Franciscan Health

Cyber Security Specialist Lead

Franciscan Health • $96K — $133K *
US-AnywhereRemote in United States
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Associate's Degree required; Bachelor's Degree preferred.
  • Relevant certification preferred.
  • 8 years of experience in Information Technology or Information Security required.
  • 5 years of experience in the healthcare industry preferred.
  • Strong background in security operations activities.

Responsibilities

  • Investigate and analyze cyber incidents within the network environment.
  • Collect and analyze data from various Computer Network Defense tools.
  • Provide persistent monitoring of designated networks and systems.
  • Lead SOC efforts during high-severity security incidents.
  • Develop and maintain SOAR playbooks to automate response tasks.
  • Build and optimize complex SPL queries for threat detection.
  • Create and review cybersecurity policies and procedures.

Benefits

  • Work from home flexibility.
  • Opportunity to lead and mentor SOC analysts.
  • Access to advanced security technologies and tools.
  • Engagement in continuous learning and professional development.
  • Collaboration with Security Architects on technology upgrades.
Full Job Description

Work From Home

Work From Home Work From Home, Indiana 46544


The Cyber Security Specialist Lead investigates and analyzes all response activities related to cyber incidents within the network environment or enclave. Collects data from a variety of Computer Network Defense (CND) tools, including intrusion detection system alerts, firewall and network traffic logs, and host system logs to analyze events that occur within their environment. Provides operations for persistent monitoring of all designated networks, enclaves, and systems. Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events. Acts as of the highest level of escalation point. Distributes directives, vulnerability, and threat advisories to identified consumers.


SPLUNK CLOUD / ON PREMISE EXPERIENCE PREFERRED.

WHAT YOU CAN EXPECT


  • Work with Security Architects to develop roadmaps and implementation plans for upgrading, enhancing or replacing security technologies for which the Cyber Security Operations team is responsible.
  • Demonstrate advanced proficiency to write and optimize complex SPL queries to identify and investigate suspicious activity, correlate events, identify attack patterns, and perform proactive threat hunting across security data.
  • Create, test, tune, and maintain high-fidelity detections; reduce false positives; utilize risk-based alerting; and establish detection thresholds and governance.
  • Stay abreast of current artificial intelligence capabilities of the SIEM and other deployed security tools, develop and implement these capabilities to improve SOC performance.
  • Lead the SOC efforts during investigation of high-severity security incidents, participate in the cyber security incident response team, and guide analysts through the incident response lifecycle.
  • Develop, maintain, and safely execute SOAR playbooks; automate enrichment and response tasks; and identify opportunities to reduce repetitive analyst work.
  • Understand security data sources, field extractions, data models, and the common information model (CIM), troubleshoot data quality issues, and validate detections are operating against reliable data.
  • Serve as a technical escalation point, coach analysts, review investigations, establish investigation standards, and communicate clearly with SOC management and other security teams.
  • Build Splunk dashboards and reports to measure data sources, alert volume, detection performance, investigation quality, and SOC effectiveness.
  • Build detections for anomalous user and entity behavior, create procedures to investigate compromised accounts and lateral movement, use risk context to prioritize investigations.
  • Work with internal resources and external 3rd parties to design and conduct penetration tests, including ones designed as “stimulus-response” for the centralized log management system.
  • Create and review cyber security policies, procedures, and standards related to Security Operations Center, Vulnerability Management, and Incident Response processes.

QUALIFICATIONS


  • Required Associate's Degree
  • Preferred Bachelor's Degree
  • Preferred Certificate
  • 8 years Information Technology or Information Security Department Required
  • 5 years Healthcare industry; experience in security operations activities aligning with Essential Job Functions Preferred

TRAVEL IS REQUIRED:

Never or Rarely

JOB RANGE:

Cyber Security Specialist Lead - 96,731.58-133,005.92

INCENTIVE:

About Franciscan Health

Franciscan Health is a Catholic healthcare system with 14 hospitals and numerous clinics located in Indiana, Illinois, and Michigan. The system is a member of the Mishawaka-based Franciscan Alliance, which is one of the largest Catholic healthcare systems in the United States. Franciscan Health provides a wide range of medical services, including cancer care, heart and vascular care, orthopedics, neurology, women's health, and pediatrics.
Learn more about Franciscan Health
Size
18,000 employees
Industry
Net Income
$200 million
5 Year Trend
-2%
Revenue
$3 billion

Similar Jobs

More Jobs at Franciscan Health

More Healthcare Jobs

Find similar Cyber Security Specialist Lead jobs: