DHR Health - US:TX:Edinburg - Days
Summary:
FLSA STATUS: ☒ Exempt • Non-Exempt POSITION SUMMARY: The Senior Security Analyst supports the Information Security program by monitoring, assessing, and responding to cybersecurity threats, vulnerabilities, and risks across the organization. This position acts as a technical and operational bridge between daily security operations and strategic initiatives. The Senior Security Analyst assists in designing, implementing, and maintaining effective security controls, supporting incident response, and performing risk and vulnerability assessments. The role requires analytical expertise, collaboration across IT and clinical departments, and the ability to translate complex security findings into actionable risk mitigation strategies.
POSITION EDUCATION/ QUALIFICATIONS: • Bachelor's degree in information security, Computer Science, Information Systems, or a related field preferred.
• Minimum 4-6 years of progressive experience in information security, system administration, or cybersecurity operations.
• Experience in healthcare IT environments preferred.
• Hands-on experience with security monitoring tools (SIEM, IDS/IPS, endpoint protection, vulnerability management).
• Familiarity with TrendMicro, CrowdStrike, or similar endpoint protection technologies.
• Working knowledge of firewalls, Active Directory, identity, and access management (IAM), and network segmentation.
• Understanding of incident response procedures, forensic analysis, and log correlation.
• Knowledge of security frameworks and standards such as HIPAA, HITECH, NIST, ISO27001, and PCI-DSS.
• Excellent analytical, problem-solving, and communication skills.
• Security certifications (e.g., Security+, CEH, CySA+, CISSP Associate) preferred.
• Some evening or weekend work will be required.
JOB KNOWLEDGE/EXPERIENCE: • Must be experienced with active directory and have a solid technical background
• Understanding of Access Controls
• Understands existing identity data in the different systems and determine ways to integrate into IdM or Active Directory
• Understanding of industry accepted standards
• Understands identity management processes and identify opportunities to automate additional functions within the company
• Understanding of governance/ access certification
• Understanding of Federation standards and SSO concepts
• Knowledge of Power Shell, SQL programming, understanding of Web Services standards
• Knowledge of Active Directory (security model, LDAP protocol, and administrative tools)
• Knowledge of Exchange Server (email configuration, mailbox management, and mailbox creation)
• Knowledge of SQL Server (database/table/view definitions, backup/restore, performance tuning
Responsibilities:
POSITION RESPONSIBILITIES: - Monitor network, application, and system logs for indicators of compromise (IOCs) and anomalous activity.
- Investigate, contain, and remediate cybersecurity incidents under the guidance of the Information Security Officer.
- Perform and document vulnerability assessments, risk analysis, and coordinate remediation with system owners.
- Maintain and tune SIEM and endpoint protection systems to ensure optimal detection and response capability.
- Participate in security awareness and training initiatives for staff.
- Review and recommend improvements to access control policies and configurations in Active Directory, VPNs, and key applications.
- Assist in security reviews for new systems, vendors, and integrations.
- Support configuration and change management processes for security devices and applications.
- Conduct periodic threat modeling and assist in updating organizational risk registers.
- Collaborate with Infrastructure and Application teams to embed security best practices in system designs and patch management.
- Generate regular security posture and incident trend reports for management review.
- Contribute to the development and refinement of security policies, standards, and procedures.
- Support compliance audits and respond to audit findings related to information security.
LINES OF REPSONSIBILITIES: (Chain-of-command)
1. Information Security Officer → 2. Director
Other information:
CUSTOMER SERVICE: Provide excellent customer service to all DHR customers. All employees are required to attend the DHR C.A.R.E.S program which outlines the Customer Service Principals including: Commitment, Accountability, Respect, Excellence and Service.
AGE SPECIFIC:
Employees must be able to demonstrate the knowledge and skills necessary to provide care appropriate to the age of the patients served in his/her assigned unit. The individual must demonstrate knowledge of principles of growth and development over the life span and possess the ability to assess data reflective of the patient's status and interpret the appropriate information needed to identify each patient's requirement relative to his or her age.
I have read and reviewed my job description with my supervisor or designee and I understand the job I am expected to perform.
If applicable ____________ certification will be completed within _________ time frame of hire/transfer date.
Employee Signature: Date:
Transfer/Hire Date Effective: .