Information Security Analyst (Red Team)

Point32Health

Canton (MA)

On-site

USD 91,000 - 137,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Point32Health is seeking a Security Analyst to simulate real-world cyber threats and validate security controls across the organization. You will perform adversary emulation, penetration testing, and security exercises reporting to the Cybersecurity Manager and collaborating with IT teams.

The role requires 3–5 years of professional information security experience, strong technical skills across IAM, cloud security, and SIEM, and an ability to document policies and participate in audits.

Qualifications

  • Bachelor's degree in computer science with emphasis on IT security or equivalent experience.
  • 3-5 years of professional information security experience.
  • 5-7 years in information services including 3 years in security and regulatory compliance.

Responsibilities

  • Consult with Security and Infrastructure staff to evaluate and implement security software.
  • Communicate security exposures or noncompliance to managers.
  • Monitor security logs and report security metrics.
  • Assess security trends and new technologies to meet business goals.
  • Analyze requirements and risks to security-related technology implementation.
  • Develop and produce systems monitoring and metrics reports.
  • Document and review security policies and procedures with Technical Writers.
  • Participate in internal and external audits as required.
  • Participate on project teams and manage assignment tasks.
  • Train information owners in implementing security controls.
  • Other duties as assigned

Skills

Identity & Access Mgmt
SailPoint IAM
PingFederate
SiteMinder/IDM
CyberArk PAM
Cloud security
Active Directory
LDAP Directory Services
Perl
Python
Java
Vulnerability scanning
IDS/IPS
Malware protection
PKI
DLP
O365
Firewalls
VPN
Forensics
Mobile app security
Data warehouse
SIEM
Windows/UNIX
Web portal tech
Salesforce
Communication skills

Education

Bachelor's degree in CS or IT security
Master's degree

Tools

SailPoint
CISM/CISSP (implied)

Job description

Who We Are

Point32Health is a leading not-for-profit health and well-being organization dedicated to delivering high-quality, affordable healthcare. Serving nearly 2 million members, Point32Health builds on the legacy of Harvard Pilgrim Health Care and Tufts Health Plan to provide access to care and empower healthier lives for everyone. Our culture revolves around being a community of care and having shared values that guide our behaviors and decisions. We’ve had a long-standing commitment to inclusion and equal healthcare access and outcomes, regardless of background; it’s at the core of who we are. We value the rich mix of backgrounds, perspectives, and experiences of all of our colleagues, which helps us to provide service with empathy and better understand and meet the needs of the communities where we serve, live, and work.

We enjoy the important work we do every day in service to our members, partners, colleagues and communities. Learn more about who we are at Point32Health.

Job Summary

This position is responsible for simulating real-world cyber threats to evaluate the effectiveness of the organization's security controls, detection capabilities, and response processes. This role conducts adversary emulation, penetration testing, social engineering assessments, and security exercises to identify vulnerabilities, improve the organization's overall security posture, validate security investments, and reduce cyber risk. Reporting to the Cybersecurity Manager, the Security Analyst will work closely with IT teams across all threads where security applies.

Job Description
Key Responsibilities/Duties – what you will be doing (top five):
  • Consult with Security and Infrastructure Services staff to evaluate and implement software systems that provide appropriate security.
  • Communicate potential security exposures, misuse, or noncompliance situation to appropriate managers.
  • Monitor security logs to identify potential security related events. Capture and report security metrics.
  • Monitors security trends and assess potential uses of new technologies to meet identified business goals.
  • Analyze business requirements and risks to technology implementation for security-related issues.
  • Develop and produce systems monitoring and metrics reports and assess the content.
  • Work with Technical Writers to document and review security policy and procedures.
  • Participate in audits both internal and external as required.
  • As required, participate on project teams, and manage the completion of all assigned project related tasks.
  • Train information owners in the implementation of necessary security controls by developing and presenting information security awareness.
  • Other duties as assigned
Qualifications – what you need to perform the job
Education
  • Required (minimum): Bachelor’s degree in computer science with emphasis on IT security required or equivalent experience.
  • Preferred: Master’s degree
Experience
  • Required (minimum): 3-5 years of professional experience
  • Preferred: 5-7 years of progressive experience in information services including 3 years in systems security, including maintenance and use of security products in a distributed enterprise environment, and experience in compliance with federal security regulations.
Skill Requirements
  • Specific working knowledge of and experience in the following work environments:
    • Identity and Access Management
    • SailPoint Identity Management
    • PingFederate
    • SiteMinder/Identity Manager/Provisioning Manager
    • CyberArk PAM
    • Cloud security
    • Active Directory
    • LDAP Directory Services
    • Perl, Python, VBS and Java.
    • Vulnerability scanning and management
    • Intrusion Detection/Prevention System
    • Virus & malware protection
    • Advanced Threat Protection
    • Public Key Infrastructure
    • Data Loss Prevention
    • Microsoft O365
    • Firewalls
    • VPN
    • Forensics
    • Mobile application security
    • Operational data stores, data marts, data warehouse
    • Security Information and Event Management (SIEM)
    • N-tiered infrastructure patterns
    • Windows and UNIX operating system environments
    • Web portal technology and application servers, i.e. Apache Tomcat, WebLogic, WebSphere
    • Data/Computer Operations technology integration and support
    • CRM solutions/Salesforce
  • Excellent communications skills both written and oral
Working Conditions and Additional Requirements (include special requirements, e.g., lifting, travel):
  • Must be able to work under normal office conditions and work from home as required.
  • Work may require simultaneous use of a telephone/headset and PC/keyboard and sitting for extended durations.
  • May be required to work additional hours beyond standard work schedule.
Disclaimer

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Management retain the discretion to add to or change the duties of the position at any time.

Salary Range

$91,188.71 -$136,783.07

Compensation & Total Rewards Overview

The annual base salary range provided for this position represents a range of salaries for this role and similar roles across the organization. The actual salary for this position will be determined by several factors, including the scope and complexity of the role; the skills, education, training, credentials, and experience of the candidate; as well as internal equity. As part of our comprehensive total rewards program, colleagues are also eligible for variable pay. Eligibility for any bonus, commission, benefits, or any other form of compensation and benefits remains in the Company’s sole discretion and may be modified at the Company’s sole discretion, consistent with the law.

Point32Health offers their Colleagues a competitive and comprehensive total rewards package which currently includes:

  • Medical, dental and vision coverage
  • Retirement plans
  • Paid time off
  • Employer-paid life and disability insurance with additional buy-up coverage options
  • Tuition program
  • Well-being benefits
  • Full suite of benefits to support career development, individual & family health, and financial health

For more details on our total rewards programs, visit https://www.point32health.org/careers/benefits/

We welcome all

All applicants are welcome and will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst (Red Team)
Information Security Analyst (Red Team)

P32HS Point32Health Services Inc • Canton (MA)

Hybrid
USD 91,000 - 137,000
Medical, dental and vision coverage
Retirement plans
Paid time off
Disaster Recovery Lead
Disaster Recovery Lead

Point32Health • Connecticut

On-site
USD 117,000 - 177,000
Medical, dental and vision coverage
Retirement plans
Paid time off
+3
Security Analyst
Security Analyst

ImageTrend • United States

Remote
USD 60,000 - 80,000
Bonus
Benefits
Community gains
Senior Security Analyst (Top Secret)
Senior Security Analyst (Top Secret)

UltraViolet Cyber • Springfield (VA)

On-site
USD 105,000 - 120,000
401(k) match
Medical, Dental, and Vision Insurance
Discretionary Time Off Program
Senior Security Analyst – Top Secret
Senior Security Analyst – Top Secret

UltraViolet Cyber • Chantilly (VA)

On-site
USD 105,000 - 120,000
401(k) with employer match
Medical, Dental, and Vision Insurance
Discretionary Time Off Program
+1
Security Operations Specialist
Security Operations Specialist

Point72 Careers • New York (NY)

On-site
USD 200,000 - 250,000
Fully-paid health care benefits
Parental and family leave policies
401(k) with employer match
+1
Sr Business Data Analyst
Sr Business Data Analyst

Point32Health • United States

Hybrid
USD 107,000 - 161,000
Medical, dental and vision coverage
Paid time off
Tuition program
Information Security Analyst
Information Security Analyst

Gifthealth • Columbus (OH)

On-site
USD 73,000 - 86,000
Systems Security Analyst
Systems Security Analyst

Brown University Health • Rhode Island

On-site
USD 102,000 - 169,000
Medical insurance
Vision insurance
401(k)
+3
Information Security Analyst
Information Security Analyst

Talener • Boston (MA)

On-site
USD 125,000 - 175,000
Comprehensive benefits