Job Summary
Under the general direction of the Manager, Risk Assessment, the Security Analyst will support the Risk Assessment team in delivery of assigned projects and engagements. The role requires a working knowledge of the support elements which compromise an effective information security program, inclusive of common industry frameworks, standards and best practices, and select laws and regulations. Key responsibilities for this role include supporting and conducting information security risk assessments while maintaining a consultative mindset when providing thoughts and guidance to clients.
Essential Job Functions
The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required.
§ Support senior team members and project leads when assigned client projects in a way which helps ensure clear communication, managed client expectations, and timely delivery
§ Provide assessment services to clients in both in-person and virtual settings
§ Support the creation and delivery of risk assessment reports based on evaluations of observed controls and workflows
§ Deliver high-quality, professional, and consistent services when providing guidance and support to clients
§ Contribute to the maintenance and continuous improvement of Fortified services and deliverables
§ Maintain a working knowledge of healthcare information security and privacy laws and regulations alongside industry frameworks including, but not limited to: HIPAA, CISA CPGs, and the NIST CSF 2.0
§ Possess a working understanding of how technical controls (e.g., EDR/XDR/MDR, SIEM, firewalls) operate within an organization’s environment and what level of security coverage they provide
Knowledge & Skills
Education & Experience
§ Bachelor's degree from a four-year college or university or combination of education and experience
§ 2+ years’ experience in all or most of the following:
o Information security consulting, preferably with a healthcare background
o Performing risk assessments in the context of information security
o Supporting an organization’s information security program creation or maturation
o Information security frameworks and/or standards such as the HITRUST CSF, the NIST CSF 2.0, and/or ISO 27001
§ Information security experience in a hospital setting highly preferred
Special Skills & Knowledge
§ Ability to be flexible and manage tasks across multiple engagements simultaneously
§ Analytical skillset which enables the individual to efficiently and accurately gain an understanding of how effectively a control or process operates within an environment
§ Consultative mindset which enables the individual to provide recommendations and solutions for clients as they apply to that specific client’s organization
§ Detail and results oriented, skilled at both planning and hands-on execution
§ Ability to excel in a team-oriented, collaborative office environment
§ Intermediate understanding of network infrastructure (both cloud and on-premises) and security concepts
§ Intermediate understanding of what elements comprise an effective information security program
§ Intermediate understanding of information security frameworks and how framework content applies to an individual system or an organizational program
§ Exceptional problem-solving abilities alongside a desire to continually learn new concepts related to the field
§ Exceptional written, verbal, and presentation skills
Licenses, Certifications, etc.
§ Preferred certifications include: Security+, AWS Certified Security, Azure Security Engineer Associate
Competencies
§ Service Delivery – Execution of risk assessments and related services as directed by Fortified.
§ Project Management – Manage assessments and relationships across multiple client accounts while maintaining consistent high-quality service delivery
§ Communication – Leverage soft skills to effectively communicate identified gaps to clients while also recommending solutions that are the most effective based on the client’s environment and infrastructure
Requirements
Supervisory Responsibility
§ Risk assessment services delivered within the Assessment Services business unit
Working Conditions & Travel Requirements
§ Hybrid in our Exton, PA office
§ Valid driver’s license
Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.