Information Security Specialist/Analyst III - Information Solutions

Job Description Summary The Information Security Specialist/Analyst III reports to the Manager, Security Operations. Under indirect supervision, the Information Security Specialist/Analyst III provides a variety of operational, compliance, and consultative functions. This position designs, implements, manages, and monitors technical, administrative, and physical controls to protect the confidentiality, integrity, and availability of the organization’s information assets. This role may be required to provide rotating 24x7 on-call support.Entity Medical University Hospital Authority (MUHA)Worker Type EmployeeWorker Sub-Type​ RegularCost Center CC005101 SYS - IS Tidelands IntegrationPay Rate Type SalaryPay Grade Health-29Scheduled Weekly Hours 40Work Shift Job Description We are seeking a highly skilled and experienced Senior Information Security Analyst to join our team. This role is critical in safeguarding our complex healthcare IT environment and ensuring compliance with industry standards. Key Responsibilities: 45% - Network Security Monitoring and Incident Response: • Serve as a lead escalation point for security incidents, overseeing detection, investigation, containment, and remediation within a CrowdStrike EDR environment across a healthcare infrastructure. Experience with arenaflex Defender for Endpoint EDR is also desired. • Analyze findings from security monitoring systems, including Intrusion Detection/Prevention Systems (ID/PS) and Security Information Event Management (SIEM) consoles, to identify and respond to potential security incidents and data breaches. • Perform cyber security incident handling, tracking and reporting. • Utilize professional judgment and institutional knowledge to assess risk levels, conduct forensic investigations, isolate malware, identify attack vectors, provide guidance on remediation planning, and prioritize remediation efforts. • Respond to relevant service requests received from end users (e.g. for investigation of security events). • Collaborate with internal Security Operations Center (SOC) teams and external Managed Security Service Providers (MSSPs) to contain and remediate security incidents. 20% - Security Technology management: • Configure, manage, and optimize SIEM platforms (Crowdstrike and/or arenaflex Sentinel) to enhance threat detection and response capabilities. • Lead and manage large scale security-related projects, including tool implementations, upgrades, and process improvements. 10% - Vulnerability Management: • Conduct vulnerability assessments to identify security risks and report findings to system owners. • Manage workflows to ensure that protected assets are properly assessed in a timely manner. 15% - Threat Analysis • Continuously evaluate and update analytics to counter evolving Threat Actor tactics, techniques, and procedures (TTPs). • Perform risk assessments and translate business requirements into effective security controls. • Maintain comprehensive documentation and present findings to stakeholders in a clear and actionable manner. 10% - Security Awareness: • Create and deliver security awareness training for technical and non-technical audiences. Additional Job Description Required Education/Skills/Work Experience: • A Bachelor's degree in information security, information assurance, computer science, or a related field with 5 years of IT security experience; or 10 years of hands-on experience in information security or related IT experience required, at least 6 of which must be directly related IT security experience;or a Master's degree in information security,information assurance, computer science, or a related field, and 3 years of IT security experience required. • Advanced knowledge of information security principles, risk management, and regulatory compliance (HIPAA, FERPA, NIST, etc.). • Strong analytical and problem-solving skills with the ability to make decisions under pressure. • Hands-on experience with Crowdstrike EDR, SIEM, IDS/IPS, vulnerability management, and threat intelligence tools. • Familiarity with cloud security (Azure, AWS) and identity management solutions. • Advanced Understanding on the administration and securing of various operating systems and enterprise applications with advanced security best practices. • Excellent written and verbal communication skills, with the ability to translate technical findings into business-relevant language. • Mentor junior analysts and contribute to the development of security standards, procedures, and playbooks. Highly Desired Certifications: • CISSP, CISM, GIAC, or equivalent. Physical Requirements • Mobility & Posture • Standing: Continuous • Sitting: Continuous • Walking: Continuous • Climbing stairs: Infrequent • Working indoors: Continuous • Working outdoors (temperature extremes): Infrequent • Working from elevated areas: Frequent • Working in confined/cramped spaces: Frequent • Kneeling: Infrequent • Bending at the waist: Continuous • Twisting at the waist: Frequent • Squatting: Frequent • Manual Dexterity & Strength • Pinching operations: Frequent • Gross motor use (fingers/hands): Continuous • Firm grasping (fingers/hands): Continuous • Fine manipulation (fingers/hands): Continuous • Reaching overhead: Frequent • Reaching in all directions: Continuous • Repetitive motion (hands/wrists/elbows/shoulders): Continuous • Full use of both legs: Continuous • Balance & coordination (lower extremities): Frequent • Lifting & Force Requirements • Lift/carry 50 lbs. unassisted: Infrequent • Lift/lower 50 lbs. from floor to 36”: Infrequent • Lift up to 25 lbs. overhead: Infrequent • Exert up to 50 lbs. of force: Frequent • Examples: • Transfer 100 lb. non-ambulatory patient = 50 lbs. force • Push 400 lb. patient in wheelchair on carpet = 20 lbs. force • Push patient stretcher one-handed = 25 lbs. force • Vision & Sensory • Maintain corrected vision 20/40 (one or both eyes): Continuous • Recognize objects (near/far): Continuous • Color discrimination: Continuous • Depth perception: Continuous • Peripheral vision: Continuous • Hearing acuity (with correction): Continuous • Tactile sensory function: Continuous • Gross motor with fine motor coordination: Continuous • Selected Positions: • Olfactory (smell) function: Continuous • Respiratoruse qualification: Continuous • Work Environment & Conditions • Effective stress management: Continuous • Rotating shifts: Frequent • Overtime as required: Frequent • Latex-safe environment: Continuous If you like working with energetic enthusiastic individuals, you will enjoy your career with us! The Medical University of South Carolina is an Equal Opportunity Employer. MUSC does not discriminate on the basis of race, color, religion or belief, age, sex, national origin, gender identity, sexual orientation, disability, protected veteran status, family or parental status, or any other status protected by state laws and/or federal regulations. All qualified applicants are encouraged to apply and will receive consideration for employment based upon applicable qualifications, merit and business need. Medical University of South Carolina participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here: Apply tot his job

Back to blog
Ads

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...