Our mission: to be the leader in improving child health.
Information Security Analyst II
Location
United States
Posted
5 days ago
Salary
$74.3K - $94.7K / year
Seniority
Mid Level
Job Description
Information Security Analyst II
Cincinnati Children's
• Participate in the design, development, and implementation of systems to protect CCHMC data. • Identify the appropriate resources needed to complete small projects. • Support the communication between internal and external parties on project related issues and developments. • Participate in developing and managing project plans. • Determine the scope and complexity of small to midsized projects. • Work with cross functional teams. • Understand incident response processes and procedures and assist in mitigating incidents when they occur. • Analyze, design, implement, and maintain moderately complex systems that greatly improves clinical care and patient management. • Support system testing. • Document testing outcomes. • Work to develop technical solutions. • Work to design, write, and prepare complete user and technical documentation. • Analyze existing documentation and provide corrections and enhancement. • Utilize Development lifecycle process, operating procedures and documentation to implement and support system solutions. • Provide technical support and problem resolution assistance for production and process issues. • Troubleshoot and decipher error messages. • Identify required resources to resolve minor to midsized issues. • Utilize appropriate Change Control methods to implement system solutions. • Serve as a resource person for and as a liaison between Cincinnati Children's departments and Information Services. • Support departmental efforts to improve customer satisfaction. • Evaluate and monitor system performance and functionality to avoid potential issues as well as gathering information for future development needs or feasibility studies. • Participate in on-call support rotation and handle incident resolution, problem determination and resolution during that time. • Ensure outstanding end-user support is provided, including ongoing monitoring of Service Level Agreements for incident management and collaboration with other areas to ensure customer-centered incident management and support. • Adhere to and promote continual adoption of change management policies and procedures. • Model outstanding customer service behavior, including timely and effective follow-up with customers. • Develop knowledge and professional skills through cross-training, literature and attendance at department meetings and vendor education. • Develop and maintain positive relationships, both internal and external to CCHMC. • Motivate people and encourage teamwork. • Work well with others and fosters a positive team environment. • Prepare oral and written presentations. • Conduct and participate in instructional seminars. • Develop expertise in several Cincinnati Children's computer-based systems.
Job Requirements
- Bachelor's degree OR equivalent combination of education and experience
- 2+ years of work experience in a related job discipline
- Experience supporting cybersecurity operations within a healthcare, hospital, or highly regulated environment.
- Experience with security incident response, threat detection, and vulnerability management processes.
- Experience working with enterprise security tools such as SIEM, endpoint protection, vulnerability scanning, identity and access management, or email security platforms.
- Experience with CrowdStrike Falcon or comparable endpoint detection and response (EDR) platforms.
- Familiarity with cybersecurity frameworks and standards such as NIST, HIPAA, CIS Controls, or HITRUST.
- Experience supporting cloud security initiatives in Microsoft Azure, AWS, or hybrid environments.
- Experience reviewing and analyzing system logs, alerts, and security events to identify potential threats or vulnerabilities.
- Experience with Active Directory, multi-factor authentication, privileged access management, or identity governance solutions.
- Knowledge of networking concepts, firewalls, VPN technologies, and secure system configurations.
- Experience participating in security audits, risk assessments, or compliance initiatives.
- Experience utilizing scripting or automation tools such as PowerShell, Python, or Bash to improve operational efficiency.
- Strong written and verbal communication skills with the ability to explain technical concepts to non-technical audiences.
- Demonstrated ability to work collaboratively across technical, operational, and clinical teams.
- Relevant industry certifications preferred, such as Security+, CISSP, GSEC, CEH, GIAC, SC-900, AZ-500, or similar cybersecurity certifications.
- Experience supporting on-call rotations and responding to critical security incidents in a fast-paced environment.
- Experience with change management, documentation standards, and secure system implementation practices.
Benefits
- Comprehensive job description provided upon request
- Health insurance
- Flexible work hours
- Professional development opportunities
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Security Analyst II
ConnectWiseConnectWise is a software managed services platform designed to support technology solution providers. The unified ConnectWise platform helps clients secure customers, manage busin
• The Security Analyst II is responsible for performing necessary operations activities, including assisting with the notification, identification, escalation, and remediation of security related threats and breaches. • This role works in partnership with cross-functional teams to provide timely support on threats, vulnerabilities, and exploits across the industry.
Senior Cybersecurity Analyst
UnitedHealth GroupUnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of
Title: Senior Cybersecurity Analyst Location: Eden Prairie United States Requisition number: 2352925 Job category: Technology Primary location: Eden Prairie, MN Overtime status: Exempt Travel: No Job Description: Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. Purpose of Job: This role is an individual contributor for the Security Incident Response Team. As the team has developed into a 24/7 365 operation, we require strong individual contributors that will investigate, analyze and contain security incidents. Schedule: This role is Wednesday to Saturday 8am CST to 6pm CST If you are located in MN or DC, you will have the flexibility to work remotely* as you take on some tough challenges. Primary Responsibilities: - Critical severity security incident management - Monitor security intake technologies for reports of security incidents - Perform analysis on cybersecurity alerts in both On-Premises or Cloud environments - Provide engineering consulting and implementation expertise in support of new initiatives - Solid ability to collaborate, delegate tasks and drive deadline compliance in a highly regulated, time sensitive environment - Identify deficiencies in processes and tools, recommend security controls and/or corrective actions for mitigating technical and business risk. Contribute to Lessons Learned Meetings - Review security tools for opportunities to improve alerting for the SOC team - Produce detailed incident reports and security recommendations - Mentor analysts, providing training and guidance through complex incidents - Lead security, policy and privacy related events and incidents - Manage containment and remediation efforts of affected assets, IOCs, and TTPs - Produce detailed incident reports and security recommendations - Hold stakeholders accountable for remediation actions - Providing training and guidance through complex incidents - Integrate and collaborate with other subject matter experts throughout the organization - Liaison with Cyber Defense, Privacy, Compliance, Legal, and Architecture teams - Influence the creation and/or adoption of new standards and procedures - On-Call duties may be required You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - High School Diploma/GED (or higher) - Information Technology Industry Certification: Willingness to obtain information/cybersecurity certification within nine (9) months of hire - Advanced level of experience analyzing attack vectors, current threats, and security remediation strategies - Advanced level of experience with SIEM technologies, EDR technologies, and/or Asset isolation tools - Intermediate level of experience in public cloud platforms, including Azure, AWS, and Google Cloud Platform - Intermediate level of experience with high level familiarity of global privacy regulations (NY Cyber, GDPR, LGPD, CERT-In) - Willing or ability to work off shift hours if needed (e.g. Nights and Weekends) Preferred Qualifications: - Undergraduate degree or equivalent experience - CISSP, CISA, GCIH, CEH, CHFI, CCSP, SEC+, Net+, A+ - PowerShell, KQL, or Python scripting experience - Understanding of NIST 800-61, Cyber Kill Chain, and MITRE ATT&CK framework - Networking experience (including the OSI Model, TCP/IP, DNS, HTTP, SMTP), System Administration, and Security Architecture - Proven Spanish Language skills - 6+ years of Cyber Security Analyst experience in any of the following areas: - Security Incident Response - Email Security - Cybersecurity threat detection, monitoring and reporting - Cyber Intelligence and Threat Hunting - Vulnerability Management - All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.
• The Senior IT Security Compliance Analyst provides support for technology compliance programs, including leading and executing functions and duties that may include: consulting and collaborating with business and technology stakeholders at all levels on control design and remediation to mitigate technology risks; participating on large-scale projects; maintaining IT control library/testing general computer and application controls; coordinating and supporting technology components of onsite and virtual audits/assessments, NCUA examinations, and client due diligence reviews; • Performing segregation of duties reviews and user attestations; documenting process flows and compliance-related deliverables; assisting with the creation and maintenance of IT and information security policies and standards required to maintain company certifications (e.g., PCI DSS, NIST CSF); • Coaching and cross-training technology compliance staff. The individual will execute assigned duties to meet stated priorities and SLAs. The individual plays a critical role in driving technology control and compliance practices and adoption across the company. • This role directs and advises technical SMEs in the design, implementation, monitoring and reporting of technology control and compliance processes and documentation on-premise and in the Cloud.
Junior Cyber Security Analyst
American Oncology NetworkRemote Position Pay Range: $25.19 - $44.31 Travel: 0-25% #LI-Remote
Role Description The Junior IT Cyber Security Analyst assists in safeguarding the organization’s systems, data, and networks across both corporate and clinical environments. This role supports core cybersecurity operations, including: - Threat monitoring - Incident response - Vulnerability management - Compliance activities Under the direction of senior cybersecurity professionals, the position contributes foundational cybersecurity expertise while contributing to day-to-day security operations. The Junior Analyst helps maintain and strengthen the organization’s overall security posture through active participation in monitoring, analysis, and risk mitigation efforts. Key Performance Areas - KPA 1 – Threat Monitoring & Initial Response (Support Role) - Monitor security alerts from SIEM, EDR, email security, and network tools. - Perform initial triage and escalate suspicious activity to senior analysts. - Follow established incident response playbooks for basic investigations. - Document incidents, actions taken, and outcomes. - KPA 2 – Vulnerability & Patch Support - Assist with vulnerability scans and review scan results. - Track remediation progress and follow up with system owners. - Support patching efforts by validating updates and documenting status. - Help maintain asset and vulnerability inventories. - KPA 3 – Compliance & Documentation - Support collection of evidence for audits (HIPAA, SOC 2, etc.). - Maintain documentation for policies, procedures, and controls. - Assist with periodic access reviews and data protection checks. - Help track remediation of audit findings. - KPA 4 – Cyber Awareness, Training, and Culture - Assist in coordinating phishing simulations and training campaigns. - Help distribute cybersecurity communications (e.g., tips, alerts). - Promote secure behaviors across staff through basic guidance. - Support onboarding security training for new employees. - KPA 5 – Clinic Onboarding and Operational Support - Assist senior analysts with clinic onboarding security tasks. - Support inventory collection (devices, users, systems). - Help validate baseline security controls during integrations. - Participate in remote or occasional on-site support activities. - KPA 6 – Learning & Continuous Improvement - Participate in cybersecurity projects and tool implementations. - Develop knowledge of security technologies and best practices. - Track and report basic metrics (e.g., ticket resolution, alert volumes). - Continuously improve technical and analytical skills. Qualifications - Associate or Bachelor’s degree in Information Technology, Cybersecurity, or related field (or equivalent experience). - High school education required. - 0–2 years of IT or cybersecurity-related experience. - Internship, lab, or hands-on training experience preferred. - CompTIA Security+ (or actively pursuing). - Other entry-level certifications (e.g., Network+, ISC2 CC). Requirements - Analytical & Problem-Solving: Applies foundational analysis to investigate alerts, review data, and identify issues; follows established processes with attention to detail and appropriate escalation. - Interpersonal Effectiveness: Communicates professionally, builds collaborative relationships, maintains confidentiality, and responds constructively to feedback. - Communication: Demonstrates clear written and verbal communication; documents incidents and findings effectively; conveys basic technical information to non-technical audiences. - Customer Focus & Organizational Awareness: Supports internal users and clinical staff with a service-oriented approach; aligns work with organizational priorities and healthcare standards. - Self-Management & Accountability: Manages time and priorities effectively; demonstrates reliability, initiative, and adaptability in a structured environment. - Adaptability: Thrives in a fast-paced, multi-site healthcare setting; manages competing priorities and collaborates across distributed teams. - Technical Proficiency: Proficient in Microsoft Office (Word, Excel, PowerPoint, Outlook); able to learn and utilize cybersecurity tools (e.g., SIEM, EDR, vulnerability scanners) with training. Benefits - Flexible hours - Ergonomic home office guidance - Communication software accessibility


