Cybersecurity Business Analyst

Posted 6 Days Ago
Waltham, MA, USA
In-Office
137K-229K Annually
Senior level
Healthtech
The Role
Partner with engineering, operations, and security teams to assess and improve security posture, design and enforce architecture and Zero Trust controls, implement security frameworks and configuration guidelines, support application and platform security (DAST/SAST), and manage tactical execution of security risk reduction and compliance activities.
Summary Generated by Built In

PRINCIPAL DUTIES AND RESPONSIBILITIES:  

  • Work closely with engineering, operations, and security specialists to ensure adequate security solutions and controls are in place throughout all IT systems and platforms to mitigate identified risks sufficiently, and to meet business objectives and regulatory requirements. 

  • Assess and understand the organization’s current security posture and future architecture requirements, providing recommendations for improvement and risk reduction. 

  • Ensures implemented solutions support cybersecurity architecture objectives (availability, scalability, performance, security, etc.), as appropriate, and monitors implementation activities to ensure architecture and design principles are upheld. 

  • Supports the implementation of technical artifacts (frameworks, standards, and repeatable patterns, etc.) that constitute the enterprise information security architecture and solutions and work with infrastructure teams to ensure adoption. 

  • Serve as a security expert in application development, database design, network and/or platform (operating system) efforts, helping project teams comply with enterprise and security policies, industry regulations, and best practices. 

  • Design security configuration guidelines for information technology devices and systems, as well as mechanisms for assessing compliance within those guidelines. 

  • Participate in the design and implementation of a comprehensive Zero Trust Architecture framework to ensure the confidentiality, integrity, and availability of our systems and data. 

  • Contribute the creation of security policies, access controls, and authentication mechanisms based on Zero Trust principles. 

  • Evaluate existing network and security infrastructure, identify vulnerabilities, and recommend enhancements to align with Zero Trust principles. 

  • Familiarity with OWASP, SANS Top 20 and prevention/remediation techniques and their implementation. 

  • Ability to work in a group development environment as an application security engineer across software engineer, QA engineer and build/test/release engineer teams. 

  • Experience in deploy/maintain/support/analyzing DAST/SAST scan result 

  • Manage the tactical execution of short- and long-term objectives through the coordination of activities with a direct responsibility for results, including costs, methods, and staffing. 

 

PHYSICAL DEMANDS AND WORKING CONDITIONS: 

  • The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. 

 

SUPERVISION:  

  • None 

 

EDUCATION:  

  • Bachelor's degree in management information systems, Computer Science, or business/science related field required. 

 

EXPERIENCE AND REQUIRED SKILLS:   

  • 6-10 years of experience working with internal/external audits or risk management - methods and techniques for the assessment and management of risk. 

  • Familiar with the management, operational, and technical aspects of IT Security in a complex enterprise environment. Additional experience in cyber risk management and assessments will be considered. 

  • Strong understanding of network architecture, protocols, and security technologies. 

  • Familiarity with cloud computing platforms, such as AWS, Azure, or Google Cloud, and their associated security services. 

  • Proficiency in security frameworks and standards, such as ISO 27001, NIST, and CIS. 

  • Ability to operate as a pro-active and result-driven problem solver with excellent analytical and interpersonal skills. 

  • Ability to understand IT processes, management objectives risk appetite and tolerances and impact of objectives, of changes to risk profiles. 

  • CISA, CISSP, CRISC, or other relevant certification(s) desired. 

  • Strong client services orientation and communication skills coupled with a high sense of urgency to keep appropriate partners informed, including solutions to overcome obstacles to deliver to expectation. 

  • Experience in IT governance, risk, and controls, including governance frameworks. 

  • Demonstrated technical writing, communication, and presentation skills. 

  • Ability to work effectively in a team environment.   

  • Creativity in addressing technical challenges.   

  • Proven record to deliver results. 

The rate of pay for this position will depend on the successful candidate’s work location and qualifications, including relevant education, work experience, skills, and competencies.
Annual Rate: $137,000.00 - $229,000.00
Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave.

Fresenius Medical Care is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sexual orientation, gender identity, parental status, national origin, age, disability, military service, or other non-merit-based factors

Skills Required

  • Bachelor's degree in management information systems, Computer Science, or related field
  • 6-10 years experience with internal/external audits or risk management
  • Familiarity with management, operational, and technical aspects of IT security in a complex enterprise
  • Strong understanding of network architecture, protocols, and security technologies
  • Familiarity with cloud platforms and their security services (AWS, Azure, Google Cloud)
  • Proficiency with security frameworks and standards (ISO 27001, NIST, CIS)
  • Experience deploying, maintaining, supporting, and analyzing DAST/SAST scan results
  • Familiarity with OWASP and SANS Top 20 and remediation techniques
  • Ability to work as an application security engineer across development, QA, and build/release teams
  • Experience in IT governance, risk, and controls including governance frameworks
  • Demonstrated technical writing, communication, and presentation skills
  • CISA, CISSP, CRISC, or other relevant certifications

Fresenius Medical Care Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Fresenius Medical Care and has not been reviewed or approved by Fresenius Medical Care.

  • Leave & Time Off Breadth PTO is described as ample for 3x12-hour shifts and is complemented by paid caregiver leave, holidays, and sick time. This range of time-off options provides meaningful flexibility for many roles.
  • Healthcare Strength Medical coverage includes 100% preventive care, office-visit copays, prescription coverage, and disability insurance, while dental covers preventive, basic, and major restorative services up to an annual limit. Vision benefits are also available.
  • Wellbeing & Lifestyle Benefits Wellness programs feature the Rally app with fitness rewards, virtual therapy, and an Employee Assistance Program with free counseling. Additional offerings like digital physical therapy and expert medical opinions broaden holistic support.

Fresenius Medical Care Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Bad Homburg v. d. Höhe
42,197 Employees

What We Do

Fresenius Medical Care is the world’s leading provider of products and services for individuals with renal diseases. We aim to create a future worth living for chronically and critically ill patients – worldwide and every day. Thanks to our decades of experience in dialysis, our innovative research and our value-based care approach, we can help them to enjoy the very best quality of life. Our portfolio encompasses a comprehensive range of high-quality health care products and services as well as various dialysis treatment options for both in-center and home dialysis that are individually tailored to our patients’ needs.

Similar Jobs

Babylist Logo Babylist

Editor

eCommerce • Healthtech • Kids + Family • Retail • Social Media
Easy Apply
Remote or Hybrid
United States
300 Employees
120K-144K Annually

PwC Logo PwC

Supply Chain Consulting - Warehouse Automation Sr. Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
29 Locations
370000 Employees
124K-280K Annually

CrowdStrike Logo CrowdStrike

Sr. Mgr, Operational & Productivity Strategy and Assessment

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
10000 Employees
130K-200K Annually

Enverus Logo Enverus

Vice President/Senior Director, Product Management, Industry Lead - 26122

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
2 Locations
1800 Employees
200K-220K Annually

Similar Companies Hiring

Camber Thumbnail
Fintech • Healthtech • Social Impact
New York, New York
90 Employees
Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account