Senior Security Analyst-2

Memorial Hermann Health System

Medical Plaza North, TX

JOB DETAILS
SKILLS
Administrative Skills, Best Practices, Biomedicine, Budgeting, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cisco Network Systems, Communication Skills, Computer Security, Content Filtering Software, Cryptography, Customer Experience, Customer Support/Service, Database Technology, Denial of Service (DoS), Documentation Plan, Documentation Standards, Establish Priorities, Federal Laws and Regulations, Firewalls, GIAC - Global Information Assurance Certification, HIPAA (Health Insurance Portability and Accountability Act), Hubs, Identify Issues, Information Assets, Information Technology & Information Systems, Information Technology/Systems Audit, Information/Data Security (InfoSec), Interpersonal Skills, Intrusion Detection Systems, Intrusion Prevention Systems, Layer 2 Protocols, Leadership, Linux Operating System, McAfee Product Family, Mentoring, Microsoft Active Directory, Microsoft Windows Operating System, NMap, Nessus, Network Administration/Management, Network Operations Center, Network Performance/Analysis, Network Routers, Network Switching, On Call, Open Systems Interconnection (OSI), Organizational Skills, PCI, Patient Care, People Management, Policy Development, Policy Implementation, Problem Solving Skills, Procedure Implementation, Productivity Management, Project/Program Management, QoS (Quality of Service), Risk Analysis, Risk Management, Security Analysis, Security Attacks, Security Monitoring, Security Scanners, Sniffer, Snort, Software Administration, State Laws and Regulations, Systems Analysis, Systems Maintenance, Team Player, Technical Writing, Testing, Time Management, Topology, Unix Operating Systems, Vendor/Supplier Management, Vulnerability Scanners, Wireshark (Ethereal), tcpdump
LOCATION
Medical Plaza North, TX
POSTED
30+ days ago

At Memorial Hermann, we pursue a common goal of delivering high-quality, efficient care while creating exceptional experiences for every member of our community. When we say every member of our community, that includes our employees. We know that when our employees feel cared for, heard, and valued, they are inspired to create moments that exceed expectations, while prioritizing safety, compassion, personalization, and efficiency. If you want to advance your career and contribute to our vision of creating healthier communities, now and for generations to come, we want you to be a part of our team.

Job Summary

Position is responsible for in-depth security administration which includes research, design, installation, testing, configuration, implementation, troubleshooting, and maintenance of security systems and services. A Senior Security Analyst collaborates with application owners, project managers, vendors, and end-users to provide design and administrative services.

---

Job Description

Minimum Qualifications

Education: Bachelors degree preferred or equivalent experience

Licenses/ Certifications: (None)

Experience / Knowledge / Skills:

• Four (4) years experience in information security and/or IT auditing • One (1) year of recent work experience in providing security solutions to large network environment (15,000+ node network) • At least one (1) active security certification (example: CISSP, GIAC, CISA, CISM) - Preferred • Strong knowledge of security tools including firewalls, IPS, IDS, encryption, SEIM, vulnerability scanners, and other security tools • Three (3) years of at least one security tool(s) technology at an in-depth level (firewalls, IPS, IDS, encryption, SEIM, vulnerability scanners, content filtering) • Strong understanding of the conceptual basics of all topologies and protocols in the OSI model • Strong understanding of Active Directory, networking, and database systems • Strong understanding of risk assessment processes and procedures • Record of participating in designing, configuring, troubleshooting, and maintaining new security processes and security technologies (firewall, IPS, IDS, content filtering deployments, Snort, eEye Retina, Nessus, nMap, zixMail or McAfee Endpoint Encryption suite) • Record of participating in information system risk assessments either technical or procedural • Record of developing and implementing information security policies and procedures • Intermediate knowledge of hubs, switches, and routers • Basic knowledge and work experience with Cisco network devices (L2 and L3), large-scale ACL management, Microsoft Windows, Unix/Linux, intrusion prevention systems (IPS), application and packet inspection firewalls, and denial of service (DoS) technologies • Experience with analyzing and troubleshooting network sessions using sniffer tools such as tcpdump, snoop, and WireShark • Demonstrated pattern of growth in ability to lead others • Knowledge of Federal and State security regulation - HIPAA/PCI/HITECH/etc. • Current knowledge of security threats, attack methodologies, security principles, best practices, and evasion techniques • Excellent planning, documentation, and organizational skills • Excellent problem-solving skills • Possess good communication and interpersonal skills to work successfully in a team environment • Strong customer service skills

---

Principal Accountabilities

Leads in the research, installation, configuration, implementation, troubleshooting, and maintenance of security systems and services.

Leads in performing risk assessment of information assets including: information systems, biomedical systems, and data centers.

Develops new and improves upon existing information security risk assessment methodologies.

Performs policy reviews and updates information security policies and identifies new policy requirements.

Leads in implementing controls and procedures to protect information systems from unauthorized or accidental modification, disclosure, or destruction, under the guidance of Senior/Lead Security Analysts or Management.

Provides unassisted support to application owners, project managers, vendors, and end-users.

Works on teams and provides task completion for all levels of projects.

Accountable for meeting and setting project timelines.

Recommends technical and documentation standards.

Responsible for designing and planning of advanced security systems or services.

Provides guidance and mentoring to Security Analyst(s).

Provides status updates to Information Security management on the results of risk assessments.

Researches and makes recommendations regarding the acquisition of new security tools and technology.

Responsible for covering a 7x24 shift of on-call support rotating, which is rotated weekly among the Information Security Risk Management team.

Ensures safe care to patients, staff, and visitors; adheres to all Memorial Hermann policies, procedures, and standards within budgetary specifications, including time management, supply management, productivity, and quality of service.

Promotes individual professional growth and development by meeting requirements for mandatory/continuing education, skills competency, supports department-based goals which contribute to the success of the organization; serves as preceptor, mentor, and resource to less experienced staff.

Demonstrates commitment to caring for every member of our community by creating compassionate and personalized experiences. Models Memorial Hermann's service standards by providing safe, caring, personalized, and efficient experiences to patients and colleagues.

Other duties as assigned.

About the Company

M

Memorial Hermann Health System