Logo for Wellstar Health System

Sr Info Security Analyst

Role overview

Qualifications

  • Bachelor's in Information Security or related field
  • Minimum 5 years in information security or a related field
  • Certifications: CISSP, CISM, CISA, HCISPP, CPHIMS, CAHIMS, CRISC, GIAC, OCSP

Responsibilities

  • Monitor and analyze critical internal and external systems for security compliance
  • Perform vulnerability assessments and recommend remediation strategies
  • Conduct security assessments and manage risks associated with vulnerabilities
  • Assist with penetration testing and security research activities

Key facts

Other skills

  • Strategic Planning
  • Detail Oriented
  • Problem Solving
  • Teamwork
  • Creative Thinking

About the company

Wellstar Health System logo

Wellstar Health System

Hospitals & Health Care

At Wellstar Health System, our mission is to enhance the health and well-being of every person we serve. Nationally ranked and locally recognized for our high-quality care, inclusive culture and world-class doctors and caregivers, Wellstar is one of the largest, most integrated healthcare systems in Georgia. Our specialists and primary care providers work in a multidisciplinary environment with nearly 25,000 diverse team members throughout our hospitals, health parks and medical offices. Communities can also access our outpatient centers, a pediatric center, nursing centers, and hospice and home care services. We’re proud to be home to the second-largest Emergency Department in the country, as well as being the only system in Georgia operating multiple trauma centers. We’re also known for our exceptional work culture, featured on the Great Places to Work®, Fortune 100 Best Companies to Work For® and the Seramount Best Company for Multicultural Women® lists. We continue to attract the best and the brightest in healthcare.At a time when our industry is changing rapidly, Wellstar remains committed to exceeding expectations from our patients and team members, while transforming healthcare delivery. We stand behind our values to serve with compassion, pursue excellence and honor every voice.

Company details

Company typeXLarge
IndustryHospitals & Health Care
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

How would you like to work in a place where your contributions and ideas are valued? A place where you can serve with compassion, pursue excellence and honor every voice? At Wellstar, our mission is simple, yet powerful: to enhance the health and well-being of every person we serve. We are proud to have become a shining example of what's possible when the brightest professionals dedicate themselves to making a difference in the healthcare industry, and in people's lives.

Work Shift

Day (United States of America)

Job Summary:

The Sr. Information Security Analyst functions as an information security subject matter expert supporting all aspects of WellStar with their knowledge and skills. The individual is experienced in many areas of the information security domains, and can conduct risk assessments, develop appropriate risk responses, and monitor the environment for change. The individual needs to have the capability to participate in several projects and tactical initiatives related to enterprise security, manage critical relationships with key stakeholders and vendors, drive process improvements for the information security program, and review risks assessments for potential security exposures. The Senior Analyst is also expected to mentor others interested in information security. The Sr. Information Security Analyst position reports directly to Mgt Information Security. Key responsibilities of the role include: This position will be responsible for monitoring and analyzing critical internal and external systems to ensure there are no misconfigurations with security standards and benchmarks that could lead to a compliance risk. Analyze management and technical controls to ensure that specific security and compliance requirements are met through the verification of documented processes, procedures and standards in order to validate maintenance of secure configurations. Perform CIS Benchmark assessments to analyze configurations and make recommendations for hardening configurations for Windows operating systems including servers, endpoints, VDI and thin clients. Identify and assess business and technology risks, controls which mitigate risks, and opportunities for control improvement. Analyze, report and track associated vulnerabilities to key stakeholders for remediation. Must be able to provide technical remediation details or workarounds, help track and identify asset inventory, log work tickets and exceptions and research vulnerability findings. Quickly respond and assess exposure and impact of zero-day vulnerabilities and provide management with briefings and course of action for mitigation. Must be able to provide management with security assessments and briefings to advise them of critical and high-risk findings that may impact WellStar operations and critical infrastructure. Identify and assess business and technology risks, internal controls which mitigate risks, and opportunities for internal control improvement. Assist with penetration testing when applicable. Experience with Rapid7 assessment tools - Rapid7 InsightVM and Insight Cloud Security preferred, CIS Benchmarking for endpoint, server and cloud infrastructure. Must be well versed in the Vulnerability Management Lifecycle Impact of this role in the organization is high. This position is important in helping to reduce loss and reputation associated with successful security breaches and resulting business disruption. If a security breach occurs, the costs of containment, recovery, public relations, and fines can quickly add up.

Core Responsibilities and Essential Functions:

1. Conduct security assessments a. Test and monitor various systems and network components for vulnerabilities and misconfigurations that could lead to the compromise of Wellstars network. b. Test new toolsets to assist Wellstar in the vulnerability identification process. 2. Remediation a. Assist with efforts related in remediating findings from vulnerability assessments, benchmarks and penetration tests. b. Provide risk-based mitigation strategies for networks, operating systems and applications including technical remediation steps c. Prioritize vulnerabilities discovered along with expected remediation timelines d. Inform various teams of active threats, zero-day vulnerabilities and exploits in the wild that can have a direct impact on Wellstar operations e. Provide retesting services to validate remediation. f. Provide proof of exploitability for vulnerabilities found during the Vulnerability Management process, on an as needed basis. g. Provide actionable reporting so that Wellstar can remediate and mitigate risks discovered. 3. Process improvements and automation a. Continue supporting current process automations for the Vulnerability Management program. b. Create new process automations for the Vulnerability Management program. 4. Security Research a. Actively search for new vulnerabilities in systems and software. b. Report new findings through appropriate private disclosure methodologies. c. Monitor threat feeds for new emerging threats applicable to our environment. Performs other duties as assigned Complies with all WellStar Health System policies, standards of work, and code of conduct.

Required Minimum Education:

  • Bachelors Information Security or Bachelors Other

Required Minimum License(s) and Certification(s):

All certifications are required upon hire unless otherwise stated.

    Additional License(s) and Certification(s):

    One of: CISSP, CISM, CISA, HCISPP, CPHIMS, CAHIMS. CRISC, GIAC, OCSP or any other equivalent security certification. Upon Hire Required

    Required Minimum Experience:

    Minimum 5 years in information security or a related field conducting security control assessments or audits Required and Rapid7 InsightVM and Insight Cloud Security, CIS Benchmark auditing tools for endpoint, server and cloud infrastructure.

    Required Minimum Skills:

    Strategic planning and the development of supporting policies and procedures Experience with information security principles, industry standards, and best practices Technical lead/project leader experience in planning, implementing, and supporting enterprise information security solutions Project management Develop and manage key stakeholder relationships Effectively coordinating work on multiple and diversified tasks while working with conflicting priorities and deadline Ability to balance business requirements, patient safety and security risks Ability to function with highly dynamic results-driven and high-pressure environment in order to achieve required objectives Strong attention to detail and problem solving skills Able to work independently and on a team Creative thinking and ability to "think outside the box" Knowledge of HIPAA Security Rule, PCI DSS and NIST CSF

    Join us and discover the support to do more meaningful work—and enjoy a more rewarding life. Connect with the most integrated health system in Georgia, and start a future that gives you more.

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    Information Security Analyst Related jobs

    Other jobs at Wellstar Health System

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.