Information Security Analyst (Red Team)

Point32Health, Inc.

$91K — $136K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science with IT security emphasis required; equivalent experience considered.
  • Preferred: Master’s degree in a relevant field.
  • 3-5 years of professional experience in information services.
  • Preferred: 5-7 years of progressive information services experience, with specific focus on systems security.
  • Working knowledge of security technologies and practices including Identity and Access Management, Cloud security, and various scripting languages.

Responsibilities

  • Consult with Security and Infrastructure Services to implement security software systems.
  • Communicate security exposures and compliance issues to management.
  • Monitor security logs to detect potential security events and report metrics.
  • Assess security trends and explore new technologies for business goals.
  • Analyze business requirements and risks related to security technology implementations.
  • Produce system monitoring reports and evaluate their content.
  • Assist in documenting and reviewing security policies and procedures.

Benefits

  • Medical, dental and vision coverage.
  • Retirement plans.
  • Paid time off.
  • Employer-paid life and disability insurance with additional buy-up options.
  • Tuition assistance program.
  • Well-being benefits for employees and their families.
Full Job Description

Job Summary

This position is responsible for simulating real-world cyber threats to evaluate the effectiveness of the organization's security controls, detection capabilities, and response processes. This role conducts adversary emulation, penetration testing, social engineering assessments, and security exercises to identify vulnerabilities, improve the organization's overall security posture, validate security investments, and reduce cyber risk. Reporting to the Cybersecurity Manager, the Security Analyst will work closely with IT teams across all threads where security applies.

Job Description

Key Responsibilities/Duties – what you will be doing (top five):

  • Consult with Security and Infrastructure Services staff to evaluate and implement software systems that provide appropriate security.
  • Communicate potential security exposures, misuse, or noncompliance situation to appropriate managers.
  • Monitor security logs to identify potential security related events. Capture and report security metrics.
  • Monitors security trends and assess potential uses of new technologies to meet identified business goals.
  • Analyze business requirements and risks to technology implementation for security-related issues.
  • Develop and produce systems monitoring and metrics reports and assess the content.
  • Work with Technical Writers to document and review security policy and procedures.
  • Participate in audits both internal and external as required.
  • As required, participate on project teams, and manage the completion of all assigned project related tasks.
  • Train information owners in the implementation of necessary security controls by developing and presenting information security awareness.
  • Other duties as assigned

Qualifications – what you need to perform the job

Certification and Licensure

Education

  • Required (minimum): Bachelor’s degree in computer science with emphasis on IT security required or equivalent experience.
  • Preferred: Master’s degree

Experience

  • Required (minimum): 3-5 years of professional experience
  • Preferred: 5-7 years of progressive experience in information services including 3 years in systems security, including maintenance and use of security products in a distributed enterprise environment, and experience in compliance with federal security regulations.

Skill Requirements

  • Specific working knowledge of and experience in the following work environments:
    • Identity and Access Management
    • SailPoint Identity Management
    • PingFederate
    • SiteMinder/Identity Manager/Provisioning Manager
    • CyberArk PAM
    • Cloud security
    • Active Directory
    • LDAP Directory Services
    • Perl, Python, VBS and Java.
    • Vulnerability scanning and management
    • Intrusion Detection/Prevention System
    • Virus & malware protection
    • Advanced Threat Protection
    • Public Key Infrastructure
    • Data Loss Prevention
    • Microsoft O365
    • Firewalls
    • VPN
    • Forensics
    • Mobile application security
    • Operational data stores, data marts, data warehouse
    • Security Information and Event Management (SIEM)
    • N-tiered infrastructure patterns
    • Windows and UNIX operating system environments
    • Web portal technology and application servers, i.e. Apache Tomcat, WebLogic, WebSphere
    • Data/Computer Operations technology integration and support
    • CRM solutions/Salesforce
  • Excellent communications skills both written and oral

Working Conditions and Additional Requirements (include special requirements, e.g., lifting, travel):

  • Must be able to work under normal office conditions and work from home as required.
  • Work may require simultaneous use of a telephone/headset and PC/keyboard and sitting for extended durations.
  • May be required to work additional hours beyond standard work schedule.

Disclaimer

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Management retains the discretion to add to or change the duties of the position at any time.

Salary Range

$91,188.71 -$136,783.07

Compensation & Total Rewards Overview

The annual base salary range provided for this position represents a range of salaries for this role and similar roles across the organization.  The actual salary for this position will be determined by several factors, including the scope and complexity of the role; the skills, education, training, credentials, and experience of the candidate; as well as internal equity. As part of our comprehensive total rewards program, colleagues are also eligible for variable pay. Eligibility for any bonus, commission, benefits, or any other form of compensation and benefits remains in the Company's sole discretion and may be modified at the Company’s sole discretion, consistent with the law.

Point32Health offers their Colleagues a competitive and comprehensive total rewards package which currently includes:

  • Medical, dental and vision coverage

  • Retirement plans

  • Paid time off

  • Employer-paid life and disability insurance with additional buy-up coverage options

  • Tuition program

  • Well-being benefits

  • Full suite of benefits to support career development, individual & family health, and financial health

For more details on our total rewards programs, visit https://www.point32health.org/careers/benefits/

Similar Jobs

More Jobs at Point32Health, Inc.

More Information Technology Jobs

Find similar Information Security Analyst (Red Team) jobs: