Get more replies from employers
Send a job-specific resume in minutes.
Join to apply for the Systems Security Analyst role at Brown University Health.
This range is provided by Brown University Health. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.
Base pay range: $102,963.22/yr - $169,000.00/yr
The Systems Security Analyst is a critical member of the Chief Information Security Officer’s (CISO’s) team and reports to the Manager of Information Security Operations. This hands‑on role requires a high level of technical and analytical expertise. Responsibilities include day‑to‑day administration of information security tools, creation of security documentation, and second- and third‑level support for SIEM alerts. The role ensures the organization maintains compliance with regulatory requirements, industry standards, and internal policies while proactively managing security risks.
Consistently applies the corporate values of respect, honesty, and fairness, and the pursuit of excellence in improving community health through customer‑friendly, geographically accessible services.
Monitors, configures, and remediates SIEM, alerting/detection (network & endpoint), log management, phishing detection & response, digital forensics, penetration testing, zero‑trust architecture, threat‑informed defense (MITRE ATT&CK), O365, and security automation.
Monitors and configures security controls across multi‑cloud (Azure / AWS) environments.
Assists in developing and documenting security architecture, policies, standards, and procedures.
Works with third‑party partners to ensure contractual value and performance.
Participates in cloud/on‑premises incident response processes, including tabletop breach exercises.
Ensures preparedness for external audits.
Maintains up‑to‑date technical knowledge through seminars, vendor presentations, and professional literature.
Attends and actively contributes to problem‑management and major‑incident conference calls as required.
Researches and pilots new tools, technologies, controls, and processes to support and enforce security policies.
Monitors emerging threats, vulnerabilities, and best practices to keep controls effective and aligned with the threat landscape.
Provides expertise on security best practices across IT, infrastructure, and enterprise operations.
Contributes to a technical reference library, security advisories, alerts, and information on trends and regulations.
Ensures audit trails, system logs, and monitoring data are reviewed and compliant with policies.
Evaluates baseline security configurations for operating systems, applications, networking equipment, and telecommunications equipment.
Assists staff in resolving reported security incidents.
Ensures compliance with HIPAA, HITECH, PCI‑DSS, NIST, and other regulatory standards.
Researches new threats and security alerts, recommending remedial actions.
Identifies opportunities to improve Security Operations practices and recommends updates to processes and controls.
Provides expert‑level guidance to IT staff and business on all Information Security policies, standards, processes, and procedures.
Works with infrastructure teams and business units to ensure policy compliance and adherence to best practices.
Participates in security projects, providing guidance on policy, process, and procedures.
Participates in compliance/audit activities as requested by internal and external auditors.
Maintains work effort status within SLA’s on the Service Desk and Task Management Platforms.
Identifies risks and performs risk register validations as required.
Participates in a recurring on‑call schedule that includes evenings and weekends.
Performs other duties as assigned.
Functions independently within departmental policies and practices, achieving goals and productivity requirements. Refers unresolved complex issues to the director when clarification of policies or procedures is required.
Functions independently within departmental policies and practices and refers specific complex problems to the direct manager for clarification of policies or procedures.