Information Security Analyst I

Socket.dev

Washington

On-site

USD 75,000 - 95,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Socket.dev in Phoenix, AZ is seeking an IT security professional to implement information security policies, audit user access, monitor security logs, and maintain security across applications and networks.

You will participate in incident response, risk assessments, and security investigations, provide guidance to teams, and ensure compliance with federal, state, and local requirements while staying current with industry best practices.

Qualifications

  • Associates degree or equivalent education/experience in information security or IT.
  • 1 year of experience in IT, information security, compliance or risk management.
  • Certifications such as CISSP/SSCP/HCISSP/PCI-ISA/CompTIA Security+ within 1 year preferred.
  • General knowledge of information technology and healthcare is required.
  • Ability to plan and report on small scale projects, individually or in a team.
  • Strong communication and presentation skills across technical and non-technical audiences.

Responsibilities

  • Conduces and participates in security reviews, risk assessments and incident handling.
  • Analyze security architecture to standardize security across infrastructure.
  • Develop and evaluate security policies, procedures and risk implications.
  • Provide technical expertise for security software and project leadership when needed.
  • Ensure compliance with federal, state and local information security laws and guidelines.
  • Audit user access, endpoint controls, and monitor security logs and networks.
  • Investigate security incidents, assist in investigations, and support threat hunting.
  • Monitor SOC communications from Information Security applications.

Skills

Incident management
Root cause analysis
Change control process
Documentation & knowledge bases
Verbal/written communication
Interpersonal skills
Troubleshooting
Time management
Project management

Education

Associate degree in Information Security or related field
1 year of IT/Security/Risk experience or equivalent
CISSP/SSCP/HCISSP/PCI-ISA/CompTIA Security+ or equivalent certification within 1 year

Tools

Palo Alto
Endpoint security
SIEM
Firewalls
NIPS
Web filter

Job description

Primary City/State:

Phoenix, Arizona

Department Name:

IT Threat & Vulnerability Mgmt

Work Shift:

Day

Job Category:

Information Technology
POSITION SUMMARY

This position is responsible for implementation of information security policies, standards, and procedures on all organizational information systems. This position is also responsible for auditing user access, security logs and user permissions. Duties include developing security processes, participating in security investigations, and maintaining documentation. This position supports and maintains the information security infrastructure, including both applications and networking components. This position performs ticket focused tactical incident support, monitors Security Operation Center (SOC) communications and audits Information Technology (IT) controls.

Performs all functions according to established policies, procedures, regulatory and accreditation requirements, as well as applicable professional standards.

CORE FUNCTIONS

1. Conducts and participates in security reviews, evaluations, and risk assessments, assisting in the development and implementation of appropriate recommendations. Participates in the handling of security incidents, recoveries, breaches, intrusions, and system abuses.

2. Analyzes the company's information security architecture, including hardware and software components, with the objective of standardizing security throughout company’s infrastructure. Maintains Information Security controlled applications/systems, updating and monitoring for compliance.

3. Evaluates and assists in the development of security policies and procedures. Evaluates security risk assessments of new systems and upgrades to determine impact to Information Security/Risk Management and the enterprise.

4. Provides technical expertise and support for security software, including operational aspects of the software. Participates in, and on occasion, leads information security projects, including the development of project scope requirements, budgeting, and project planning.

5. Provides guidance, direction, and oversight for compliance with all federal, state, and local mandated information security laws, rules, and guidelines. Remain current with the latest industry technical information.

6. Performs audits of users’ system access and work areas. Performs audits of endpoint security controls. Mitigates any issues with systems that are not in compliance. Monitors anti-virus/malware systems, DLP, encryption, network logs, and users’ Internet access.

7. Participates in problem resolution and incident support. Investigates security incidents that may negatively impact the company (including hacking attempts, intrusions, virus infections, mishandling of information, and other security threats); provide support during large incidents and investigations; participate in threat hunting activities.

8. Monitors Service Operations Center (SOC) communications from Information Security applications.

KNOWLEDGE, SKILLS AND ABILITIES
  • Receptive to learning and mentoring

  • Actively completes routine tasks of moderate complexity and small scope

  • Demonstrates competency in appropriate range of technical skills

  • Understands incident management, root cause analysis and change control process

  • Refers to and applies appropriate documentation and Knowledge Bases

  • Strong verbal/written communication skills

  • Excellent interpersonal skills

  • Troubleshooting and complex problem-solving ability

  • Good judgement and decision-making ability

  • Effective time management skills

  • Project management and organizational skills

MINIMUM QUALIFICATIONS
  • Associates degree in Information Security, Computer Information Systems, or another relevant field, or have equivalent education and experience.

  • One (1) year of relevant experience of any combination of IT, Information Security, Compliance, or Risk Management experience.

  • Certification in one of the following areas within in one year of entering the position: Certified Information Systems Security Professional (CISSP), Systems Security Certified Practitioner (SSCP), HealthCare Information Security & Privacy Practitioner (HCISSP), Payment Card Industry - Internal Security Assessor (PCI-ISA), CompTIA Security+, HIPAA Security, Information Security Technology Fundamentals, Internet Security or ITAA Information Security Awareness.

  • Must demonstrate general knowledge of information technology and healthcare.

  • Needs experience in small scale project planning and reporting either individually or in a team.

  • Requires communication and presentation skills to engage technical and non-technical audiences.

  • Requires ability to communicate and interact across facilities and at various levels. As is typical in this industry, variable shifts and hours and carrying/responding to cell phone may be required.

PREFERRED QUALIFICATIONS
  • Palo Alto and endpoint product experience

  • Firewalls, Network-based Intrusion Prevention System (NIPS), and web filter experience

  • Vulnerability scanning and patch management experience

  • Security Information and Event Management (SIEM) experience

  • Windows & Linux experience

  • HIPAA, PCI-DSS, or previous healthcare experience

  • Security+, GIAC Security Essentials (GSEC), Associate of (ISC)2, CompTIA A+ and/or Network+ certification and training

  • Additional related education and/or experience.

EEO Statement:

EEO/Disabled/Veterans

Our organization supports a drug-free work environment.

Privacy Policy:

Privacy Policy

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst I
Information Security Analyst I

Sonora Quest Laboratories/ Laboratory Sciences of Arizona • Phoenix (AZ)

On-site
USD 90,000 - 130,000
Information Security Analyst I
Information Security Analyst I

Laboratory Sciences of Arizona • Phoenix (AZ)

On-site
USD 80,000 - 110,000
Information Security Analyst I
Information Security Analyst I

Banner Health • Phoenix (AZ), Northern (KY)

Hybrid
USD 65,000 - 90,000
Senior IT Security Analyst
Senior IT Security Analyst

TridentCare • United States

On-site
USD 110,000 - 150,000
IT Security Engineer, Level III
IT Security Engineer, Level III

SherlockTalent • Fort Lauderdale (FL)

Hybrid
USD 90,000 - 120,000
Senior Information Security Analyst
Senior Information Security Analyst

UNIVERSITY OF AZ FOUNDATION • Tucson (AZ)

On-site
USD 90,000 - 110,000
Sr. Information Security Engg.
Sr. Information Security Engg.

SA Technology • Phoenix (AZ)

On-site
USD 95,000 - 120,000
Information Security Engineer
Information Security Engineer

Clinical Reference Laboratory • Lenexa (KS)

On-site
USD 95,000 - 180,000
Medical, Dental, Vision
Life/AD&D
Section 125 FSA Plan
+4
Information Security Analyst, FT, Days
Information Security Analyst, FT, Days

Prisma Health • Greenville (SC)

On-site
USD 90,000 - 130,000
Information Security Analyst I
Information Security Analyst I

Laboratory Sciences of Arizona • United States

On-site
USD 90,000 - 120,000