurity certification within nine (9) months of hire - Advanced level of experience analyzing attack vectors, current threats, and security remediation strategies - Advanced level of experience with SIEM technologies, EDR technologies, and/or Asset isolation tools - Intermediate level of experience in public cloud platforms, including Azure, AWS, and Google Cloud Platform - Intermediate level of experience with high level familiarity of global privacy regulations (NY Cyber, GDPR, LGPD, CERT-In) - Willing or ability to work off shift hours if needed (e.g. Nights and Weekends) Preferred Qualifications: - Undergraduate degree or equivalent experience - CISSP, CISA, GCIH, CEH, CHFI, CCSP, SEC+, Net+, A+ - PowerShell, KQL, or Python scripting experience - Understanding of NIST 800-61, Cyber Kill Chain, and MITRE ATT&CK framework - Networking experience (including the OSI Model, TCP/IP, DNS, HTTP, SMTP), System Administration, and Security Architecture - Proven Spanish Language skills - 6+ years of Cyber Security Analyst experience in any of the following areas: - Security Incident Response - Email Security - Cybersecurity threat detection, monitoring and reporting - Cyber Intelligence and Threat Hunting - Vulnerability Management - All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

District Of Columbia
$91.7K - $163.7K / year
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

• The Senior IT Security Compliance Analyst provides support for technology compliance programs, including leading and executing functions and duties that may include: consulting and collaborating with business and technology stakeholders at all levels on control design and remediation to mitigate technology risks; participating on large-scale projects; maintaining IT control library/testing general computer and application controls; coordinating and supporting technology components of onsite and virtual audits/assessments, NCUA examinations, and client due diligence reviews; • Performing segregation of duties reviews and user attestations; documenting process flows and compliance-related deliverables; assisting with the creation and maintenance of IT and information security policies and standards required to maintain company certifications (e.g., PCI DSS, NIST CSF); • Coaching and cross-training technology compliance staff. The individual will execute assigned duties to meet stated priorities and SLAs. The individual plays a critical role in driving technology control and compliance practices and adoption across the company. • This role directs and advises technical SMEs in the design, implementation, monitoring and reporting of technology control and compliance processes and documentation on-premise and in the Cloud.

United States
$95.8K - $124.5K / year
American Oncology Network logo

Junior Cyber Security Analyst

American Oncology Network

Remote Position Pay Range: $25.19 - $44.31 Travel: 0-25% #LI-Remote

Full TimeRemoteTeam 1,001-5,000

Role Description The Junior IT Cyber Security Analyst assists in safeguarding the organization’s systems, data, and networks across both corporate and clinical environments. This role supports core cybersecurity operations, including: - Threat monitoring - Incident response - Vulnerability management - Compliance activities Under the direction of senior cybersecurity professionals, the position contributes foundational cybersecurity expertise while contributing to day-to-day security operations. The Junior Analyst helps maintain and strengthen the organization’s overall security posture through active participation in monitoring, analysis, and risk mitigation efforts. Key Performance Areas - KPA 1 – Threat Monitoring & Initial Response (Support Role) - Monitor security alerts from SIEM, EDR, email security, and network tools. - Perform initial triage and escalate suspicious activity to senior analysts. - Follow established incident response playbooks for basic investigations. - Document incidents, actions taken, and outcomes. - KPA 2 – Vulnerability & Patch Support - Assist with vulnerability scans and review scan results. - Track remediation progress and follow up with system owners. - Support patching efforts by validating updates and documenting status. - Help maintain asset and vulnerability inventories. - KPA 3 – Compliance & Documentation - Support collection of evidence for audits (HIPAA, SOC 2, etc.). - Maintain documentation for policies, procedures, and controls. - Assist with periodic access reviews and data protection checks. - Help track remediation of audit findings. - KPA 4 – Cyber Awareness, Training, and Culture - Assist in coordinating phishing simulations and training campaigns. - Help distribute cybersecurity communications (e.g., tips, alerts). - Promote secure behaviors across staff through basic guidance. - Support onboarding security training for new employees. - KPA 5 – Clinic Onboarding and Operational Support - Assist senior analysts with clinic onboarding security tasks. - Support inventory collection (devices, users, systems). - Help validate baseline security controls during integrations. - Participate in remote or occasional on-site support activities. - KPA 6 – Learning & Continuous Improvement - Participate in cybersecurity projects and tool implementations. - Develop knowledge of security technologies and best practices. - Track and report basic metrics (e.g., ticket resolution, alert volumes). - Continuously improve technical and analytical skills. Qualifications - Associate or Bachelor’s degree in Information Technology, Cybersecurity, or related field (or equivalent experience). - High school education required. - 0–2 years of IT or cybersecurity-related experience. - Internship, lab, or hands-on training experience preferred. - CompTIA Security+ (or actively pursuing). - Other entry-level certifications (e.g., Network+, ISC2 CC). Requirements - Analytical & Problem-Solving: Applies foundational analysis to investigate alerts, review data, and identify issues; follows established processes with attention to detail and appropriate escalation. - Interpersonal Effectiveness: Communicates professionally, builds collaborative relationships, maintains confidentiality, and responds constructively to feedback. - Communication: Demonstrates clear written and verbal communication; documents incidents and findings effectively; conveys basic technical information to non-technical audiences. - Customer Focus & Organizational Awareness: Supports internal users and clinical staff with a service-oriented approach; aligns work with organizational priorities and healthcare standards. - Self-Management & Accountability: Manages time and priorities effectively; demonstrates reliability, initiative, and adaptability in a structured environment. - Adaptability: Thrives in a fast-paced, multi-site healthcare setting; manages competing priorities and collaborates across distributed teams. - Technical Proficiency: Proficient in Microsoft Office (Word, Excel, PowerPoint, Outlook); able to learn and utilize cybersecurity tools (e.g., SIEM, EDR, vulnerability scanners) with training. Benefits - Flexible hours - Ergonomic home office guidance - Communication software accessibility

United States
$52.4K - $92.2K / year
Job Closed