Cybersecurity Incident Response Analyst II

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Arizona
Remote
Mid level
Healthtech
The Role
The Cybersecurity Incident Response Analyst II at Banner Health actively monitors and responds to cybersecurity threats. Responsibilities include real-time alert handling, incident investigation, remediation recommendations, escalation of incidents, and development of processes. The role requires collaboration with various teams to ensure effective incident management.
Summary Generated by Built In

Primary City/State:

Arizona, Arizona

Department Name:

IT Threat & Vulnerability Mgmt

Work Shift:

Day

Job Category:

Information Technology

Innovation and highly trained staff. The Information Technology professionals at Banner Health are utilizing cutting edge technology to change health care for the better. If you’re ready to change lives, we want to hear from you.

Healthcare is constantly changing, and at Banner Health, we are at the front of that change. As Banner continues to leverage technology to deliver the highest quality of possible care cybersecurity is a top priority. The Cyber Security Operations Center (CSOC) is responsible for monitoring and responding to cyber security threats targeting Banner Health and their patients.

This position helps detect and secure Banner's computing environment against both insider and outsider threats. As a Cybersecurity Incident Response Analyst II, you will be on the frontlines of this effort. Response Analysts respond to threats in real-time through effective analysis, triage and handling of cybersecurity alerts and events, help investigate and remediate cybersecurity incidents, escalate cybersecurity incident as defined by procedure, and help liaise closely other teams to ensure the correct response and remediation of cybersecurity incidents.

The location for this role will be hybrid and does include on call rotation duties.

The typical schedule for this role is Monday - Friday 10 am - 6 pm AZ time.

Within Banner Health Corporate, you will have the opportunity to apply your unique experience and expertise in support of a nationally-recognized healthcare leader. We offer stimulating and rewarding careers in a wide array of disciplines. Whether your background is in Human Resources, Finance, Information Technology, Legal, Managed Care Programs or Public Relations, you'll find many options for contributing to our award-winning patient care.

POSITION SUMMARY
This position helps secure Banner's computing environment against both insider and outsider threats. The incumbent will utilize Banner's various security tools and processes to complete real-time monitoring & alert triage, log correlation analysis, incident analysis & response, intrusion detection, cloud security, trade craft analysis, traffic analysis, malware analysis, forensic artifact handling & analysis, and blue teaming. The incumbent will work collaboratively to develop new procedures and runbooks.
CORE FUNCTIONS
1. Respond to threats in real-time through effective analysis, triage and handling of cybersecurity alerts and events.
2. Perform cyber security investigations and recommend remediation actions.
3. Take ownership of escalated cybersecurity incidents and work until conclusion.
4. Evaluate cyber incidents for legal concerns and where appropriate engage internal forensics and compliance teams.
5. Assist in updating/developing, implementing and operating requisite processes and procedures.
6. Establish and evaluate appropriate Key Performance Indicators, or Key Risk Indicators for accuracy and value.
7. Identify gaps in incident handling use cases and drive/lead the effort to develop process and alerting rules within SIEM technologies.

8. This position is responsible for Cybersecurity across multiple departments system-wide and requires interaction at all levels of staff and management.
MINIMUM QUALIFICATIONS
Must possess strong knowledge of business, cybersecurity and/or computer science as normally obtained through the completion of a bachelor's degree.
Must possess knowledge as normally obtained through four years of experience as cybersecurity operations center analyst, participating in 24/7 incident response. Experience working within a Security Operations Center to include an in-depth understanding of cyber incident response and ability to effectively triage security events. Strong understanding of system, network, and/or application security experience, Linux, virtualization, and networking concepts. Technical proficiency in SIEM (Security information and event management) tools, such as Splunk. Strong Technical proficiency in Endpoint Detection and Response security tools, CASB (cloud access security broker) tools, and DLP (Data Loss Prevention) solutions. Knowledge of utilizing enterprise managed Antivirus and encryption tools. Strong technical competence up and down the technology stack - user interface, applications, communications, infrastructure, database, network, storage, etc. Strong communication skills to work with both collaborative cross-functional team of peers and departments within the company (product development, operations, networking, etc.). Must possess strong critical thinking, analytical, troubleshooting and problem-solving skills. Must be a team player with ability to work autonomously. Ability to prioritize and reprioritize work as required. Experience with Vulnerability Assessment tools and processes and experience leveraging their output to support incident handling. Technical proficiency for creating and updating standard operating procedures. Ability to work calmly under pressure in the face of adversity and threat activity. Ability to establish positive working relationships and garner influence with other teams and team members. Strong desire and aptitude for continuous learning and keeping abreast of new and emerging technology. A collaborative attitude and strong desire to succeed as part of the team. Self-motivated and a strong passion for learning. Knowledge of MITRE ATT&CK Framework and Lockheed Martin Cyber Kill Chain. Knowledge of security threat and attack countermeasures. Experience in automation of tasks through scripting or programming with Bash, Python, Perl, etc.
PREFERRED QUALIFICATIONS

GIAC Continuous Monitoring Certification (GMON). GIAC Certified Incident Handler (GCIH). GIAC Certified Intrusion Analyst (GCIA).
Additional related education and/or experience preferred.

EEO Statement:

EEO/Female/Minority/Disability/Veterans

Our organization supports a drug-free work environment.

Privacy Policy:

Privacy Policy

Top Skills

Bash
Perl
Python
The Company
Casa Grande, AZ
25,000 Employees
On-site Workplace
Year Founded: 1999

What We Do

Banner Health makes health care easier, so your life can be better. Find a provider, schedule an appointment, or find the nearest Banner Health location near you.

Headquartered in Arizona, Banner Health is one of the largest nonprofit health care systems in the country. The system owns and operates 28 acute-care hospitals, Banner Health Network, Banner – University Medicine, academic and employed physician groups, long-term care centers, outpatient surgery centers and an array of other services; including Banner Urgent Care, family clinics, home care and hospice services, pharmacies and a nursing registry. Banner Health is in six states: Arizona, California, Colorado, Nebraska, Nevada and Wyoming.

Want to Transform the healthcare industry? Find your future at Banner Health

Similar Jobs

Remote
Arizona, USA
27053 Employees

CrowdStrike Logo CrowdStrike

Incident Response Principal Consultant - Weekend Shift (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote
Hybrid
USA
10000 Employees
145K-215K Annually
Remote
8 Locations
831 Employees
Remote
US
27104 Employees
149K-269K Annually

Similar Companies Hiring

Zealthy Thumbnail
Telehealth • Social Impact • Pharmaceutical • Healthtech
New York City, NY
13 Employees
Cencora Thumbnail
Pharmaceutical • Logistics • Healthtech
Conshohocken, PA
46000 Employees
Stepful Thumbnail
Software • Healthtech • Edtech • Artificial Intelligence
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account