Are you passionate about the patient experience? At HCA Healthcare, we are committed to caring for patients with purpose and integrity. We care like family! Jump-start your career as a(an) Senior Security Analyst today with Galen College of Nursing.
Job Summary and Qualifications
Sr Security Analysts are responsible for performing a wide range of tasks that support the ongoing maturation of the HCA Information Protection & Security (IPS) program, including: monitoring and triaging security alerts; serving as the day-to-day operational owner for Managed Detection & Response (MDR) alert and ticket review and closure; coordinating incident response activities with MDR provider, corporate cyber teams, IT, and business stakeholders; driving consistency and visibility of IPS activities; working with business owners to protect customers and prevent data loss; and providing guidance and consultation to colleagues at every level to reduce or eliminate risky behaviors. They are responsible for helping workforce members appropriately comply with the company's IPS requirements while supporting timely investigation and closure of cyber security events. This role requires extensive focus on operational execution, documentation, and follow-through, while building and expanding relationships with key stakeholders who support IPS objectives and activities.
The Senior Information Security Analyst supports the DISA by handling security alerts, maintaining incident and ticket queues, performing approved containment actions, supporting DFIR and threat analysis activities, supporting operational health of security tools and integrations, and helping implement IPS and cyber defense initiatives across the Galen College of Nursing environment.
The Senior Information Security Analyst must have a combination of skills including written and verbal communication skills, interpersonal skills, attention to detail, critical thinking, and the ability to coordinate, influence, guide, and/or lead others necessary to accomplish IPS and cyber defense goals.
Risk Management
- Coordinate and perform risk assessments using corporate-provided tools and templates under the direction of the DISA and Consulting Information Security Analyst.
- Drive and manage execution of corrective and risk treatment plans in concert with Cyber Issues Management to address deficiencies identified during risk assessments, security alerts, or incident reviews.
- Assist the DISA and Consulting Information Security Analyst in ensuring that designated committees receive, document, track, investigate, and sponsor remediation of security control deficiencies, suspected IPS incidents, cyber security events, and complaints.
- Work with Corporate Information Security / Architect Team, IT, IAM, and other technical teams to identify appropriate security controls as part of the field intake process and validate that required security controls are implemented and working as designed.
- Perform Security Risk Analysis (SRA) support activities to validate that required security controls are in place in order to drive ongoing compliance with IPS policies, standards, and operational procedures.
- Support audit response activities to address IPS issues identified by Internal Audit, external auditors, partners, the HCA cyber teams, or other security monitoring functions.
- Review vulnerability, exposure, secure web gateway, cloud access, endpoint, identity, and network security findings from approved security platforms; assess severity, business impact, and remediation urgency; coordinate with IT, IAM, endpoint support, vendors, and business owners to track findings through closure.
- Support vulnerability management and secure access operations by validating remediation evidence, documenting exceptions, escalating high-risk or aging findings, and identifying recurring control gaps or improvement opportunities.
Issues Tracking and Resolution
- Monitor, review, investigate, and triage security alerts from The MDR provider, M365, cloud, endpoint, network security tools, and other approved security tools based on criticality and business impact.
- Serve as the day-to-day operational owner for MDR alert and ticket review and closure by managing assigned security tickets and alert queues, documenting findings, tracking remediation actions, validating resolution, escalating when appropriate, and closing tickets in accordance with established procedures.
- Coordinate with MDR, HCA cyber defense teams, IT, IAM, endpoint support, application owners, vendors, and business stakeholders to support timely investigation and remediation of security events.
- Perform approved operational containment actions such as revoking user sessions, suspending or disabling accounts, resetting credentials, removing access, and initiating endpoint isolation through approved tooling and documented procedures.
- Review available evidence including Microsoft Entra ID sign-in logs, audit logs, Conditional Access events, SIEM incidents & alerts, endpoint telemetry, DLP/DSPM events, and ticket history to support incident review and root cause analysis.
- Provide guidance to field resources and business owners on how to properly remediate identified threats, risky behaviors, or security control gaps.
- Continuously improve documentation of incident handling, ticket closure, root cause analysis, lessons learned, and repeatable processes used to resolve security issues.
- Support initial cyber investigation and DFIR activities, including Windows artifact analysis, memory analysis, network forensic analysis, endpoint and account activity review, evidence preservation support, and documentation of investigative findings.
- Apply structured analysis methods such as Analysis of Competing Hypotheses and Kill Chain analysis to validate potential threats, understand adversary behavior, determine likely root cause, and support escalation or remediation recommendations.
- Monitor approved digital media, threat intelligence, and security reporting sources for threats or other security concerns that may impact Galen locations, students, colleagues, or leadership; document findings and escalate through appropriate channels.
Execution
- Provide ad hoc IPS and cyber defense guidance and consultation to workforce members and colleagues that balances business and security requirements.
- Educate Galen ITG colleagues and business stakeholders on security policies, standards, alert handling procedures, remediation expectations, and ticket response processes to help ensure compliance.
- Assist the DISA and Consulting Information Security Analyst in supporting and driving enterprise, division, and Galen-specific IPS projects and cyber defense initiatives to a successful end and ensure that required processes are adopted and maintained.
- Support implementation of initiatives assigned by the DISA and Consulting Information Security Analyst, including process changes, playbook development, monitoring enhancements, ticket workflow improvements, and security control adoption.
- Facilitate, and lead where appropriate, proactive IPS communication and awareness activities including follow-up education for workforce members exhibiting risky behaviors and/or behaviors that violate Company IPS policies and standards.
- Prepare operational reporting related to MDR ticket volume, alert trends, remediation status, incident aging, recurring issues, and other metrics needed by the DISA.
- Lead and coordinate implementation and adoption of assigned technology and process changes.
- Support operational management of approved security platforms by assisting with configuring security tools, managing integrations, maintaining SIEM ingestion, performing tool health checks, troubleshooting tool performance, supporting API integrations, and coordinating security platform upgrades with responsible engineering teams.
- Assist the Consulting Information Security Analyst with implementation of cyber defense initiatives resulting from MDR findings, incident reviews, recurring ticket trends, Microsoft security alerts, and DISA priorities.
Vendor Systems Security
- Collaborates with system business owners to ensure vendor contracts are in place for department and IT systems and services.
- Work with appropriate business, IT, supply chain, and corporate IPS stakeholders to help ensure specific systems, services, and devices receive proper security assessments and remediation.
- Work with business, purchasing, and IT stakeholders to ensure proper controls are in place for existing vendor-maintained solutions.
- Work with system business owners and vendors to document system vulnerabilities and document mitigation controls or remediation actions.
- Coordinate security event and ticket follow-up for vendor-maintained systems identified through MDR, SIEM, HCA cyber teams, or other approved monitoring sources.
- Ensure vendor systems use approved connectivity, remote management and monitoring.
- Performs other duties as assigned
- Practices and adheres to the “Code of Conduct” philosophy and “Mission and Value Statement.”
What qualifications you will need:
- Bachelors Degree three or more years of experience in a relevant field or
- High School Graduate/Equivalent and FIve or more years of experience in a relevant field
- One or more years of experience in cybersecurity operations, SOC alert triage, DFIR support, security tool operations, information security domains, risk management, and/or education or healthcare IT operations
Licenses, Certifications, & Training:
- SEC+, CySA+, GCIH, GCIA, GCED, GCFE, GCFA, Microsoft SC-200, Microsoft AZ-500, CISSP, CISA, CISM, CRISC, SSCP, or other relevant certifications in information security, cyber defense, digital forensics, and cyber risk management.
Knowledge, Skills, Abilities, Behaviors:
- Experience managing security alert queues, triaging security events, documenting incident activity, and tracking tickets through closure.Required
- Experience with security tools and technologies such as M365 security tools, SIEM, EDR, phishing triage, threat intelligence, and work ticketing systems.Required
- Experience coordinating with cyber defense teams, IT, IAM, endpoint support, vendors, and business stakeholders.Required
- Experience in developing and assessing technical and process-based controls, managing risk assessments/investigations, and working with organization management to integrate controls into the scope of existing business practices.Preferred
- Exposure to management and/or operations in healthcare business or IT functional areas.Preferred
- Experience in some combination of audit, risk management, information security, privacy, cyber defense, and information technology.Required
- Knowledge of information security regulations (FERPA or HIPAA Privacy/Security, Sarbanes-Oxley IT controls, Payment Card Industry (PCI))Required Possesses the ability to build and maintain positive team relationships at all levels of the facility, market, and corporate levels.Required
- Possesses a sense of responsibility and accountability and takes ownership and initiative.Required Demonstrates strong critical thinking skills to understand available data, validate potential threats, and communicate conclusions and recommendations.Required
- Creative thinker, always looking for a “better way” to deliver value; not stopped or discouraged by adversity.Required Maintains professional demeanor, appearance, and positive attitude.Required
- Adaptable and flexible, with the ability to handle ambiguity and sometimes changing priorities.Required
- Experience or working knowledge of incident response and DFIR concepts including Windows artifact analysis, memory analysis, network forensic analysis, evidence handling, root cause analysis, Analysis of Competing Hypotheses, and Kill Chain analysis.Preferred
- Experience with security tool operations including configuring security tools, managing integrations, maintaining SIEM ingestion, performing tool health checks, troubleshooting tool performance, API integrations, and coordinating security platform upgrades.Preferred
- Experience monitoring digital media, threat intelligence sources, or security reporting channels for physical threats, safety concerns, or other security events requiring escalation.Preferred
- Ability to serve as the day-to-day operational owner for MDR alert and ticket review and closure while maintaining accurate documentation, escalation, and follow-through.Required
Benefits
Galen College of Nursing, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
- Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services
- Wellbeing support, including free counseling and referral services
- Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence
- Savings and retirement resources, including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling
- Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing
- Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts
Learn more about Employee Benefits
Note: Eligibility for benefits may vary by location.
HCA Healthcare has been recognized as one of the World's Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"The great hospitals will always put the patient and the patient's family first, and the really great institutions will provide care with warmth, compassion, and dignity for the individual."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
If you are looking for an opportunity that provides satisfaction and personal growth, we encourage you to apply for our Senior Security Analyst opening. We promptly review all applications. Highly qualified candidates will be contacted for interviews. Unlock the possibilities and apply today!
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.