Job Description:
As an Information Security Analyst II, you will be responsible for supporting the day-to-day security operations as well as running periodic security projects for the organiza on. The Informa on Security Analyst II is a security role focused on monitoring, analyzing and responding to security incidents and alerts in the EMS|MC corporate environment. This position plays a critical part in protecting organizational data and infrastructure by assisting in the implementation on and maintenance of security tools and processes, conducing basic threat analysis, and supporting security audits and compliance ac vi es.
Roles and Responsibilities
1. Security Monitoring & Analysis
a. Monitor security tools, logs, and alerts for indicators of threats or unauthorized activities.
b. Perform triage and analysis of security events, escalating to senior staff when necessary.
c. Investigate vulnerabilities and assist with patch management verification.
d. Resolve security portal tickets based on SLA.
e. Review vulnerability management data and encourage/assist system owners to mitigate vulnerabilities in line with our policy SLA.
f. Update process documentation after reviewing with senior staff.
2. Incident Response Support
a. Document incident findings and response steps for reporting and compliance purposes.
b. Follow established protocols to assist with incident detection, containment, and remediation.
c. Automation of security processes.
3. Threat Intelligence & Reporting
a. Stay informed and up-to-date on current threat trends and vulnerabilities.
b. Assist in gathering and analyzing threat intelligence to support proactive defense measures.
4. Security Administration
a. Assist and/or manage endpoint protection, firewalls, and other security systems following change management guidelines.
b. Assist in the maintenance of access control lists, user permissions, and role-based access across systems.
c. Perform other duties as assigned.
5.Compliance & Risk Management
a. Support audits and regulatory compliance efforts (HIPAA, PCI-DSS, SOC 2, etc.).
b. Ensure regular user and role-based audits are performed in accordance with our compliance requirements.
c. Report any abnormalities or improper access to management.
d. Assist in reviewing logs, creating reports, and ensuring security controls are in place.
6. Policy & Awareness
a. Support the rollout of security awareness training.
b. Ensure regular security testing using phishing simulations or other solutions.
c. Help maintain, review, and enforce IT security policies and procedures.
7. Partner Questionnaires
a. Answer security questionnaires from our partners and prospects
b. Maintain repository of questions and answers
Required Education, Skills, & Experience
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field (or equivalent experience).
-
Understanding of fundamental cybersecurity concepts (CIA triad, threat vectors, etc.).
-
Ability to effectively engage in high level, self-directed time management and prioritization of workload.
-
Demonstrated ability to effectively drive and manage projects to timely completion.
-
Willing and able to adapt to changes in work environment, procedures, priorities, and job duties.
-
Excellent verbal and written communication.
-
Strong analytical and problem-solving skills.
-
Ability to work independently and as part of a team.
-
High attention to detail and commitment to continuous learning.
-
Good working knowledge of risk management practices, IT security frameworks, and best practices.
-
2 or more years of hands-on experience with information, data, system, or application security.
Preferred Education, Skills, & Experience
-
Relevant certifications: CompTIA Security+, CompTIA Network+, GSEC, SSCP, or equivalent.
-
Experience in IT, cybersecurity, or network administration, Microsoft 365 and Entra ID, and Active Directory.
-
Hands-on lab experience in security tools or incident response.
-
Experience with operating systems (Windows, Linux), networking basics, and system logs.
-
Experience with programming/scripting (Bash, PowerShell, or Python).
-
Exposure to tools such as antivirus platforms, vulnerability scanners, or firewalls.
-
Understanding of HIPAA Security Rule, HITECH Act, PCI-DSS, and general data privacy principles.
-
Process Improvement Experience.
Working Environment
On-call rotation or availability for after-hours incident response may be required.
Regular interaction with IT team, compliance team, and end-users.
For employees approved to work in a hybrid or remote setting, a quiet, private workspace free from significant distractions is required to ensure productivity during work hours.
A reliable internet connection is required for hybrid/remote work. EMS|MC will provide necessary equipment, including a computer, monitor, keyboard, mouse and headset.
Physical Requirements:
Sitting: frequent and prolonged periods of sitting at a desk while working on a computer.
Communication: frequent and prolonged periods of speaking, listening, reading, and writing.
Fine motor skills: frequent use of hands for typing and operating a computer mouse.
Movement: occasional walking and climbing of stairs; limited bending, kneeling, lifting, and carrying of office-related items.
Travel: must be able to travel occasionally to attend any required company meetings.