About the RoleThis position is a lead security analyst within IT Security Governance and IT Security Operations. The incumbent will be responsible for the administration, monitoring, maintenance, and continuous improvement of numerous critical security technologies. In addition to maintaining day-to-day cybersecurity operations, the team is responsible for several enterprise-wide strategic initiatives,
What You'll DoIT Security Operations:
- Recommend FireWall change requests for approval
- Analyze and take appropriate action on intrusion detections
- Analyze and recommend action on security related incidents; notify appropriate owners and IT Security Governance
- Review and approve access requests
- Provide Role Based Access Control (RBAC) to individual users and perform recertification based on segregation of duties and roles
- Map work flows in provisioning users into our systems and infrastructure
- Comply with internal and external audit requests
- Monitor the effectiveness of the Enterprise wide information security program
- Provide data for audit indicating changes made to access control lists to facilitate audits and other investigations
- Participate in investigating possible security violations
- Track and maintain operational security access metrics
IT Security Governance:
- Design workflow diagrams showing the production of, transmission and use of electronic Protected Health Information (ePHI) and other sensitive information
- Provide guidance and direction regarding security control elements in policies throughout the organization
- Document relevant business processes and their implications on information security
- Develop information security risk identification, tracking and mitigation processes strategy and methodology
- Develop the information security awareness, training and education program-s strategy and methodology
- Facilitate or lead development of accurate and relevant information security process and operational metrics
- Establish monitoring measures to detect and ensure correction of security breaches and policy violations
- Proactively keep current on information security issues related to business processes as input into departmental policies and procedures
- Analyze and enhance the effectiveness of the Enterprise wide information security program.
What You BringEducation/Experience:- Minimum high school diploma or GED
- Requires Bachelor's degree, preferably in Computer Science, from an accredited college or university
- Prefers advanced degree in Information Security, Computer Science or related field
- 5 years prior IT security related work experience
- Experience with IDS, IPS, ICE Engine or
Additional licensing, certifications, registrations:- Requires one or more of the following certifications: CISSP, SANS GIAC or CISA
Knowledge:- Requires an excellent understanding of IT security concepts with an emphasis on Security and Risk Assessment
- Microsoft 365 security implementation and ongoing support
- Micro-segmentation initiatives to reduce lateral movement risks
- AI performance, governance, and security controls
- Data classification and sensitive data protection initiatives
- Cloud security enhancements
- Continuous vulnerability remediation efforts
- Security architecture improvements aligned with organizational objectives
Skills and Abilities:- Perimeter Defense
- Palo Alto Networks (PAN) Firewalls)
- Prisma GlobalProtect VPN
- Cisco Sourcefire
- Cisco Stealthwatch
- Cisco Identity Services Engine (ISE)
- Secure Mail Gateway (ProofPoint)
- Enterprise Proxy
- Endpoint and Data Protection
- Endpoint Protection Platforms
- Data Loss Prevention (DLP)
- File Integrity Monitoring (FIM)
- Absolute/Computrace
- Vulnerability Scanning Platforms
- Disc Encryption
- EDR (Crowdstrike)
- Application and Cloud Security
- Web Application Firewall (WAF)
- Secure Proxy Services
- Zscaler
- Application Security Programs
- Cloud Access Security Broker (CASB)
- Cloud Security Controls
- Security Operations
- Security Information and Event Management (SIEM)
- Security Monitoring and Alerting
- Incident Response Activities
- Threat Detection and Vulnerability Management
Salary Range:$97,800 - $133,455
This compensation range is specific to the job level and takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to: education, experience, licensure, certifications, geographic location, and internal equity. This range has been created in good faith based on information known to Horizon at the time of posting. Compensation decisions are dependent on the circumstances of each case. Horizon also provides a comprehensive compensation and benefits package which includes:
- Comprehensive health benefits (Medical/Dental/Vision)
- Retirement Plans
- Generous PTO
- Incentive Plans
- Wellness Programs
- Paid Volunteer Time Off
- Tuition Reimbursement