Padmi
Medical University of South Carolina logo
Medical University of South Carolina

academic medical center · medical education

Information Security Specialist/Analyst III - Information Solutions (Remote)

Remote · United StatesPosted 4 days ago
SecurityStaff+Full Time
Apply at Medical University of South Carolina

Opens the source posting on musc.wd1.myworkdayjobs.com

Source description

About the role

View original

Job Description Summary The Information Security Specialist/Analyst III reports to the Manager, Security Operations. Under indirect supervision, the Information Security Specialist/Analyst III provides a variety of operational, compliance, and consultative functions. This position designs, implements, manages, and monitors technical, administrative, and physical controls to protect the confidentiality, integrity, and availability of the organization’s information assets. This role may be required to provide rotating 24x7 on-call support. Entity Medical University Hospital Authority (MUHA) Worker Type Employee Worker Sub-Type​ Regular Cost Center CC002271 SYS - IS Cyber Operations Pay Rate Type Salary Pay Grade Health-29 Scheduled Weekly Hours 40 Work Shift

Job Description We are seeking a highly skilled and experienced Senior Information Security Analyst to join our team. This role is critical in safeguarding our complex healthcare IT environment and ensuring compliance with industry standards.

Key Responsibilities: 45% - Network Security Monitoring and Incident Response: Serve as a lead escalation point for security incidents, overseeing detection, investigation, containment, and remediation within a CrowdStrike EDR environment across a healthcare infrastructure. Experience with Microsoft Defender for Endpoint EDR is also desired. Analyze findings from security monitoring systems, including Intrusion Detection/Prevention Systems (ID/PS) and Security Information Event Management (SIEM) consoles, to identify and respond to potential security incidents and data breaches. Perform cyber security incident handling, tracking and reporting. Utilize professional judgment and institutional knowledge to assess risk levels, conduct forensic investigations, isolate malware, identify attack vectors, provide guidance on remediation planning, and prioritize remediation efforts. Respond to relevant service requests received from end users (e.g. for investigation of security events). Collaborate with internal Security Operations Center (SOC) teams and external Managed Security Service Providers (MSSPs) to contain and remediate security incidents.

20% - Security Technology management: Configure, manage, and optimize SIEM platforms (Crowdstrike and/or Microsoft Sentinel) to enhance threat detection and response capabilities. Lead and manage large scale security-related projects , including tool implementations, upgrades, and process improvements.

10% - Vulnerability Management: Conduct vulnerability assessments to identify security risks and report findings to system owners. Manage workflows to ensure that protected assets are properly assessed in a timely manner.

15% - Threat Analysis Continuously evaluate and update analytics to counter evolving Threat Actor tactics, techniques, and procedures (TTPs) . Perform risk assessments and translate business requirements into effective security controls. Maintain comprehensive documentation and present findings to stakeholders in a clear and actionable manner.

10% - Security Awareness: Create and deliver security awareness training for technical and non-technical audiences.

Additional Job Description Required Education/Skills/Work Experience: A Bachelor's degree in information security, information assurance, computer science, or a related field with 5 years of IT security experience; or 10 years of hands-on experience in information security or related IT experience required, at least 6 of which must be directly related IT security experience; or a Master's degree in information security, information assurance, computer science, or a related field, and 3 years of IT security experience required. Advanced knowledge of information security principles, risk management, and regulatory compliance (HIPAA, FERPA, NIST, etc.). Strong analytical and problem-solving skills with the ability to make decisions under pressure. Hands-on experience with Crowdstrike EDR, SIEM, IDS/IPS, vulnerability management, and threat intelligence tools . Familiarity with cloud security (Azure, AWS) and identity management solutions . Advanced Understanding on the administration and securing of various operating systems and enterprise applications with advanced security best practices. Excellent written and verbal communication skills, with the ability to translate technical findings into business-relevant language. Mentor junior analysts and contribute to the development of security standards, procedures, and playbooks.

Highly Desired Certifications: CISSP, CISM, GIAC, or equivalent.

Physical Requirements Mobility & Posture

Standing: Continuous

Sitting: Continuous

Walking: Continuous

Climbing stairs: Infrequent

Working indoors: Continuous

Working outdoors (temperature extremes): Infrequent

Working from elevated areas: Frequent

Working in confined/cramped spaces: Frequent

Kneeling: Infrequent

Bending at the waist: Continuous

Twisting at the waist: Frequent

Squatting: Frequent

Manual Dexterity & Strength

Pinching operations: Frequent

Gross motor use (fingers/hands): Continuous

Firm grasping (fingers/hands): Continuous

Fine manipulation (fingers/hands): Continuous

Reaching overhead: Frequent

Reaching in all directions: Continuous

Repetitive motion (hands/wrists/elbows/shoulders): Continuous

Full use of both legs: Continuous

Balance & coordination (lower extremities): Frequent

Lifting & Force Requirements

Lift/carry 50 lbs. unassisted: Infrequent

Lift/lower 50 lbs. from floor to 36”: Infrequent

Lift up to 25 lbs. overhead: Infrequent

Exert up to 50 lbs. of force: Frequent

Examples:

Transfer 100 lb. non-ambulatory patient = 50 lbs. force

Push 400 lb. patient in wheelchair on carpet = 20 lbs. force

Push patient stretcher one-handed = 25 lbs. force

Vision & Sensory

Maintain corrected vision 20/40 (one or both eyes): Continuous

Recognize objects (near/far): Continuous

Color discrimination: Continuous

Depth perception: Continuous

Peripheral vision: Continuous

Hearing acuity (with correction): Continuous

Tactile sensory function: Continuous

Gross motor with fine motor coordination: Continuous

Selected Positions:

Olfactory (smell) function: Continuous

Respirator use qualification: Continuous

Work Environment & Conditions

Effective stress management: Continuous

Rotating shifts: Frequent

Overtime as required: Frequent

Latex-safe environment: Continuous

If you like working with energetic enthusiastic individuals, you will enjoy your career with us!

The Medical University of South Carolina is an Equal Opportunity Employer. MUSC does not discriminate on the basis of race, color, religion or belief, age, sex, national origin, gender identity, sexual orientation, disability, protected veteran status, family or parental status, or any other status protected by state laws and/or federal regulations. All qualified applicants are encouraged to apply and will receive consideration for employment based upon applicable qualifications, merit and business need.

Medical University of South Carolina participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here: http://www.uscis.gov/e-verify/employees

More at Medical University of South Carolina

Related open roles

View all roles
Information Security Specialist/Analyst III - Information Solutions (Remote) at Medical University of South Carolina · Padmi