Information Security Analyst
HealthTech PartnersJob Title: Information Security Analyst
Reports to: Information Security Manager
Employment: Full-Time, Exempt
Company Summary:
StationMD is a telehealth company dedicated to serving individuals with intellectual and/or developmental disabilities (I/DD). All StationMD clinicians are board-certified and specially trained to treat individuals with I/DD. Clinicians are available 24/7 via telemedicine for urgent and non-urgent medical matters. StationMD also offers scheduled psychiatry telemedicine to individuals with I/DD. In providing this suite of services, StationMD enables individuals with I/DD faster access to high-quality care and substantially reduces unnecessary medical costs.
Position Summary:
StationMD is seeking an Information Security Analyst to serve as a core member of the Security Operations Center (SOC), responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats and incidents. This role focuses on triaging security alerts, enhancing SIEM capabilities, and maintaining the organization's security monitoring infrastructure to protect against cyber threats.
This is a fast-paced, growth-stage environment with frequently shifting priorities, and the successful candidate will be comfortable balancing multiple concurrent initiatives.
Essential Duties and Responsibilities:
- Serve as a core member of the Security Operations Center (SOC), providing real-time monitoring and alert triage coverage
- Review of security event logs and alerts from security systems and tools
- Provide an analysis of security events and investigate cybersecurity threats
- Identify and communicate threat intelligence
- Analyze, document, and escalate security events and alerts per policy
- Maintain updated knowledge of security threats, vulnerabilities, and mitigation techniques
- Enhance and customize SIEM monitoring capabilities and rule sets
- Manage and improve SIEM data collection and alerting capabilities
- Conduct regular testing and maintenance on monitoring systems
- Tune alert thresholds to reduce false positives while maintaining detection efficacy
- Regular review of security configurations, such as firewall configurations
- Review and act on vulnerability scan results (Qualys)
- Provide occasional after-hours and weekend support for security alerts and incidents
- Other duties as assigned
Required Qualifications:
Education/Certification
- Undergraduate degree in Computer Science, Cybersecurity, or related fields
Qualifications/Requirements
- 2 years of experience in IT, Information Security, Compliance, Legal, Data Privacy, or a related industry (internship experience may be acceptable)
- General knowledge of cloud IaaS products such as AWS and Microsoft Azure
- Good troubleshooting/problem-solving skills
- Excellent writing and communication skills
- Ability to thrive in a fast-paced environment with competing priorities
Preferred Qualifications:
- Previous experience in healthcare information security
- Working knowledge of Linux systems
- General knowledge of SIEMs, including Wazuh/ELK Stack
- Experience with vulnerability scanning tools such as Qualys
- Experience maintaining endpoint detection and response (EDR) systems
- Experience creating correlation rules for the purpose of improving security monitoring
- Familiarity with the MITRE ATT&CK framework
- Understanding of cloud security, including cloud-native logging and monitoring tools (e.g., AWS CloudTrail)
- Working knowledge of scripting languages (Python, Bash), and working with REGEX
Salary:
Commensurate with experience
Location:
This position is fully remote, with optional time in office if within commuting distance of Maplewood, NJ.
This role may involve access to Protected Health Information (PHI) and is subject to HIPAA and organizational data protection policies, including background screening and confidentiality agreements as a condition of employment.