Information Security Analyst I

Posted Yesterday
Be an Early Applicant
Hiring Remotely in USA
Remote
77K-101K Annually
Junior
Healthtech • Social Impact
The Role
Monitors and maintains cloud, infrastructure, application, and endpoint security solutions. Investigates incidents, vulnerabilities, and suspicious activity; responds to security tickets; conducts vulnerability assessments, penetration tests, and audits; maintains secure configuration baselines; supports application security, security architecture, policies, and business continuity planning.
Summary Generated by Built In

Position Title: Information Security Analyst I

Department: Technology

Reports to: Information Security Manager                   

Location: Remote

Salary Range: $76,700 - $101,000

Vibrant Emotional Health’s groundbreaking solutions have delivered high quality services and support, when, where and how people need it for over 50 years. Through our state-of-the-art technology-enabled services, community wellness programs, and advocacy and education work, we are building a society in which emotional wellness can be a reality for everyone.

Formerly the Mental Health Association of New York City (MHA-NYC), Vibrant Emotional Health’s groundbreaking solutions have delivered high quality services and support, when, where and how people need it for over 50 years. Through our state-of-the-art technology-enabled services, community wellness programs, and advocacy and education work, we are building a society in which emotional wellness can be a reality for everyone.

Position Overview:

The Information Security Analyst I is responsible for cloud, infrastructure and application security, incident response, auditing, and other relevant aspects of the program, as required. This role is involved in day-to-day operations of the in-place security solutions.  The position plays a key role in protecting the confidentiality, integrity, and availability of all company data and systems.  This may include the identification, investigation, and resolution of security incidents detected by those systems.  Projects may include the implementation of new security solutions, participation in the creation and/or maintenance of policies, standards, baselines, guidelines, and procedures, as well as conducting vulnerability audits and assessments, and working with technology teams to update and maintain system security. The Security Analyst is expected to be fully aware of the enterprise’s security goals as established by its stated policies, procedures, and guidelines and to actively work towards upholding those goals.

Duties/Responsibilities:

  • Perform the deployment, integration, and initial configuration of all new security solutions and of any enhancements to existing security solutions in accordance with standard best operating procedures generically and the enterprise’s security documents specifically.

  • Maintain up-to-date detailed knowledge of the Cybersecurity industry including awareness of new or revised security solutions, improved security processes, and the development of new attacks and threat vectors.

  • Assist with recommending additional security solutions or enhancements to existing security solutions to improve overall enterprise security.

  • Review existing cloud, on-prem, and end-user system configurations, and make recommendations to improve security posture

  • Monitor all in-place security solutions for efficient and appropriate operations.

  • Review logs and reports of all in-place devices, whether they be under direct control (i.e. security tools) or not (e.g. workstations, servers, network devices). Interpret the implications of that activity and devise plans for appropriate resolution.

  • Respond to tickets for addressing security concerns, vulnerabilities, and end-user reported issues.

  • Participate in investigations into problematic activity.

  • Participate in the design and execution of vulnerability assessments, penetration tests, and security audits.

  • Maintain up-to-date baselines using industry standard frameworks such as CIS and CSA for the secure configuration and operations of all in-place devices, whether they be under direct control (i.e. security tools) or not (e.g. workstations, servers, network devices).

  • Maintain operational configurations of all in-place security solutions as per the established baselines and industry best practices.

  • Provide on-call support for end users for all in-place security solutions.

  • Partner with AppDev to identify and remediate vulnerabilities in applications

  • Participate in the planning and design of enterprise security architecture.

  • Participate in the creation of enterprise security documents (policies, standards, baselines, guidelines, and procedures).

  • Participate in the planning and design of an enterprise business continuity plan and disaster recovery plan.

  • Additional duties as assigned.

Required Skills/Abilities:

  • Proven analytical, troubleshooting and problem-solving abilities.

  • Ability to effectively prioritize and execute tasks in a high-pressure environment.

  • Good written, oral, and interpersonal communication skills.

  • Ability to conduct research into IT security issues and products as required.

  • Ability to present ideas in business-friendly and user-friendly language.

  • Highly self-motivated and directed.

  • Keen attention to detail.

  • Team-oriented and skilled in working within a collaborative environment.

  • Familiar with cloud security principles and best practices.

  • Experience working with AWS IAM, infrastructure, security services, logging, and other serverless services.

  • Familiar with AWS Security Hub

  • Experience working with and implementing security controls and system configurations for technologies such as: AWS, Azure, GCP, Microsoft AD, Linux.

  • Working technical knowledge of Cloud and SaaS security solutions and tools.

  • Familiar with DevSecOps, Application Security, or other secure software development lifecycle methodologies.

  • Some scripting experience with bash or Python

  • Some experience with Incident Response or Penetration Testing as a nice to have

  • Familiar with threat modeling methodologies

  • General knowledge of security frameworks and controls such as: NIST (CSF, SP 800-53, SP 800-171), CIS, CSA, ISO27000.

  • Some experience with security systems and tools that may include: Firewalls, WAF, SIEM, SOAR, MDR, IAM, PAM/PIM, Network Packet sniffers, Nmap, IDS/IPS, Vulnerability Management tools, SAST/DAST Burp Suite.

  • Some experience with Encryption, Antivirus/Malware, Penetration Testing, Source Code Scanning.

  • Basic understanding of IP, TCP/IP, and other network administration protocols.

Required Qualifications:

  • College diploma or university degree in Cybersecurity or other computer technology degree and/or two years equivalent work experience.

  • One or more of the following certifications: Any AWS Certified Associate level certifications, AWS Certified Security - Specialty, GIAC Cloud Security Essentials (GCLD), CompTIA Security+, GIAC Security Essentials (GSEC).

  • 2+ years of technical experience working in cloud, application, infrastructure, and/or network security required

  • 1+ year of experience with AWS required

  • 1+ year of experience with Cloud-based security technologies required

  • 1+ year of experience with Linux operating systems required

Physical Requirements:

  • Must be able to remain in a stationary position 50% of the time

  • Will constantly operate a computer and other office productivity machinery, such as a calculator, copy machine, and computer printer

  • Will frequently communicate over video calls with internal and external stakeholders

We determine base pay through a comprehensive review of skills, experience, education, certifications, geographic location, and other relevant factors. The range listed reflects the compensation parameters for the role and does not represent the full compensation package. A complete overview of compensation and benefits will be provided by the Talent Acquisition team during the hiring process.

Full time employees will be eligible for excellent comprehensive benefits, including medical, dental, vision, supplemental income insurance, employer paid disability insurance, employer paid life insurance, pre-tax FSA for medical and dependent care, and 401K available.

Studies have shown that women and people of color are less likely to apply for jobs unless they believe they are able to perform every task in the job description. We are most interested in finding the best candidate for the job, and that candidate may be one who comes from a less traditional background. Vibrant will consider any equivalent combination of knowledge, skills, education and experience to meet minimum qualifications. If you are interested in applying, we encourage you to think broadly about your background and skill set for the role.

Vibrant Emotional Health is an equal opportunity employer. Applicants are considered for positions without regard to veteran status, uniformed service member status, race, creed, color, religion, gender, gender identity, sex, sexual orientation, citizenship status, national origin, marital status, age, physical or mental disability, genetic information, caregiver status or any other category protected by applicable federal, state or local laws.

Please be aware that fictitious job openings, consulting engagements, solicitations, or employment offers may be circulated on the Internet in an attempt to obtain privileged information, or to induce you to pay a fee for services related to recruitment or training. Vibrant does NOT charge any application, processing, or training fee at any stage of the recruitment or hiring process. All genuine job openings will be posted on our careers page and all communications from the Vibrant recruiting team and/or hiring managers will be from an @vibrant.org email address.


Skills Required

  • College diploma or university degree in Cybersecurity or another computer technology field, or two years of equivalent work experience
  • At least one qualifying certification, including an AWS Certified Associate certification, AWS Certified Security Specialty, GIAC Cloud Security Essentials, CompTIA Security+, or GIAC Security Essentials
  • 2 or more years of technical experience in cloud, application, infrastructure, and/or network security
  • At least 1 year of experience with AWS
  • At least 1 year of experience with cloud-based security technologies
  • At least 1 year of experience with Linux operating systems
  • Experience with AWS IAM, infrastructure, security services, logging, and serverless services
  • Experience implementing security controls and system configurations for AWS, Azure, GCP, Microsoft Active Directory, and Linux
  • Experience with cloud and SaaS security solutions and tools
  • Scripting experience with Bash or Python
  • Knowledge of cloud security principles, DevSecOps, application security, secure software development, threat modeling, security frameworks, and network protocols
  • Some experience with incident response or penetration testing
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
139 Employees
Year Founded: 1969

What We Do

Vibrant Emotional Health is a non-profit organization that connects individuals and families with emotional support and care when, where, and how they need it. The organization focuses on providing accessible care and running innovative community programs to support people across all stages of life, ensuring that critical emotional support is available to those who need it most.

Similar Jobs

In-Office or Remote
Gardiner, ME, USA
575 Employees
52K-76K Annually

ChowNow Logo ChowNow

Operations Manager

Food • Software
Easy Apply
Remote or Hybrid
USA
208 Employees
130K-168K Annually

General Motors Logo General Motors

Sales Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

General Motors Logo General Motors

Sales Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

Similar Companies Hiring

Playground (tryplayground.com) Thumbnail
Kids + Family • Payments • Social Impact • Software
New York City, New York
80 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account