Cyber Security Analyst II - Incident Response

Sutter HealthSacramento, CA
$117,437 - $176,155Onsite

About The Position

Monitors, correlates, and analyzes security event data from a number of security solutions and technical systems. Aids in the development and coordination of system security plans and their implementation. Provides hands-on security administration of a broad range of security duties, including correlating, analyzing, researching, testing, and monitoring. Performs vulnerabilities scans across the environment and track remediation efforts. Develops periodic reports on security metrics, remediation progress, and deficiencies and then present them to management. Assists with preparing training materials and presentations for various cyber security initiatives.

Requirements

  • Bachelor's in Business, Cybersecurity, Computer Science, Information Technology/Security, Risk Management, or related field
  • 2 years recent relevant experience.
  • Knowledge of information systems security concepts and current information security trends and practices including security processes and methods.
  • General knowledge of Federal and State IS security and privacy-related regulatory requirements and laws.
  • General knowledge regarding National Institute of Standards and Technology (NIST), Health Insurance Portability and Accountability Act (HIPAA), Federal Information Processing Standards (FIPS), and other recognized industry security standards. and best practices.
  • General understanding of Diagnostic peritoneal lavage (DLP) and DLP technologies.
  • General understanding of using Microsoft windows workstation and server, Unix/Linux and network OS’s.
  • Knowledge of software, hardware, databases, networks, firewalls, encryption, and other systems security devices, including a good understanding of end point operating systems (Windows and Linux), internet technologies such as Domain Name System (DNS), routing, Simple Mail Transfer Protocol (SMTP), Hypertext Transfer Protocol (HTTP), Dynamic Host Configuration Protocol (DHCP), and File Transfer Protocol (FTP), and familiarity in a command line environment.
  • Familiarity in a command line environment.
  • Written/verbal interpersonal communication skills with the ability to interact effectively with a broad and diverse group of peers, users, and executives.
  • Proven ability to prioritize work while multi-tasking on assigned work.
  • Working knowledge of common enterprise applications, e-mail, web, cloud, client/server applications.

Nice To Haves

  • Experience in a healthcare, financial services, critical infrastructure, or other highly regulated environment.
  • Experience investigating incidents, alerts and performing threat hunts.
  • Experience with security orchestration, automation, and response (SOAR) platforms.
  • Experience developing or improving incident response playbooks and investigative procedures.
  • Experience performing memory, disk, network, email, and cloud forensics.
  • Experience with threat intelligence and incorporating threat intelligence into investigations.
  • Experience conducting proactive threat hunting.
  • Experience with malware analysis or reverse engineering.
  • Experience supporting legal, compliance, privacy, or regulatory requirements associated with security incidents.
  • Relevant certifications such as GCIH, GCFA, GCIH, GCFE, GNFA, CISSP, Security+, CySA+, or equivalent.

Responsibilities

  • Monitors, correlates, and analyzes security event data from a number of security solutions and technical systems.
  • Aids in the development and coordination of system security plans and their implementation.
  • Provides hands-on security administration of a broad range of security duties, including correlating, analyzing, researching, testing, and monitoring.
  • Performs vulnerabilities scans across the environment and track remediation efforts.
  • Develops periodic reports on security metrics, remediation progress, and deficiencies and then present them to management.
  • Assists with preparing training materials and presentations for various cyber security initiatives.
  • Ability to perform and conduct Incident Response and participate in security incident and post incident response process.
  • Ability to break down highly complex technical topics into language and diagrams understandable to a wide audience.

Benefits

  • Eligible positions also include a comprehensive benefits package.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service