5-7 years of IT Infrastructure or IT Security experience required
Hands-on experience with Cisco security technologies, including Secure Network Analytics and Identity Services Engine
Bachelor's degree in Information Technology, Information Security, or a related field
CISSP or equivalent industry certification required
Strong understanding of cloud security fundamentals and zero-trust architecture concepts
Responsibilities
Design, implement, and manage enterprise security solutions using Cisco security platforms
Configure, maintain, and optimize Palo Alto Networks firewalls for network security
Administer and enhance email security solutions to combat phishing and malware
Design and maintain cloud security controls for policy enforcement and compliance
Architect network segmentation initiatives aligned with zero-trust principles
Deploy and manage secure remote access solutions, including zero-trust technologies
Investigate security alerts and support incident response efforts
Benefits
Collaborative work environment with opportunities for professional growth
Exposure to cutting-edge security technologies and practices
Support for continuous learning and certifications
Engagement with cross-functional teams in a dynamic setting
Opportunity to mentor junior team members and contribute to team development
Full Job Description
Job Summary:
The Risk Analyst II position within the Digital Transformation Information Services Information Security team is a senior level position.
The Risk Analyst II is responsible for designing, implementing and managing enterprise level security solutions. They oversee and enforce network security policies through a host of activities and practices. Included among these are the configuration, optimization and monitoring of network firewalls; zero-trust/SASE infrastructure, administration of email security measures to identify and filter phishing attempts, malware and data loss; monitoring and managing remote connections; implementing cloud controls; Administration of identify and access management controls; monitoring and responding to alerts from EDR/XDR and other endpoint detection and responses. The Risk Analyst II is also responsible for the oversight of security software and systems upgrades, troubleshooting issues and verifications of system availability and performance. An understanding of business requirements across areas involved, e.g. clinical, ancillary, administrative and financial areas, is necessary. They will document activities, resolutions, and other outcomes throughout the life cycle of a security breach, problem or related response. The Risk Analyst II will coordinate and collaborate with other WMC IT Teams in support 11of system, project rollout, problem resolution, and end user support. This senior team member will assist junior members of the team on more complex aspects of the aforementioned areas for growth and knowledge.
Responsibilities:
Design, implement, and manage enterprise security solutions, including Cisco security platforms (Secure Network Analytics/Stealthwatch, Identity Services Engine (ISE), AnyConnect, Firepower, and Umbrella).
Configure, maintain, and optimize Palo Alto Networks firewalls to enforce network security policies.
Administer and enhance email security and filtering solutions to protect against phishing, malware, and data loss.
Design and maintain cloud security controls, including policy enforcement, continuous monitoring, and compliance validation.
Architect and support network segmentation initiatives aligned with zero-trust architecture principles.
Deploy and manage zero-trust/SASE secure remote access solutions, including zero-trust solutions.
Administer Identity and Access Management (IAM) controls, ensuring strong authentication, least privilege, and secure access governance.
Manage Microsoft EntraID capabilities, including Conditional Access policies and Microsoft Authenticator for MFA.
Deploy, monitor, and respond to alerts from CrowdStrike (Endpoint Detection & Response - EDR).
Support OT/IoT/Medical device security initiatives to enhance visibility, vulnerability identification, remediation, and risk reduction
Investigate security alerts, support incident response efforts, and coordinate remediation with IT and infrastructure teams.
Maintain security documentation, system configurations, and operational runbooks.
Qualifications/Requirements:
Experience:
Minimum 5-7 years IT Infrastructure or IT Security experience, required
Hands-on experience with Cisco security technologies, including:
Bachelor's degree in information technology, Information Security, or related/relevant discipline.
*Equivalent combination of experience and education may be substituted for degree requirements*
Licenses / Certifications:
CISSP or equivalent industry certification, required
Other:
Knowledge of computer systems and applications in meeting medical data reporting requirements Knowledge of program planning and evaluation techniques
Ability to compile, analyze and interpret InfoSec data and forecast trends
Ability to work well with other technology and medical professionals
Ability to communicate effectively, both orally and in writing; ability to effectively use computer applications such as spreadsheets, word processing, calendar, e-mail and database software in performing work assignments
Good judgment, initiative, accuracy, thoroughness and physical condition commensurate with the demands of the position.
Special Requirements:
Experience configuring and managing Palo Alto Networks firewalls.
Experience with enterprise email security and filtering platforms.
Strong understanding of cloud security fundamentals, including monitoring, policy enforcement, and compliance controls.
Knowledge of network segmentation strategies and zero-trust architecture concepts.
Practical experience with Microsoft Entra, including Conditional Access and Microsoft Authenticator deployment.
Experience managing or supporting CrowdStrike (or similar EDR solutions).
Familiarity with OT/IoT/Medical device security platforms, preferably Claroty xDome.
Experience in designing, implementing, and maintaining Zero Trust architecture and operating principle. Experience with Netskope preferred.
Solid understanding of IAM principles, authentication methods (MFA, SSO), and least privilege access.
Strong analytical, troubleshooting, and incident response skills.
About Westchester Medical Group, P.C.
Westchester Medical Group, P.C. is a medical group practice located in White Plains, NY that specializes in Internal Medicine and Cardiology. The group has been providing high-quality medical care to patients in Westchester County for over 30 years. The practice has several locations throughout the county and offers a wide range of services, including primary care, cardiology, gastroenterology, and dermatology. The group is committed to providing personalized care to each patient and has a team of highly trained physicians and staff. Westchester Medical Group, P.C. is privately held and headquartered in White Plains, NY.