Full Job Description
Summary/Objective
The Security Administrator is responsible for performing the day-to-day operational activities that support Envision Radiology's enterprise cybersecurity program, including monitoring security events, investigating potential threats, and administering cybersecurity technologies. Working under the direction of the Cybersecurity Manager and the technical guidance of the Security Engineer, this position collaborates with Information Technology teams, Compliance, managed security service providers, and business stakeholders to protect organizational systems and information assets in alignment with HIPAA, HITRUST, the NIST Cybersecurity Framework, and PCI DSS.
Essential Functions
1. Monitors, analyzes, and responds to cybersecurity alerts, events, and incidents by performing initial investigation, triage, documentation, containment activities, escalation, and follow-up in coordination with the Security Engineer and Cybersecurity Manager.
2. Executes vulnerability management activities by conducting vulnerability assessments, validating findings, evaluating risk and business impact, tracking remediation efforts, coordinating with technology owners, verifying corrective actions, and maintaining accurate vulnerability records and reporting.
3. Administers and supports enterprise cybersecurity technologies, including endpoint protection, endpoint detection and response (EDR), email security, identity security, vulnerability management, security monitoring, and other cybersecurity platforms under the guidance of the Security Engineer.
4. Supports cybersecurity governance and compliance activities by assisting with security assessments, audits, evidence collection, policy and procedure documentation, regulatory compliance initiatives, customer security questionnaires, and remediation tracking.
5. Assists with Identity and Access Management (IAM) security activities by supporting access reviews, privileged access monitoring, identity investigations, authentication security, and identity-related security controls in partnership with Information Technology teams.
6. Contributes to the organization's cybersecurity training and security awareness program by assisting with phishing simulations, user education initiatives, security communications, awareness campaigns, reporting, and efforts that promote a culture of cybersecurity throughout the organization.
7. Researches emerging cybersecurity threats, vulnerabilities, attack techniques, and security best practices, recommending operational improvements and contributing to the continuous improvement of Envision Radiology's cybersecurity program.
8. Collaborates with the Security Engineer, Cybersecurity Manager, managed security service providers, vendors, and Information Technology teams to support incident response, technology implementations, operational projects, cross-training, and knowledge sharing.
9. Performs other duties as assigned. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Competencies
1. Security Operations
2. Alert & Event Analysis
3. Incident Triage
4. Risk & Vulnerability Management
5. Security Compliance
6. Technical Problem Solving
7. Communication & Documentation
8. Cross-Functional Collaboration
Supervisory Responsibility
This position has no supervision responsibilities.
Work Environment
This job operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.
Physical Demands
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. While performing the duties of this job, the employee is regularly required to use hands and fingers to handle, feel or operate objects, tools or controls, and reach with hands and arms. The employee is frequently required to talk and hear.
Travel
Minimal travel is expected for this position.
Job Qualifications
Job Qualifications/Experience:
• Two (2) to four (4) years of direct cybersecurity or information security experience, or four (4) to five (5) years of progressively responsible enterprise Information Technology experience with demonstrated cybersecurity responsibilities.
• Experience with enterprise cybersecurity technologies such as endpoint protection, endpoint detection and response (EDR), vulnerability management, identity security, email security, security monitoring, or related security technologies.
• Experience supporting Microsoft enterprise technologies, cloud platforms, or hybrid infrastructure environments.
• Experience participating in security investigations, vulnerability remediation, incident response, security monitoring, or other security operations activities preferred.
• Experience supporting internal or external security audits, compliance activities, or regulatory frameworks such as HIPAA, HITRUST, the NIST Cybersecurity Framework, or PCI DSS preferred.
• Experience working with managed security service providers, third-party security vendors, or security operations partners preferred.
• Scripting or automation experience using PowerShell, Python, or similar technologies preferred.
• Experience supporting healthcare or another highly regulated industry preferred.
• Strong analytical, troubleshooting, documentation, communication, and collaboration skills.
Education/Certifications:
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or an equivalent combination of education and experience.
• One or more of the following certifications preferred: Security+, CySA+ (CompTIA Cybersecurity Analyst), Microsoft Certified: Security Operations Analyst Associate (SC 200), Microsoft Certified: Identity and Access Administrator Associate (SC-300), GIAC Security Essentials (GSEC) or another relevant GIAC certification, CrowdStrike Certified Falcon Administrator, or other relevant cloud, networking, or cybersecurity vendor certifications.
Additional Eligibility Qualifications
None required for this position.
Compliance
Adheres to Envision's Code of Conduct and Compliance Policies and attends annual Compliance training as set forth by the Company.
Company Benefits
The following benefit programs are available to eligible employees. Benefits eligibility is dependent on a variety of factors, including employee classification.
• Health Benefits: Medical/Dental/Vision/Life Insurance
• Company Matched 401k Plan • Employee Stock Ownership Plan
• Paid Time Off + Paid Holidays • Employee Assistance Program
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
OSHA Exposure Rating: 1
It is reasonably anticipated NO employees in this job classification will have occupational exposure to blood and other potentially infectious body fluids.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.