IT - Analyst II, Security Systems

ArchWell Health

$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, Computer Science, Information Systems, or related field; equivalent experience considered.
  • Minimum 4 years in cybersecurity, security operations, incident response, vulnerability management, or related fields.
  • Experience with Microsoft cloud and security technologies including Microsoft 365, Azure, Entra ID, and Defender.
  • Proficient in investigating security events, documentation, remediation, and incident response actions.
  • Experience supporting enterprise security technologies and monitoring activities.

Responsibilities

  • Protect organizational systems, identities, and data from unauthorized access or disruption.
  • Monitor compliance with security standards across endpoints, mobile devices, and cloud services.
  • Administer identity and access management processes and entitlement reviews.
  • Coordinate vendor risk assessments and security reviews.
  • Investigate and respond to security alerts and log events across multiple platforms.
  • Participate in incident response activities from triage to post-incident reporting.
  • Perform vulnerability assessments and report on organizational risk exposure.

Benefits

  • Opportunity to work with cutting-edge cybersecurity technologies.
  • Supportive environment for professional growth and continued learning.
  • Collaborative workplace culture promoting team-oriented projects and initiatives.
Full Job Description
Analyst II, IT Security

Job Summary:

The IT Security Analyst II is responsible for supporting the organization's cybersecurity program through continuous monitoring, incident response, vulnerability management, identity and access governance, security assessments, and administration of security technologies. This role helps protect organizational systems, networks, cloud services, and data assets while supporting security operations, compliance requirements, and risk reduction initiatives.

The Analyst II partners with infrastructure, support, application, and business teams to investigate security events, implement security controls, improve security posture, and promote cybersecurity awareness across the organization.

Duties/Responsibilities:
  • Protect organizational systems, identities, networks, cloud platforms, and data from unauthorized access, modification, disclosure, disruption, or destruction.
  • Monitor compliance with endpoint, mobile device, and cloud security standards including encryption, endpoint protection, vulnerability remediation, and secure configuration baselines.
  • Administer and review identity and access management processes including provisioning, deprovisioning, entitlement reviews, privileged access governance, and periodic access certification reviews.
  • Coordinate and support the vendor risk assessment process, including security reviews, documentation collection, risk evaluations, and remediation tracking.
  • Monitor, investigate, and respond to security alerts, log events, suspicious activity, and anomalies across endpoint, network, cloud, email, and identity platforms. Provide operational reporting and coordinate remediation activities as appropriate.
  • Participate in incident response activities including triage, investigation, containment, remediation, documentation, escalation, and post-incident reporting.
  • Perform vulnerability assessments, track remediation efforts, validate corrective actions, and report on organizational risk exposure.
  • Support, maintain, evaluate, and improve cybersecurity technologies including SIEM, EDR/XDR, vulnerability management, email security, endpoint protection, firewall, identity security, and cloud security platforms.
  • Implement and review security controls including application security, access control, data protection, and security configuration standards.
  • Collaborate with infrastructure, network, and cloud teams to design, implement, and support security controls across servers, endpoints, applications, and cloud services.
  • Develop, update, and maintain cybersecurity policies, standards, procedures, and technical security guidance.
  • Adhere and participate in change management.
  • Contribute recommendations for improving security operations, monitoring capabilities, threat detection, and overall cybersecurity maturity.
  • Organize and lead internal phishing campaign efforts, including reporting and presenting to IT and business leadership,
  • Manage and resolve security-related tickets, incidents, service requests, and escalations through internal and vendor-managed ticketing systems. Report on SLA or other service issues as required as they relate to our strategic security business partners,
  • Participate in cybersecurity projects, operational meetings, security reviews, assessments, and cross-functional initiatives.
  • Primary contributor for creating or gathering content for the annual security assessment report.


Required Skills/Abilities:
  • Experience reviewing SIEM alerts, escalations, and security events, including coordinating response activities with internal and external stakeholders.
  • Experience conducting threat hunting activities using SIEM, EDR/XDR, threat intelligence, endpoint telemetry, and log analysis to identify suspicious behavior and potential threats.
  • Strong knowledge of network protocols, attack techniques, attack surface analysis, threat detection methodologies, and mitigation strategies.
  • Strong understanding of DNS, DHCP, TCP/IP, Active Directory, Entra ID, authentication protocols, and enterprise networking fundamentals.
  • Solid understanding of Windows 10, Windows 11, Windows Server, endpoint security management, and Microsoft enterprise productivity environments.
  • Ability to evaluate technologies, identify security risks, and recommend practical mitigation strategies.
  • Ability to produce clear technical documentation, procedures, reports, security findings, and recommendations for both technical and non-technical audiences.
  • Proactive self-starter able to manage multiple priorities while maintaining a stewarding heart and team-oriented attitude.
  • Experience working in a fast-paced environment with multiple concurrent projects and initiatives.
  • Effective interpersonal skills with the ability to interact effectively with technical, non-technical, support, and business stakeholders at all levels.
  • Strong oral and written communication skills.
  • Sound working knowledge of LAN/WAN topologies and architecture. Multi-site WAN experience required; Meraki experience preferred.
  • Ability to build effective working relationships with customers, co-workers, leadership, vendors, and business stakeholders while maintaining a strong customer service orientation.


Minimum Qualifications:
  1. Bachelor's degree in information security, Computer Science, Information Systems, or a related field; equivalent experience considered.
  2. Minimum 4 years of experience in cybersecurity, security operations, incident response, vulnerability management, threat hunting, or related information security functions.
  3. Experience supporting Microsoft cloud and security technologies including Microsoft 365, Azure, Entra ID, Defender, Sentinel, Intune, Conditional Access, MDM, or related security platforms.
  4. Experience investigating security events and incidents, including documentation of findings, remediation activities, and incident response actions.
  5. Experience supporting enterprise security technologies and security monitoring activities

    Preferred Qualifications:
    • Experience supporting healthcare, regulated, or highly compliant environments.
    • Familiarity with HIPAA, NIST Cybersecurity Framework, CIS Controls, HITRUST, or similar security and compliance frameworks.
    • Experience conducting proactive threat hunting activities using SIEM, EDR/XDR, threat intelligence, and endpoint telemetry.
    • Experience with Microsoft Defender XDR, Defender for Cloud, Sentinel automation, advanced hunting, KQL, and security orchestration capabilities.
    • Experience with SIEM, EDR/XDR, vulnerability management, identity protection, cloud security, and security monitoring platforms.
    • Security certifications such as Security+, SC-200, SC-300, AZ-500, CySA+, CISSP, GCIH, or equivalent.

    Similar Jobs

    More Jobs at ArchWell Health

    More Information Technology Jobs

    Find similar IT - Analyst II, Security Systems jobs: