S&S Health logo
S&S Health

Your health. Your way.

Senior Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 51-200Since 1994H1B No SponsorCompany SiteLinkedIn

Location

Ohio

Posted

4 days ago

Salary

$120K - $140K / year

Seniority

Senior

Bachelor DegreeEnglishCyber SecuritySplunk

Job Description

Senior Security Analyst

S&S Health

• Review, investigate, and adjudicate security incidents escalated from the Security Operations Center (SOC), including triage, root cause analysis, containment, remediation, and post-incident review while partnering with the SOC to improve detection logic, escalation workflows, and operational effectiveness • Drive the vulnerability management lifecycle through identification, risk-based prioritization, remediation tracking, and reporting while coordinating penetration testing activities, supporting remediation efforts, and performing application security assessments and reviews • Partner with engineering teams to identify, prioritize, and remediate security risks across production environments while contributing to secure configuration standards, monitoring coverage, security best practices, and the protection of AI-enabled workloads • Support the ongoing maturation of the security program by improving security tools, processes, and operational capabilities while recommending enhancements that strengthen the organization's overall security posture • Ensure complete and reliable collection of security logs and telemetry into the SIEM while supporting security data architecture decisions, onboarding new data sources, validating monitoring coverage, and identifying visibility gaps across systems and environments • Support internal and external audits, including HITRUST, SOC 2, client assessments, and regulatory reviews while coordinating evidence collection, tracking remediation activities, conducting third-party risk assessments, maintaining risk registers, and supporting ongoing audit readiness • Develop, analyze, and present security and risk metrics, KPIs, KRIs, dashboards, and executive-level reporting that translate technical findings into meaningful business insights and support organizational decision-making • Partner with engineering, infrastructure, operations, compliance, risk management, and business stakeholders to support security initiatives, policy and control mapping efforts, risk remediation activities, and strategic security projects

Job Requirements

  • Proven experience in Information Security, Cybersecurity, Security Operations, Governance Risk & Compliance (GRC), ideally within the healthcare or TPA industry
  • Hands-on experience with incident response, vulnerability management, penetration testing coordination, application security reviews, and security operations processes
  • Experience working with SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, or similar security monitoring and analytics technologies
  • Experience supporting security audits, assessments, and compliance frameworks including HITRUST, SOC 2, NIST, HIPAA, ISO 27001, or related standards
  • Demonstrated experience conducting third-party and vendor risk assessments, maintaining risk registers, and supporting enterprise risk management initiatives
  • Strong analytical, reporting, and problem-solving abilities with experience translating technical findings into actionable risk assessments and business recommendations
  • Excellent verbal and written communication skills with the ability to collaborate effectively across technical and non-technical teams and present information to executive leadership.

Related Job Pages

More Security Analyst Jobs

GEHA Health logo

Continuity & Security Assurance Analyst

GEHA Health

G.E.H.A (Government Employees Health Association, Inc) is a nonprofit member association that provides medical and dental benefits to more than two million federal employees and retirees, military retirees, and their families. We celebrate diversity and are committed to creating an inclusive environment for all employees. G.E.H.A has one mission: To empower federal workers to be healthy and well. We serve our members with products they value and a personalized customer experience, sustained by a nimble and efficient organization.

Full TimeRemoteTeam 1,001-5,000

Role Description The Continuity and Security Assurance Analyst supports G.E.H.A’s Cybersecurity and Information Protection (CIP) program by executing security, compliance, and business continuity initiatives. This role is responsible for: - Assessing controls - Monitoring compliance with regulatory and internal standards - Supporting audit activities - Contributing to the resilience and security posture of G.E.H.A’s systems, data, and third-party relationships Qualifications - Bachelor’s degree in Computer Science, Information Systems, or a related discipline - Three (3) or more years of experience in Information Technology, Information Security, IT Assurance, Risk Management, Governance, or Business Continuity - Equivalent combinations of education and additional experience may be considered in lieu of formal degree or certification requirements - One or more industry certifications such as: CISSP, HCISPP, CRMA, CGEIT, CRISC, CISM, CISA, CBCP, GIAC, or similar governance, risk, security, or BCDR certifications Requirements - Working knowledge of governance, risk, and compliance frameworks such as: COSO, COBIT, ITIL, ISO 31000, ISO 27002, ISO 22301, NIST CSF, NIST 800‑53, and SANS Critical Security Controls - Experience with enterprise Governance, Risk, and Compliance (GRC) platforms (e.g., Archer, MetricStream, LockPath, etc.) - Proficiency with Microsoft Office applications - Strong analytical and problem-solving skills with the ability to identify risk and recommend practical solutions - Effective written and verbal communication skills, including the ability to translate technical risks into business-focused language - Ability to build relationships, influence stakeholders, and collaborate across multiple business units and teams - Strong organizational skills with the ability to manage multiple priorities in a fast-paced environment - Customer service orientation with a focus on delivering high-quality, accurate outcomes - Effective presentation and interpersonal skills Benefits - Competitive pay/salary ranges - Incentive plan - Health/Vision/Dental benefits effective day one - 401(k) retirement plan: company match – dollar for dollar up to 4% employee contribution (pretax or Roth options) plus a 6% annual company contribution - Robust employee well-being program - Paid Time Off - Personal Community Enrichment Time - Company-provided Basic Life and AD&D - Company-provided Short-Term & Long-Term Disability - Tuition Assistance Program

United States
$75.9K - $106.9K / year

Senior Physical Red Team Security Analyst

UnitedHealth Group

UnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of

Title: Senior Physical Red Team Security Analyst Location: Remote United States Requisition number: 2354040 Job category: Technology Travel: Yes, 50 % of the Time Job Description: Optum is a global organization that delivers care, aided by technology, to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together. We are seeking a highly skilled and resourceful offensive security assessment member to join our Physical Red Team. In this role, you will simulate real-world adversaries to evaluate and improve the physical security posture of our facilities, personnel, and processes. You will plan and execute covert operations-such as facility penetration, surveillance, and social engineering-and provide detailed reporting to help strengthen defenses against sophisticated threats. You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. Primary Responsibilities: - Conduct physical security assessments of facilities by attempting to bypass locks, alarms, access controls, and security personnel - Perform covert entry operations including reconnaissance, surveillance, and red team exercises - Test human-factor vulnerabilities through social engineering, impersonation, or tailgating - Conduct intelligence (OSINT, HUMINT, SIGINT) collection on facilities, personnel, and businesses - Design, source, build, and deploy physical and technological offensive security tools - Create and communicate risk-profiles for executive members - Document findings with accurate reporting, photography, and after-action reviews, including remediation recommendations - Collaborate with cybersecurity, corporate security, and defensive security teams to ensure findings are integrated into broader risk management strategies - Maintain strict compliance with legal, ethical, and safety guidelines during all engagements - Stay current with emerging tools, techniques, and threat actor behaviors relevant to physical security testing - Effectively communicate successes and obstacles with fellow team members and team lead(s) - Create written reports, detailing assessment findings and recommendations - Interface with customer contact(s) and staff in a constructive and professional manner - Have subject matter expertise in advanced testing specialties: containerization, automation, wireless/IoT, exploit development, hardware, radio frequency, reconnaissance procedures - Ethically operate with appreciable latitude in developing methodology and applying it in the field - Research and analyze adversary methodologies and develop testing models to mimic adversaries - Ability to communicate clearly and effectively through oral or written communication with all levels in the organization - Ability to initiate, design, execute, complete, and provide metrics on projects with minimal direction - Drive cross-team efforts to address systemic risks across the business - Conduct business/risk portfolio research and test planning work that encompasses holistic testing efforts You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - High School Diploma/GED (or higher) - 6 + years of experience in demonstrable ability to think critically and creatively to solve complex problems with limited to no guidance - 6 + years of experience in time operating within a team which produced superior results to bring increased value and proficiency to an organization - 4+ years of experience conducting risk assessments, identifying and implementing controls, and adhering to safety, legal, ethical, and moral rules and guidelines - 3+ years of in-depth experience in physical red team assessments and reporting - 3+ years of demonstrable experience deploying RF detection, monitoring, baselining, and alerting tools - 3+ years of experience with intelligence gathering and sorting (HUMINT, OSINT, SIGINT, etc.) used in cohesive reports on action operations - 3+ years of demonstrable coding experience and capabilities - 3+ years of demonstrable experience in ability to design, source, build, and deploy various offensive security tools (wireless detection, SDR, drone, surveillance), both hardware and software - 3+ years of hands-on experience with assessment and exploitation tools including: - Software-defined radios - RFID scanners - WiFi Pineapple - RaspberryPi - Directional antennas - 2+ years of hands-on experience with assessment and exploitation tools including: - Kali, Burp, Cobalt Strike, and Metasploit - Malware development - Technology C2 infrastructure - CCTV (NVR, DVR) exploitation - Ability to travel up to 50% of the time; including outside the United States Preferred Qualification: - Physical Red Team certification (CCRTS, PSP, CEE, etc.) - Offensive security certification (GPEN, OSCP, CRT) - Law enforcement, military, or private/government security experience - Ham radio license - FAA Part 107 drone license - Located in Minneapolis/St. Paul, MN - All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment. #RPO #GREEN

United States
$91.7K - $163.7K / year
Booz Allen Hamilton logo

Cyber Security Analyst

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

ISSO and Cyber Security Analyst Location: San Antonio United States Full time Job Description: The Opportunity: Provide expert information security support for an Air Force contract, ensuring compliance with Department of Defense standards and maintaining a secure operational environment. Leverage analytical skills, deep technical knowledge, and the ability to communicate effectively with both technical and non-technical stakeholders. Design, implement, and manage policies and procedures to ensure database and software security. You Have: - 6+ years of experience in cyber security or information assurance - Secret clearance - Bachelor's degree in a Computer Science, Cyber Security, or Information Technology field - DoD 8570.01-M IAT II certification, such as Security+, CCNA Security, or GSEC Nice If You Have: - Experience supporting Air Force or other DoD contracts - Experience with NIST RMF, DIACAP, and FISMA compliance frameworks - Experience with STIGs and security hardening of systems - Experience with incident response and digital forensics - Knowledge of vulnerability assessment tools such as Nessus or Qualys - Knowledge of cloud security such as AWS, Azure or DoD Cloud - Ability to lead security audits and assessments - Possession of strong documentation and technical writing skills - Advanced certifications such as CISSP, CASP+, or CEH Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $77,500.00 to $176,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Texas
$77.5K - $176K / year

Associate Security Analyst

Hornblower Group Inc.

Hornblower Group is a global leader in experience and transportation. Spanning a 100-year history, Hornblower Group’s portfolio of international offerings includes water- and land-based experiences and ferry and transportation services. City Experiences, Hornblower Group’s premier experience division, offers dining and sightseeing cruises and walking and food tours through the City Cruises, Walks, and Devour brands. City Ferry, part of Hornblower Group’s Ferry and Transportation Division, is the largest private operator of high-speed passenger and vehicle ferries in the United States, carrying more than 10 million passengers annually. Hornblower Group’s subsidiaries include Hornblower Marine, which provides vessel outhaul and maintenance services, and Seaward Services, Inc., a full-service shipping, waterfront logistics, and management company. Anchor Operating System, LLC, provides reservation, ticketing, and website integration services for clients in the transportation, tourism, and entertainment industries. Hornblower Group’s global portfolio covers over 10 countries, over 50 U.S. cities, and serves more than 20 million guests annually. Headquartered in Orlando, Florida, with additional corporate offices in various locations including San Francisco, Boston, Chicago, London, New York, Dublin, and Ontario.

Role Description Cybersecurity at Hornblower is responsible for protecting the business. We do so by establishing, maintaining, and enforcing policies to meet and exceed industry standards for security and compliance. We are seeking a motivated Junior Security Analyst to join our information security team. In this role, you will help defend our organization against cyber threats by: - Monitoring security tools - Investigating alerts - Supporting incident response efforts This is an excellent opportunity for an early-career professional to develop hands-on experience across a broad range of security disciplines while working alongside experienced practitioners. Responsibilities - Monitor security information and event management (SIEM) platforms, intrusion detection systems, and other security tools for suspicious activity. - Triage and investigate security alerts, escalating confirmed incidents to senior analysts according to established playbooks. - Assist in incident response activities, including evidence collection, containment, and post-incident documentation. - Conduct regular vulnerability scans and help track remediation efforts with system owners. - Review logs from firewalls, endpoint protection, identity providers, and cloud platforms to identify anomalies. - Support phishing investigations, including analysis of suspicious emails, URLs, and attachments in a sandboxed environment. - Contribute to the maintenance of security documentation, runbooks, and knowledge base articles. - Assist with user access reviews, security awareness initiatives, and routine compliance tasks. - Stay current on emerging threats, vulnerabilities, and attacker techniques, sharing relevant findings with the team. Qualifications - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field — or equivalent practical experience (internships, home labs, military, or self-directed study). - Foundational understanding of networking concepts (TCP/IP, DNS, HTTP/S, VPNs) and common operating systems (Windows and Linux). - Familiarity with core security concepts: the CIA triad, common attack types (phishing, malware, brute force, privilege escalation), and basic defensive controls. - Hands-on exposure to SIEM platforms (Microsoft Sentinel, Elastic, etc.), EDR tools, or vulnerability scanners. - Basic scripting ability in Python, PowerShell, or Bash for log parsing or task automation. - Familiarity with frameworks such as MITRE ATT&CK, NIST CSF, or the Cyber Kill Chain. - Experience with cloud environments (AWS, Azure, or Google Cloud) and their native security services. - Strong analytical and problem-solving skills, with attention to detail. - Clear written and verbal communication, including the ability to document findings for both technical and non-technical audiences. - Eagerness to learn and a methodical, curious approach to investigation. Requirements - None specified. Benefits - None specified. Company Description Hornblower Group is a global leader in experience and transportation. Spanning a 100-year history, Hornblower Group’s portfolio of international offerings includes water- and land-based experiences and ferry and transportation services. - City Experiences, Hornblower Group’s premier experience division, offers dining and sightseeing cruises and walking and food tours through the City Cruises, Walks, and Devour brands. - City Ferry, part of Hornblower Group’s Ferry and Transportation Division, is the largest private operator of high-speed passenger and vehicle ferries in the United States, carrying more than 10 million passengers annually. - Hornblower Group’s subsidiaries include Hornblower Marine, which provides vessel outhaul and maintenance services, and Seaward Services, Inc., a full-service shipping, waterfront logistics, and management company. - Anchor Operating System, LLC, provides reservation, ticketing, and website integration services for clients in the transportation, tourism, and entertainment industries. - Hornblower Group’s global portfolio covers over 10 countries, over 50 U.S. cities, and serves more than 20 million guests annually. - Headquartered in Orlando, Florida, with additional corporate offices in various locations including San Francisco, Boston, Chicago, London, New York, Dublin, and Ontario.

United States
Job Closed