Job Closed
This listing is no longer active.
Founded in 1980, BMC Software is a privately-held, business-to-business (B2B) software firm serving companies in the healthcare, financial services, retail, tel
Senior Cybersecurity Analyst
Location
United States
Posted
4 days ago
Salary
$89.5K - $130K / year
Seniority
Senior
Job Description
Senior Cybersecurity Analyst
BMC Software
Role Description The Senior Cybersecurity Analyst (Governance, Risk, and Compliance) plays an important role in building and maturing Boston Medical Center Health System’s GRC program. This role will be key to developing and improving human-driven processes before enterprise tooling is in place, and will make that work visible, auditable, and ready to scale. - Lead execution of GRC program initiatives, contributing design input on processes, workflows, and work products as the program matures toward enterprise tooling adoption. - Maintain and operationalize risk registers, control frameworks, and maturity assessments aligned to NIST CSF 2.0, HIPAA/HITECH, and applicable federal and state security and privacy regulations. - Drive compliance monitoring activities and recommend updates to security policies, standards, and procedures that balance regulatory rigor with operational practicality. - Coordinate the third-party risk management process, including vendor risk assessments and ongoing vendor risk workflows. - Apply risk scoring methodologies to support framework maturity tracking and quantified risk metrics, incorporating business continuity and disaster recovery considerations. - Manage structured GRC work products in spreadsheet and document-based environments (e.g., Excel, SharePoint), keeping them accurate, accessible, and audit-ready on an ongoing basis. - Translate technical findings into clear, actionable written and verbal reporting for executive and non-technical audiences. - Partner with stakeholders across IT and non-IT business functions to advance new standards and workflows, influencing adoption without direct authority. - Prioritize multiple concurrent workstreams to deliver accurate results on schedule in a fast-paced, evolving environment. Qualifications - Bachelor's degree in Cybersecurity, Computer Science, Information Management, or a related field preferred. - A minimum of six years of experience in information security or related discipline, with a strong focus on governance, risk, and compliance programs in complex or regulated environments. - Or equivalent combination of education and experience. - Demonstrated experience building or significantly maturing a GRC function, including the design of processes and workflows prior to enterprise tooling adoption. Requirements - Professional certifications such as CISA, CRISC, CISSP, or equivalent are highly desirable. - Demonstrated experience in data mining, analysis and report development required. - Strong knowledge of information systems security concepts and current information security/privacy trends and practices. - Knowledge of Federal and State security and privacy-related regulatory requirements. - Excellent written and oral communication skills, interpersonal skills, and effective leadership skills to support privacy programs. - Must be able to prepare formal reports and presentations as needed. - Must be detail-oriented and possess the ability to prioritize tasks so work is completed in an accurate, timely manner. - Strong business and technical skills in the planning, administration, and management of information systems, operational and technical security controls; and security risk analysis and management. - Self-starter with the ability to work independently, prioritize, multi-task, and maintain flexibility in fast-paced, changing environment. - Ability to confront conflict and difficult issues in a professional, assertive, and proactive manner. - Ability to build strong working relationships at all levels, internal and/or external to the organization. - Knowledge about medical records and other medical information, patient privacy and confidentiality, and release of information. Academic medical center and/or health care consulting experience preferred. Benefits - Compensation Range: $89,500.00 - $130,000.00 - Generous total compensation that includes benefits (medical, dental, vision, pharmacy). - Discretionary annual bonuses and merit increases. - Flexible Spending Accounts. - 403(b) savings matches. - Paid time off. - Career advancement opportunities. - Resources to support employee and family well-being.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Security Analyst
DarkshieldDarkshield is an expert cybersecurity agency based in York, UK. We help organisations navigate an increasingly complex digital landscape by providing expert services in penetration testing, vulnerability assessment, managed security, and more. Our mission is to protect businesses by delivering tailored, cutting-edge cybersecurity solutions that keep them resilient and ahead of cyber threats.
Role Description We are seeking a Security Analyst to join our team and play a key role in threat detection, incident response, and security monitoring. The ideal candidate will have a strong analytical mindset, an understanding of cyber threats and attack techniques, and the ability to implement effective security controls to mitigate risks. This role involves proactively monitoring security events, investigating potential breaches, and supporting clients with vulnerability management and security best practices. Key Responsibilities - Threat Detection & Security Monitoring - Continuously monitor SIEM, IDS/IPS, firewalls, and endpoint security tools to identify suspicious activity. - Analyze and correlate security alerts to detect potential cyber threats and data breaches. - Perform log analysis and anomaly detection to identify patterns indicative of compromise. - Incident Response & Threat Investigation - Investigate security incidents, phishing attempts, malware infections, and unauthorized access events. - Develop and implement remediation strategies to mitigate security risks. - Conduct digital forensics and root cause analysis on security breaches. - Work closely with internal teams and clients to ensure swift containment and resolution of threats. - Vulnerability Management & Security Operations - Perform regular vulnerability scans and assessments, identifying security gaps and misconfigurations. - Recommend and implement security improvements based on assessment findings. - Optimize security configurations and policies across cloud and on-premise environments. - Assist in security patch management and tracking remediation efforts. - Security Policy & Awareness - Assist in the development and enforcement of security policies, procedures, and best practices. - Provide security awareness training to employees and clients to mitigate human-related risks. - Stay informed on emerging cyber threats, attack techniques, and security technologies. Qualifications - Experience in security monitoring, threat detection, or incident response. - Strong understanding of security tools including SIEM, IDS/IPS, firewalls, and endpoint security platforms. - Familiarity with log analysis, malware analysis, and digital forensics techniques. - Knowledge of threat intelligence platforms and cyber threat hunting techniques. - Experience with vulnerability assessment tools such as Nessus, Qualys, or OpenVAS. - Understanding of network security, cloud security, and endpoint protection. Requirements - Scripting & Automation (Preferred, Not Required) - Basic proficiency in Python, PowerShell, or Bash for security automation. - Ability to write scripts for log analysis, threat hunting, or security automation is a plus. - Certifications (Preferred, Not Required) - CompTIA Security+, CEH (Certified Ethical Hacker), GCIH (GIAC Certified Incident Handler), or similar certifications are desirable. - Soft Skills & Work Environment - Strong problem-solving skills and ability to think like an attacker. - Ability to work both independently and collaboratively within a security team. - Effective communication and reporting skills to convey security findings to technical and non-technical stakeholders. - Strong attention to detail with a methodical approach to security investigations. - A passion for learning and keeping up with the latest security threats and technologies. Benefits - Work on real-world cybersecurity threats and gain experience in high-impact security operations. - Opportunity to develop and implement security controls across various industries. - Career growth opportunities in a fast-growing cybersecurity agency. - Flexible work environment – remote and hybrid options available. - Competitive salary and performance-based incentives.
• Conduct risk assessments of vendors and third-party partners. • Evaluate security controls implemented by third parties and identify potential vulnerabilities. • Ensure adherence to corporate information security and risk management policies. • Identify, document and track mitigation plans for identified risks. • Collaborate with the GRC team in managing information security risks. • Review evidence, certifications and compliance attestations from vendors. • Assess alignment with industry frameworks and best practices, including NIST. • Support the implementation and monitoring of security controls. • Participate in contract reviews between the company and vendors, ensuring information security requirements are included and followed. • Work closely with Legal and Procurement teams to mitigate contractual risks related to security. • Prepare executive reports and technical opinions on identified risks. • Present assessment results to business areas, managers and stakeholders. • Support risk-based decision making by providing mitigation recommendations. • Assist with concurrent investigations of security incidents. • Contribute to threat and vulnerability monitoring activities. • Produce incident reports and support senior teams in the analysis and remediation of occurrences.
Information Security Analyst
Cresol CooperativaFornecendo soluções financeiras com excelência por meio do relacionamento.
• Incident Management: Lead the incident response lifecycle (preparation, identification, containment, eradication, and recovery). • Forensic Analysis: Perform digital forensics on hosts (Windows/Linux/iOS/Android), memory, networks, and cloud environments to identify the root cause of compromises. • Advanced Monitoring: Work together with the SOC/Support team to triage high-complexity alerts in XDR/SIEM and NDR tools. • Threat Hunting: Conduct proactive searches for threats that may have bypassed existing security controls. • Documentation and Reporting: Produce detailed technical reports and forensic findings to support executive decision-making and regulatory compliance (Bacen/LGPD). • Continuous Improvement: Recommend adjustments to detection rules and security policies based on the tactics (TTPs) observed during investigations.
• Monitor and analyze security events utilizing Splunk Enterprise Security (ES). • Build, maintain, and tune Splunk searches, correlation rules, alerts, and dashboards. • Conduct incident response activities from detection through containment, eradication, recovery, and closure. • Investigate endpoint security incidents utilizing Microsoft Defender for Endpoint. • Perform endpoint policy management and incident investigations. • Assess AWS cloud security telemetry utilizing GuardDuty, Security Hub, and related cloud security services. • Identify threats, vulnerabilities, suspicious activity, and cloud misconfigurations. • Execute alert triage, incident scoping, and escalation activities according to established playbooks. • Recommend updates and improvements to operational procedures and incident response playbooks. • Support threat hunting activities and detection engineering initiatives aligned to MITRE ATT&CK methodologies. • Perform phishing investigations, alert enrichment, and forensic review activities. • Conduct root cause analysis and document corrective actions following security incidents. • Track incidents and operational tasks utilizing case management systems. • Participate in tabletop exercises and operational readiness activities. • Collaborate with Security Operations teams, Incident Response personnel, and federal stakeholders. • Prepare reports and communicate findings to technical and non-technical audiences. • Perform other job-related duties as assigned.



