JOB SUMMARY
Seeking an experienced Incident Response Analyst. The analyst will be responsible for incident response, threat hunting, and data analysis to protect and maintain the overall security of the enterprise.
ESSENTIAL RESPONSIBILITIES
Protecting enterprise systems and information by promptly responding to security threats and incidents, acting individually and as part of a team to resolve issuesProactively hunting for threats and enacting identification, containment, and eradication measures while supporting recovery efforts.Act as subject matter expert to provide insight and guidance to colleagues engaging in prevention measures.Analyzing cyber security incidents to solve issues and improve incident handling proceduresReceive Tier 2/3 incident escalation from detection operations and assist with real-time, continuous (24x7) security event monitoring, response, and reportingProactive coordination with appropriate departments during a security incident – management, legal, security, operations, and others.Conducting research regarding the latest methods, tools, and trends in digital forensics analysisCreating thorough reports and documentation of all incidents and procedures; presenting findings to team and leadership on a routine basisOther duties as assigned or requested.EDUCATION
Required
Bachelor’s Degree - Information Security, Information Systems, Information Assurance, Computer Science or related fieldSubstitutions
5 years of Information Security, Governance, Risk and/or Compliance, Information Technology or Business AnalysisPreferred
NoneEXPERIENCE
Required
3 - 5 years of experience with Information Security and Systems Analysis 3 - 5 years of experience with Information Security and/or Information Risk Management and/or Information Technology3 - 5 years of experience with Information Security Governance, Risk and/or Compliance functions and activities 3 - 5 years of experience developing, communicating and presenting Information Security and Risk Management concepts to varying audiences 3 - 5 years of experience with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platformsPreferred
5 - 7 years of experience with information security and systems analysis Experience working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework Experience supporting SSAE 16 or SOC 2 Security Trust Principle audits IT/information security risk advisory experience Governance Risk and Compliance (GRC) tool experience such as ARCHER In-depth understanding of network security architecture, network and networking protocolLICENSES AND CERTIFICATIONS
Required
NonePreferred
GCFA, GCIH, GCFE, GNFA, GREM, GCCCCISSP,SKILLS
Must have a deep understanding of computer intrusion activities, incident response techniques, tools, and proceduresThorough knowledge of digital forensics methodology as well as security architecture, system administration, and networking (including TCP/IP, DNS, HTTP, SMTP)Knowledge of operating systems including Linux/Unix and WindowsExperience with programming languages such as Python, Perl, C/C++, PowerShell, etc.Experience with security assessment tools such as NMAP, Netcat, Nessus, and Metasploit is a plus.Excellent written and verbal communication skillsExcellent organization, time management, and attention to detailMust be action-oriented and have a proactive approach to solving issuesAbility to work individually and as part of a teamDisclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, age, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, age, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability.
EEO is The Law
Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled/Sexual Orientation/Gender Identity (https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf)
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact number below.
For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org
California Consumer Privacy Act Employees, Contractors, and Applicants Notice