Sutter Health

Cybersecurity Analyst IV

Sutter Health • $150K — $240K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Business, Cyber Security, Risk Management, Information Technology, Computer Science, or related field (equivalent experience accepted).
  • 8 years of recent relevant experience in cybersecurity.
  • Professional certifications such as CISSP, GIAC, or Microsoft Security preferred.
  • Experience with enterprise cybersecurity programs, including vulnerability management and threat intelligence.
  • Proficiency in SQL, Python, and Power BI for cybersecurity analytics.

Responsibilities

  • Provide cybersecurity support and technical leadership across Sutter Health entities.
  • Perform advanced security administration, engineering, and incident response activities.
  • Develop cybersecurity metrics and risk-based recommendations for stakeholders.
  • Support security awareness and human risk management initiatives.
  • Collaborate with technical and business teams to enhance cybersecurity resilience.

Benefits

  • Comprehensive benefits package including health, dental, and vision insurance.
  • Retirement savings plan with employer contributions.
  • Professional development opportunities and training programs.
  • Flexible work arrangements with hybrid options, though in-office attendance is required.
  • Supportive work environment focused on team collaboration and continuous improvement.
Full Job Description

Organization:

SHSO-Sutter Health System Office-Valley

Position Overview:

Responsible for providing cybersecurity support, guidance, and technical leadership to Sutter Health operating units, entities, and the Cybersecurity Department to protect information systems, networks, data, and digital assets. This senior-level role performs advanced security administration, engineering, research, testing, monitoring, incident response, threat hunting, and risk management activities while supporting enterprise cybersecurity initiatives and programs. Serving as a trusted advisor to Information Security leadership, the Cybersecurity Analyst IV provides subject matter expertise across multiple cybersecurity domains, including endpoint security, data protection, vulnerability management, security information and event management (SIEM), network security, and threat intelligence. The position develops cybersecurity metrics, security insights, and risk-based recommendations, supports security awareness and human risk management initiatives, mentors team members, and collaborates with technical and business stakeholders to strengthen cybersecurity resilience, enhance operational effectiveness, support regulatory compliance, and reduce risk to patient care and business operations.

Job Description:

***Please Note: While this position is listed as hybrid, regular in-office attendance is required. Candidates should be prepared to commute to the Sacramento office on a consistent basis to support team collaboration and business needs.***


EDUCATION:
Equivalent experience will be accepted in lieu of the required degree or diploma.

  • Bachelor's in Business, Cyber Security, Risk Management, Information Technology, Computer Science or related field

TYPICAL EXPERIENCE:

  • 8 years recent relevant experience.

PREFERREED EXPERIENCE:

  • Experience supporting enterprise cybersecurity programs, including vulnerability management, threat intelligence, data protection, data loss prevention (DLP), and risk reduction initiatives.
  • Experience with Microsoft Defender, SIEM, and other enterprise cybersecurity platforms to support security monitoring, threat analysis, and operational effectiveness.
  • Experience providing security consultation, risk assessments, policy reviews, vendor/third-party security reviews, and risk-based recommendations to technical and business stakeholders.
  • Experience supporting security awareness, phishing prevention, workforce education, and human risk management programs.
  • Experience developing cybersecurity metrics, executive dashboards, KPIs, and risk reporting, including the use of SQL, Python, and Power BI to support cybersecurity analytics, automation, and data-driven decision-making.
  • Experience utilizing ServiceNow or similar platforms to support investigations, workflow management, exception management, customer engagement, and cybersecurity operations processes.
  • Experience integrating and analyzing data from multiple cybersecurity technologies to identify risks, trends, and opportunities for operational improvement.
  • Experience leading cybersecurity initiatives, mentoring team members, and driving program maturity, operational effectiveness, and continuous improvement efforts.
  • Professional cybersecurity certifications such as CISSP, GIAC, Microsoft Security, or equivalent advanced certifications.


SKILLS AND KNOWLEDGE:

  • Thorough knowledge of information systems security concepts and current information security trends and practices including security processes and methods.
  • General knowledge of Federal and State IS security and privacy-related regulatory requirements and laws.
  • General knowledge regarding National Institute of Standards and Technology (NIST), Health Insurance Portability and Accountability Act (HIPAA), Federal Information Processing Standards (FIPS), and other recognized industry security standards. and best practices.
  • Detailed understanding of end point security technologies (Antivirus, Forensics, Anti-malware, HIPS)
  • Detailed understanding of end point operating systems (Windows and Linux)
  • In depth knowledge of cyber security solutions, policies and technologies
  • Understanding of the lifecycle of a network threat and network vulnerability exploitation in a healthcare environment
  • Working understanding of the anatomy of a cyber attack: advanced level of skill using Microsoft windows workstation and server, Unix/Linux and network Os’s, proven ability to use internet technologies including dns, routing, smtp, http, dhcp, and ftp etc.
  • Technical skills in planning, administration, and management of information systems, operational and technical security controls, and security risk analysis and management
  • Written/verbal interpersonal communication skills with the ability to interact effectively with a broad and diverse group of peers, users, and executives.
  • Proven ability to prioritize work while multi-tasking on assigned work.
  • Demonstrated ability to acquire images, either remote or local, to a workstation or server.
  • Proven ability to conduct forensics activities in the context of an active attack.
  • Technical skills in end point security controls, such as acls, hips, registry, logging, and forensics.
  • Ability to perform and conduct incident response and participate in security incident and post incident response process
  • Proven ability to break down highly complex technical topics into language and diagrams understandable to a wide audience

These Principal Accountabilities, Requirements and Qualifications are not exhaustive, but are merely the most descriptive of the current job. Management reserves the right to revise the job description or require that other tasks be performed when the circumstances of the job change (for example, emergencies, staff changes, workload, or technical development).


#LI-JI1

Job Shift:

Days

Schedule:

Full Time

Days of the Week:

Monday - Friday

Weekend Requirements:

As Needed, Occasionally

Benefits:

Yes

Unions:

No

Position Status:

Exempt

Weekly Hours:

40

Employee Status:

Regular

Pay Range is $150,300.80 to $240,489.60 / annual salary

The compensation range may vary based on the geographic location where the position is filled. Total compensation considers multiple factors, including, but not limited to a candidate’s experience, education, skills, licensure, certifications, departmental equity, training, and organizational needs. Base pay is only one component of Sutter Health’s comprehensive total rewards program. Eligible positions also include a comprehensive benefits package.

About Sutter Health

Sutter Health is a not-for-profit health system in Northern California, headquartered in Sacramento. It includes doctors, hospitals and other health care services in more than 100 Northern California cities and towns. Major service lines of Sutter Health-affiliated hospitals include cardiac care, women’s and children’s services, cancer care, orthopedics and advanced patient safety technology.
Learn more about Sutter Health
Size
58,000 employees
Industry
Founded
1981

Similar Jobs

More Jobs at Sutter Health

More Information Technology Jobs

Find similar Cybersecurity Analyst IV jobs: