HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    FR

    Franciscan Alliance Information Services

    Healthcare IT

    Cyber Security Specialist Lead

    Work From Home, United StatesFull-timePosted Yesterday
    All Franciscan Alliance Information Services jobs

    Job description

    Work From Home
    Work From Home Work From Home, Indiana 46544

    The Cyber Security Specialist Lead investigates and analyzes all response activities related to cyber incidents within the network environment or enclave. Collects data from a variety of Computer Network Defense (CND) tools, including intrusion detection system alerts, firewall and network traffic logs, and host system logs to analyze events that occur within their environment. Provides operations for persistent monitoring of all designated networks, enclaves, and systems. Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events. Acts as of the highest level of escalation point. Distributes directives, vulnerability, and threat advisories to identified consumers.

    WHO WE ARE

    With 11 ministries and access points across Indiana, Franciscan Health is one of the largest Catholic health care systems in the Midwest. Franciscan Health takes pride in hiring coworkers that provide compassionate, comprehensive care for our patients and the communities we serve.

    SPLUNK CLOUD / ON PREMISE EXPERIENCE PREFERRED.

    WHAT YOU CAN EXPECT

    • Work with Security Architects to develop roadmaps and implementation plans for upgrading, enhancing or replacing security technologies for which the Cyber Security Operations team is responsible.
    • Demonstrate advanced proficiency to write and optimize complex SPL queries to identify and investigate suspicious activity, correlate events, identify attack patterns, and perform proactive threat hunting across security data.
    • Create, test, tune, and maintain high-fidelity detections; reduce false positives; utilize risk-based alerting; and establish detection thresholds and governance.
    • Stay abreast of current artificial intelligence capabilities of the SIEM and other deployed security tools, develop and implement these capabilities to improve SOC performance.
    • Lead the SOC efforts during investigation of high-severity security incidents, participate in the cyber security incident response team, and guide analysts through the incident response lifecycle.
    • Develop, maintain, and safely execute SOAR playbooks; automate enrichment and response tasks; and identify opportunities to reduce repetitive analyst work.
    • Understand security data sources, field extractions, data models, and the common information model (CIM), troubleshoot data quality issues, and validate detections are operating against reliable data.
    • Serve as a technical escalation point, coach analysts, review investigations, establish investigation standards, and communicate clearly with SOC management and other security teams.
    • Build Splunk dashboards and reports to measure data sources, alert volume, detection performance, investigation quality, and SOC effectiveness.
    • Build detections for anomalous user and entity behavior, create procedures to investigate compromised accounts and lateral movement, use risk context to prioritize investigations.
    • Work with internal resources and external 3rd parties to design and conduct penetration tests, including ones designed as “stimulus-response” for the centralized log management system.
    • Create and review cyber security policies, procedures, and standards related to Security Operations Center, Vulnerability Management, and Incident Response processes.

    QUALIFICATIONS

    • Required Associate's Degree
    • Preferred Bachelor's Degree
    • Preferred Certificate
    • 8 years Information Technology or Information Security Department Required
    • 5 years Healthcare industry; experience in security operations activities aligning with Essential Job Functions Preferred

    TRAVEL IS REQUIRED:

    Never or Rarely
    JOB RANGE:
    Cyber Security Specialist Lead - 96,731.58-133,005.92
    INCENTIVE:

    EQUAL OPPORTUNITY EMPLOYER

    It is the policy of Franciscan Alliance to provide equal employment to its employees and qualified applicants for employment as otherwise required by an applicable local, state or Federal law.

    Franciscan Alliance reserves a Right of Conscience objection in the event local, state or Federal ordinances that violate its values and the free exercise of its religious rights.

    Franciscan Alliance is committed to equal employment opportunity.

    Franciscan provides eligible employees with comprehensive benefit offerings. Find an overview on the benefit section of our career site, jobs.franciscanhealth.org.

    Job details are sourced from the employer's original posting.

    Open job posting
    FR

    About the company

    Franciscan Alliance Information Services

    Franciscan Alliance Information Services is a healthcare organization focused on providing information technology services.

    View all Franciscan Alliance Information Services jobs
    Industry
    Healthcare IT
    Open roles
    12

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.