We are so glad you are interested in joining Sutter Health!
Organization:
SHSO-Sutter Health System Office-ValleyPosition Overview:
Monitors, correlates, and analyzes security event data from a number of security solutions and technical systems. Aids in the development and coordination of system security plans and their implementation. Provides hands-on security administration of a broad range of security duties, including correlating, analyzing, researching, testing, and monitoring. Performs vulnerabilities scans across the environment and track remediation efforts. Develops periodic reports on security metrics, remediation progress, and deficiencies and then present them to management. Assists with preparing training materials and presentations for various cyber security initiatives.Internal Candidates and Contractors for Sutter Health: Please note that if you are selected as the final candidate for this position, a reference check will be conducted with your current supervisor as part of the consideration process. By proceeding with your application, you acknowledge and understand that your current supervisor may be contacted at the appropriate stage of the selection process.
Job Description:
***The selected candidate must be located within the Sutter Health footprint.***
EDUCATION:
Equivalent experience will be accepted in lieu of the required degree or diploma.
Bachelor's in Business, Cybersecurity, Computer Science, Information Technology/Security, Risk Management, or related field
TYPICAL EXPERIENCE:
2 years recent relevant experience.
PREFERRED EXPERIENCE:
Experience in a healthcare, financial services, critical infrastructure, or other highly regulated environment.
Experience investigating incidents, alerts and performing threat hunts.
Experience with security orchestration, automation, and response (SOAR) platforms.
Experience developing or improving incident response playbooks and investigative procedures.
Experience performing memory, disk, network, email, and cloud forensics.
Experience with threat intelligence and incorporating threat intelligence into investigations.
Experience conducting proactive threat hunting.
Experience with malware analysis or reverse engineering.
Experience supporting legal, compliance, privacy, or regulatory requirements associated with security incidents.
Relevant certifications such as GCIH, GCFA, GCIH, GCFE, GNFA, CISSP, Security+, CySA+, or equivalent.
SKILLS AND KNOWLEDGE:
Knowledge of information systems security concepts and current information security trends and practices including security processes and methods.
General knowledge of Federal and State IS security and privacy-related regulatory requirements and laws.
General knowledge regarding National Institute of Standards and Technology (NIST), Health Insurance Portability and Accountability Act (HIPAA), Federal Information Processing Standards (FIPS), and other recognized industry security standards. and best practices.
General understanding of Diagnostic peritoneal lavage (DLP) and DLP technologies.
General understanding of using Microsoft windows workstation and server, Unix/Linux and network OS’s.
Knowledge of software, hardware, databases, networks, firewalls, encryption, and other systems security devices, including a good understanding of end point operating systems (Windows and Linux), internet technologies such as Domain Name System (DNS), routing, Simple Mail Transfer Protocol (SMTP), Hypertext Transfer Protocol (HTTP), Dynamic Host Configuration Protocol (DHCP), and File Transfer Protocol (FTP), and familiarity in a command line environment.
Familiarity in a command line environment.
Written/verbal interpersonal communication skills with the ability to interact effectively with a broad and diverse group of peers, users, and executives.
Proven ability to prioritize work while multi-tasking on assigned work.
Ability to perform and conduct Incident Response and participate in security incident and post incident response process.
Ability to break down highly complex technical topics into language and diagrams understandable to a wide audience.
Working knowledge of common enterprise applications, e-mail, web, cloud, client/server applications.
These Principal Accountabilities, Requirements and Qualifications are not exhaustive, but are merely the most descriptive of the current job. Management reserves the right to revise the job description or require that other tasks be performed when the circumstances of the job change (for example, emergencies, staff changes, workload, or technical development).
Job Shift:
DaysSchedule:
Full TimeDays of the Week:
Monday - FridayWeekend Requirements:
As NeededBenefits:
YesUnions:
NoPosition Status:
ExemptWeekly Hours:
40Employee Status:
RegularSutter Health is an equal opportunity employer EOE/M/F/Disability/Veterans.
Pay Range is $117,436.80 to $176,155.20 / annual salaryThe compensation range may vary based on the geographic location where the position is filled. Total compensation considers multiple factors, including, but not limited to a candidate’s experience, education, skills, licensure, certifications, departmental equity, training, and organizational needs. Base pay is only one component of Sutter Health’s comprehensive total rewards program. Eligible positions also include a comprehensive benefits package.
Skills Required
- Bachelor's degree in Business, Cybersecurity, Computer Science, Information Technology or Security, Risk Management, or a related field; equivalent experience accepted
- 2 years of recent relevant experience
- Experience in healthcare, financial services, critical infrastructure, or another highly regulated environment
- Experience investigating incidents and alerts and performing threat hunts
- Experience with security orchestration, automation, and response platforms
- Experience developing or improving incident response playbooks and investigative procedures
- Experience performing memory, disk, network, email, and cloud forensics
- Experience with threat intelligence and incorporating it into investigations
- Experience conducting proactive threat hunting
- Experience with malware analysis or reverse engineering
- Experience supporting legal, compliance, privacy, or regulatory requirements associated with security incidents
- Relevant certification such as GCIH, GCFA, GCFE, GNFA, CISSP, Security+, CySA+, or equivalent
- Knowledge of information systems security concepts, processes, methods, trends, and practices
- General knowledge of federal and state information security and privacy regulations and laws
- General knowledge of NIST, HIPAA, FIPS, and recognized industry security standards and best practices
- Understanding of DLP and DLP technologies
- Understanding of Windows, Unix/Linux, and network operating systems
- Knowledge of software, hardware, databases, networks, firewalls, encryption, endpoint operating systems, and internet technologies
- Familiarity with command-line environments
- Ability to perform incident response and participate in security incident and post-incident response processes
- Strong written and verbal communication skills
- Ability to prioritize and multitask
- Ability to explain complex technical topics using accessible language and diagrams
- Working knowledge of enterprise, email, web, cloud, and client/server applications
- Must be located within the Sutter Health footprint
Sutter Health Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sutter Health and has not been reviewed or approved by Sutter Health.
-
Healthcare Strength — Healthcare coverage is described as comprehensive, with broad networks and strong wellness support. Family coverage is characterized as low-cost or nearly free in some plan options, reinforcing perceived value.
-
Retirement Support — Retirement offerings include employer matching and, in some cases, a pension after a tenure threshold. Supplemental protections like life and disability insurance add to the overall financial security package.
-
Leave & Time Off Breadth — Paid time off is framed as generous, with examples of sizable PTO allotments early in tenure. Additional supports such as flexible scheduling and leave programs contribute to a sense of time-off breadth.
Sutter Health Insights
What We Do
Sutter Health is one of the nation's leading not-for-profit healthcare networks, which includes award-winning physician organizations, acute care hospitals, surgery centers, medical research facilities and specialty services. Our team of 68,000 doctors, employees and volunteers proudly cares for Northern California. Our facilities and care centers are located in large, urban cities and small, rural communities, from the Pacific Coast to the San Joaquin Valley. You’ll find us in San Francisco, Oakland, Sacramento, the snowy mountains of the Sierra Nevada and Lake Tahoe, Napa Valley, Yosemite and the coastal redwoods. We even have an affiliate in Hawaii. Join us and be part of a dedicated group of professionals committed to putting patients’ needs first and achieving the highest levels of quality, access and affordability.





