Security Analyst II - IS INFO SECURITY

Kettering Health Network

Miamisburg (OH)

On-site

USD 90,000 - 120,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Kettering Health Network is seeking an Information Security Analyst II to safeguard ePHI and healthcare systems. You will monitor threats, respond to incidents, and perform vulnerability assessments in a regulated clinical environment.

The role requires 3–5 years in information security, a cybersecurity-related degree or equivalent experience, and strong knowledge of HIPAA, Windows, Linux, and networking. On-site location in Ohio with proximity to Kettering Health ASB in Miamisburg.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, Computer Science, or related field or equivalent experience.
  • 3–5 years of information security or security operations experience.
  • Hands-on experience with security monitoring, incident response, and vulnerability management.
  • Knowledge of HIPAA Security Rule, Windows and Linux, TCP/IP, DNS, and firewalls.

Responsibilities

  • Monitor security events using SIEM and EDR to detect threats.
  • Investigate and document security incidents involving ePHI and systems.
  • Support containment, recovery, root-cause analysis, and post-incident reporting.
  • Conduct vulnerability scanning and risk assessments on servers, endpoints, and devices.
  • Assist remediation and verify security controls with IT and clinical teams.
  • Contribute to audits and third-party security reviews and policy updates.

Skills

SIEM monitoring
EDR
Vulnerability management
Incident response
Threat detection
Security controls
Network security
HIPAA knowledge
Analytical communication

Education

Bachelor's degree in Cybersecurity / IT / CS
Equivalent experience

Tools

Security monitoring tools

Job description

Preferred Qualifications

Position Summary

The Information Security Analyst II supports the protection of sensitive healthcare information, clinical systems, and technology infrastructure. This role focuses on threat detection, incident response, vulnerability management, and compliance with healthcare regulations such as HIPAA and HITECH. The analyst collaborates with IT, clinical, and business stakeholders to reduce risk and ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI).

Key Responsibilities

  • Monitor security events and alerts using SIEM, EDR, and other security tools to detect potential threats impacting healthcare systems and data
  • Investigate, respond to, and document security incidents involving ePHI, clinical applications, and enterprise infrastructure
  • Support incident response activities including containment, recovery, root‑cause analysis, and post‑incident reporting
  • Conduct vulnerability scanning and risk assessments of servers, endpoints, medical devices, and healthcare applications
  • Assist with remediation efforts and validate security control effectiveness in collaboration with IT, clinical engineering, and application teams
  • Support compliance with healthcare regulatory requirements including HIPAA, HITECH, and organizational security policies
  • Participate in audits, risk assessments, and third‑party security reviews
  • Maintain and update security documentation, incident response playbooks, and standard operating procedures
  • Contribute to security awareness initiatives and provide guidance to staff on protecting patient information
  • Stay informed of emerging healthcare cybersecurity threats, ransomware trends, and industry best practices

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience)
  • 3–5 years of experience in information security, security operations, or related IT roles
  • Hands‑on experience with:
    • Security monitoring and incident response
    • Vulnerability management tools and processes
    • Endpoint, network, and identity security controls
  • Working knowledge of:
    • HIPAA Security Rule requirements
    • Windows and Linux operating systems
    • Networking fundamentals (TCP/IP, DNS, firewalls)
    • Common attack techniques targeting healthcare environments
  • Strong analytical, documentation, and communication skills
  • Ability to work effectively in a regulated, patient‑care‑focused environment
  • no more than 50-75 miles from Kettering Health ASB in Miamisburg

Preferred Qualifications

  • Experience in healthcare, hospital, payer, or clinical environments
  • Familiarity with electronic health record (EHR) platforms and clinical systems
  • Experience securing cloud‑based healthcare workloads (Azure, AWS, or GCP)
  • Scripting or automation experience (PowerShell, Python, or similar)
  • Certifications such as:
    • CompTIA Security+ or CySA+
    • HCISPP, SSCP, GCIH, or similar
Overview

Kettering Health is a not-for-profit system of 14 medical centers and more than 120 outpatient facilities serving southwest Ohio.Our mission is to live God’s love by promoting and restoring health. Our commitment to our patients is to help individuals be their best. With that context, safety is our top priority. We provide an integrated system of healthcare experts committed to providing exceptional care.

Get your free, confidential resume review.
or drag and drop your file here.