Security Analyst II - IS INFO SECURITY

Kettering Health

$80K — $95K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field (or equivalent experience)
  • 3-5 years of experience in information security or related IT roles
  • Hands-on experience with security monitoring and incident response
  • Experience with vulnerability management tools and endpoint, network, and identity security controls
  • Working knowledge of HIPAA Security Rule, Windows and Linux systems, networking fundamentals, and healthcare attack techniques
  • Strong analytical, documentation, and communication skills
  • Ability to work in a regulated, patient-care-focused environment

Responsibilities

  • Monitor security events and alerts to detect potential threats to healthcare systems and data
  • Investigate and document security incidents involving sensitive healthcare information
  • Support incident response activities, including containment and recovery efforts
  • Conduct vulnerability scanning and risk assessments of healthcare applications and devices
  • Assist with remediation efforts and validate security controls with stakeholders
  • Support compliance with HIPAA, HITECH, and organizational security policies
  • Maintain security documentation and contribute to security awareness initiatives

Benefits

  • Opportunities for professional development and continuing education
  • Collaborative work environment with cross-functional teams
  • Contributions to health information protection and patient safety
  • Involvement in a rapidly evolving field of healthcare cybersecurity
  • Supportive organizational culture focused on compliance and risk management
Full Job Description
Preferred Qualifications

Position Summary

The Information Security Analyst II supports the protection of sensitive healthcare information, clinical systems, and technology infrastructure. This role focuses on threat detection, incident response, vulnerability management, and compliance with healthcare regulations such as HIPAA and HITECH. The analyst collaborates with IT, clinical, and business stakeholders to reduce risk and ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI).

 

Key Responsibilities

  • Monitor security events and alerts using SIEM, EDR, and other security tools to detect potential threats impacting healthcare systems and data
  • Investigate, respond to, and document security incidents involving ePHI, clinical applications, and enterprise infrastructure
  • Support incident response activities including containment, recovery, root0cause analysis, and post0incident reporting
  • Conduct vulnerability scanning and risk assessments of servers, endpoints, medical devices, and healthcare applications
  • Assist with remediation efforts and validate security control effectiveness in collaboration with IT, clinical engineering, and application teams
  • Support compliance with healthcare regulatory requirements including HIPAA, HITECH, and organizational security policies
  • Participate in audits, risk assessments, and third0party security reviews
  • Maintain and update security documentation, incident response playbooks, and standard operating procedures
  • Contribute to security awareness initiatives and provide guidance to staff on protecting patient information
  • Stay informed of emerging healthcare cybersecurity threats, ransomware trends, and industry best practices

Required Qualifications

  • Bachelor0degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience)
  • 305 years of experience in information security, security operations, or related IT roles
  • Hands0on experience with:
    • Security monitoring and incident response
    • Vulnerability management tools and processes
    • Endpoint, network, and identity security controls
  • Working knowledge of:
    • HIPAA Security Rule requirements
    • Windows and Linux operating systems
    • Networking fundamentals (TCP/IP, DNS, firewalls)
    • Common attack techniques targeting healthcare environments
  • Strong analytical, documentation, and communication skills
  • Ability to work effectively in a regulated, patient0care0focused environment
  •   no more than 50-75 miles from KH ASB

Preferred Qualifications

  • Experience in healthcare, hospital, payer, or clinical environments
  • Familiarity with electronic health record (EHR) platforms and clinical systems
  • Experience securing cloud0based healthcare workloads (Azure, AWS, or GCP)
  • Scripting or automation experience (PowerShell, Python, or similar)
  • Certifications such as:
    • CompTIA Security+ or CySA+
    • HCISPP, SSCP, GCIH, or similar

 

Similar Jobs

More Jobs at Kettering Health

More Healthcare Jobs

Find similar Security Analyst II - IS INFO SECURITY jobs: