Jobbie
← Discover jobs
Gifthealth

Information Security Analyst

Industry Cybersecurity

RemotePosted 21h ago

Job description

Description

Information Security Analyst

About Us

At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.

Position Summary

We are seeking an Information Security Analyst to support the day-to-day operation of the organization's security program, with a focus on security monitoring, incident response, vulnerability management, endpoint security, email security, and operational security processes. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.

This role works across Security, IT, Engineering, and other business teams to identify and investigate security risks, coordinate remediation activities, and help ensure security controls remain effective and operational. The ideal candidate is technically curious, comfortable investigating security events, and able to move between hands-on security work, documentation, and coordination with internal teams.

Key Responsibilities

Security Operations: - Monitor and investigate security alerts generated by endpoint, identity, email, cloud, and other security technologies. - Perform initial triage and investigation of suspected security incidents. - Escalate security events based on established severity and incident response procedures. - Support containment, remediation, recovery, and post-incident activities. - Maintain accurate records of security investigations, findings, and response actions. - Assist with the development and maintenance of security incident response procedures and playbooks. - Participate in security exercises and tabletop exercises.

Vulnerability Management: - Review vulnerability scan results and help prioritize findings based on severity, exploitability, asset criticality, and business risk. - Coordinate remediation activities with IT, Engineering, Infrastructure, and system owners. - Track vulnerabilities through remediation, mitigation, or approved risk acceptance. - Validate remediation where appropriate. - Identify recurring vulnerability trends and opportunities to improve preventative controls.

Endpoint, Email, and Identity Security: - Support the administration and monitoring of endpoint detection and response, email security, identity security, and related security platforms. - Investigate suspicious endpoint, authentication, phishing, and email activity. - Assist with phishing investigations and response. - Review security tool configurations and identify opportunities to improve detection or reduce unnecessary alerting. - Security Monitoring and Detection: - Assist with maintaining and improving security monitoring and detection capabilities. - Review logs and security telemetry during investigations. - Help develop or tune detection rules and alerts. - Identify gaps in security visibility and recommend improvements. - Work with managed security providers and other security vendors when applicable.

Security Operations and Reporting: - Track security activities through established ticketing and workflow systems. - Perform security reviews of new software, tools, and vendor requests submitted by employees or business teams, including assessing data handling, access requirements, and integration risk before approval, and document findings in the vendor risk register. - Maintain operational security metrics and dashboards. - Document recurring security processes and procedures. - Support security audits, assessments, and compliance activities by providing technical evidence when needed. - Identify opportunities to automate repetitive security tasks.

Qualifications

Education: BA Computer Science, Cybersecurity, or related field preferred; but we also evaluate demonstrated hands-on experience.

Licensure/Certification: Not required. Preferred: Security+, CySA+, GSEC, SSCP, or equivalent experience.

Experience: 2 to 4 years of hands-on experience operating and tuning security tools in a live production environment. This role carries day-to-day ownership of alerts, tickets, and remediation, not solely compliance or audit-focused work.

Knowledge, Skills, and Abilities:   - Understanding of common security concepts, including endpoint security, identity and access management, vulnerability management, phishing and email security, network security, incident response, and security logging and monitoring. - Experience investigating technical security issues, with familiarity across Windows, macOS, Linux, cloud platforms, or enterprise SaaS environments. - Ability to interpret logs, alerts, vulnerability findings, and other technical security information. - Strong documentation and communication skills, with the ability to manage multiple security activities and follow issues through resolution. - Preferred: experience with EDR/MDR, vulnerability management, and email security platforms such as SentinelOne, Tenable, or Proofpoint; identity and SSO platforms such as Okta; and AWS or other public cloud platforms. - Demonstrated application of the above Qualification - Preferred: experience with security frameworks or regulatory requirements such as NIST, CIS Controls, SOC 2, PCI DSS, or HIPAA. - ? Preferred: familiarity with scripting or automation using Python, PowerShell, APIs, or similar technologies, and with GRC or IT service management platforms such as Vanta and Freshservice. - Measures of Success

Success in this role includes: - Security alerts and incidents are investigated and documented consistently. - Vulnerabilities are accurately prioritized and actively driven toward remediation. - Security tickets and investigations have clear ownership and timely follow-up. - Security monitoring provides useful and actionable detection coverage. - Operational security metrics accurately reflect the current security environment. - Security procedures and playbooks become increasingly repeatable and documented. - Recurring manual security activities are identified and automated where practical.

Work Environment - Location: Not specified in the source job description; to be confirmed with the hiring manager. - Schedule: Full-time; standard business hours. - May require availability outside standard hours for active security incidents or urgent escalations. - Regular collaboration with Security, IT, Engineering, and other business teams to ensure alignment.

Key Essential Functions - Must be able to work at a computer for extended periods, including during active incident response - Must be able to communicate effectively, verbally and in writing, with Security, IT, Engineering, and other business teams - Must be able to handle and access sensitive security and system data in compliance with organizational data handling requirements - Must be able to respond to security incidents outside standard working hours when required

Employment Classification

Status: Full-time

FLSA: Exempt

Equal Employment Opportunity (EEO) Statement

Gifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.

We celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply!

Disclaimer