The Sr. Information Security Analyst functions as an information security subject matter expert supporting all aspects of WellStar with their knowledge and skills. The individual is experienced in many areas of the information security domains, and can conduct risk assessments, develop appropriate risk responses, and monitor the environment for change. The individual needs to have the capability to participate in several projects and tactical initiatives related to enterprise security, manage critical relationships with key stakeholders and vendors, drive process improvements for the information security program, and review risks assessments for potential security exposures. The Senior Analyst is also expected to mentor others interested in information security. The Sr. Information Security Analyst position reports directly to Mgt Information Security. Key responsibilities of the role include: This position will be responsible for monitoring and analyzing critical internal and external systems to ensure there are no misconfigurations with security standards and benchmarks that could lead to a compliance risk. Analyze management and technical controls to ensure that specific security and compliance requirements are met through the verification of documented processes, procedures and standards in order to validate maintenance of secure configurations. Perform CIS Benchmark assessments to analyze configurations and make recommendations for hardening configurations for Windows operating systems including servers, endpoints, VDI and thin clients. Identify and assess business and technology risks, controls which mitigate risks, and opportunities for control improvement. Analyze, report and track associated vulnerabilities to key stakeholders for remediation. Must be able to provide technical remediation details or workarounds, help track and identify asset inventory, log work tickets and exceptions and research vulnerability findings. Quickly respond and assess exposure and impact of zero-day vulnerabilities and provide management with briefings and course of action for mitigation. Must be able to provide management with security assessments and briefings to advise them of critical and high-risk findings that may impact WellStar operations and critical infrastructure. Identify and assess business and technology risks, internal controls which mitigate risks, and opportunities for internal control improvement. Assist with penetration testing when applicable. Experience with Rapid7 assessment tools - Rapid7 InsightVM and Insight Cloud Security preferred, CIS Benchmarking for endpoint, server and cloud infrastructure. Must be well versed in the Vulnerability Management Lifecycle Impact of this role in the organization is high. This position is important in helping to reduce loss and reputation associated with successful security breaches and resulting business disruption. If a security breach occurs, the costs of containment, recovery, public relations, and fines can quickly add up.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior