Security Analyst

Sorry, this job was removed at 7:35 a.m. (EST) on Saturday, May 15, 2021
Find out who's hiring in Greater Boston Area.
See all Cybersecurity + IT jobs in Greater Boston Area
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

*Due to COVID-19 we are working 100% remotely, this includes the hiring process. When it is safe to do so, we will return to a hybrid of onsite and remote work for some positions.


Why This Role Is Important To Arcadia


The Arcadia.io Security Analyst for will work as a member for the Information Security team focused on ensuring the security of Arcadia’s cloud-based Population Health Analytics portfolio through technical security control implementation. This role will be based in Burlington, MA (remote is also available) and will partner with teams throughout the company to ensure that technical security requirements are consistently implemented.


What Success Looks Like

In 3 months

Performing the following with the supervision of the Security Manager:

- All tasks related to vulnerability and configuration management (review scans, as well as assess and document results)

- Conducting vulnerability risk assessments for risk adjustment requests

- Completing timebound security tasks (aligned with HITRUST) and produces reports


In 6 months

- Participating in Security Incident Investigations

- Owning tasks associated with the Security Analyst Role


In 12 months

- Completing customer and vendor security assessments

- Reviewing security documentation on an annual basis for currency

What You'll Be Doing

  • Supporting the Operations, Engineering, Production Support, and Technical Implementation teams by providing the necessary security expertise required to ensure that applications and infrastructure are implemented in accordance with company objectives for risk acceptance
  • Ensuring that the organizations infrastructure and applications meet Arcadia’s technical security objectives (as outlined in Policies and Procedures) and are designed, implemented and executed effectively, efficiently and economically
  • Performing, reviewing, evaluating, assessing, documenting and communicating the results of regular vulnerability and configuration scans
  • Interface with external partners including Managed Detection and Response vendor as first contact for identified alerts and issues
  • Reviewing (at pre-defined intervals) access rights, ports/protocols/services, audit monitoring, interconnections, firewall and router configurations, asset inventory, position risk designations, and blacklisting/whitelisting
  • Recommending, documenting and monitoring the implementation of any prescribed corrective actions resulting from assigned security assessments and reviews
  • Designing and implementing annual testing and training on Security Incident Response and Business Continuity/Disaster Recovery
  • Providing technical and forensic support during investigations into any suspected security incidents in accordance with company security incident handling, reporting and management procedures
  • Completing security assessments and annual audits for customers/prospective customers as well as providing artifacts (snapshots, etc.) to support such requests
  • Completing security assessments and annual audits for 3rd party vendors/partners including gathering artifacts (snapshots, etc.) and performing risk analyses and making go-forward recommendations
  • Supporting annual compliance audits (HITRUST, ISO and SOC 2)
  • Producing as required, any security metrics reports for the Information Security Officer (ISO), VP Information Security & Compliance and any other stakeholders or security steering committees prescribed
  • Responding to requests for consultation or other inquiries from staff and provide security advice as required
  • Supporting any requests for information by any external authoritative agencies as required (E.g., assessors, auditors, investigators, etc.)
  • Providing any requested input for the ongoing maturation and development of the information security, risk, compliance and governance strategies necessary to support the business planning process
  • Maintain currency and expertise with emerging trends in security, risk, compliance and governance standards and technologies (both internal and external)
  • Work with our offensive security team to document and report vulnerabilities discovered from our internal penetration testing program to product stakeholders. 
  • Track and drive remediation efforts for discovered vulnerabilities in web applications and network ensuring they are patched according to the timeframes specified.
  • Work with engineering teams to configure and perform automated scans that integrate security into our development process. Review, evaluate, document, and communicate the results to stakeholders. 
  • Work with security and engineering to ensure relevant tasks in the SDLC Security Plan are completed and required artifacts are completed and maintained.

What You’ll Bring

  • College Degree (from an IT Security /computer related field) or equivalent experience with at least 3 years of professional experience including security in the cloud
  • Good working knowledge of security, governance, risk, compliance and privacy concepts and practices
  • Demonstrated experience in network security monitoring/analysis, event escalation, cyber threat analysis, and vulnerability analysis
  • Specific experience in monitoring, evaluating, and interpreting vulnerabilities, CVEs, remedies, mitigation measures, techniques for escalation, social engineering tactics, phishing techniques, and performing vulnerability assessments
  • Familiarity with:
  • Windows, MacOS, and Linux
  • Basic knowledge of networking fundamentals (OSI model, etc.)
  • Fundamentals of information security including concepts related to confidentiality, integrity and availability as well as technical competency with computer BIOS, disk encryption, antivirus, vulnerability scanning, configuration scanning, and open source firewalls
  • Ability to write formal assessment reports and to present to varying stakeholders.

Would Love for You to Have

  • Professional Certification(s) in information security, governance, risk and/or compliance (e.g., CISSP, CEH, GSEC, CISM, CISA, CCSP, CompTIA Security+, etc.)
  • AWS Cloud Practitioner Certification
  • Working knowledge of firewalls and common AWS management, monitoring and configuration services
  • Professional Certification(s) in information security, governance, risk and/or compliance (e.g., CISSP, CEH, GSEC, CISM, CISA, CCSP, CompTIA Security+, OSCP, etc.)
  • Experience performing application security assessments or penetration tests.

What You'll Get

  • You will work with a team of experts in building and maintaining a highly validated security and privacy program for the leader in Population Health and Healthcare data analytics including experience with certifications such as HITRUST, ISO 27001, and SOC 2.
  • Be a part of a team and organization the had built security and privacy into the fabric and culture of the organization.
  • You will learn how to secure highly-regulated sensitive data in a cloud environment and how to build and maintain a fully validated and industry leading security program.
  • Your responsibilities will grow with you as a critical member of our team.
  • Competitive compensation/benefits package.
  • Become an expert in all elements of securing clinical and claims healthcare data in the cloud

About Arcadia

Arcadia.io helps innovative healthcare systems and health plans around the country transform healthcare to reduce cost while improving patient health. We do this by aggregating massive amounts of clinical and claims data, applying algorithms to identify opportunities to provide better patient care, and making those opportunities actionable by physicians at the point of care in near-real time. We are passionate about helping our customers drive meaningful outcomes. We are growing fast and have emerged as the market leader in the highly competitive population health management software and value-based care services markets, and we have been recognized by industry analysts KLAS, IDC, Forrester and Chilmark for our leadership. For a better sense of our brand and products, please explore our website, our online resources, and our interactive Data Gallery.


This position is responsible for following all Security policies and procedures in order to protect all PHI under Arcadia's custodianship as well as Arcadia Intellectual Properties. For any security-specific roles, the responsibilities would be further defined by the hiring manager.

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
    • JavaLanguages
    • JavascriptLanguages
    • PythonLanguages
    • RubyLanguages
    • ScalaLanguages
    • SqlLanguages
    • jQueryLibraries
    • jQuery UILibraries
    • ReactLibraries
    • ReduxLibraries
    • HadoopFrameworks
    • Node.jsFrameworks
    • Ruby on RailsFrameworks
    • SparkFrameworks
    • TensorFlowFrameworks
    • PostgreSQLDatabases
    • HadoopDatabases
    • SQLDatabases
    • Google AnalyticsAnalytics
    • IllustratorDesign
    • PhotoshopDesign
    • PixelmatorDesign
    • AsanaManagement
    • ConfluenceManagement
    • JIRAManagement
    • WordpressCMS
    • HubSpotCRM
    • SalesforceCRM
    • HubspotEmail
    • HubspotLead Gen

Location

Our new corporate headquarters is located in Downtown Boston, a short walk from South Station. Easily accessible by public transit (MBTA, commuter rail, South Station Bus Terminal) and a short 30 minute Uber from Logan airport. A close walk to nearby coffee shops, restaurants, bars, and sights.

An Insider's view of Arcadia

What's something quirky about your company?

Arcadia's Got Talent (AGT) is an annual talent show that I won last year. The best part about AGT was that it encouraged me to work on something I am passionate about outside of work. All of the entries were amazing & I think it's really awesome that the company does things to bring people together and celebrate our passions outside of the office.

Gary

Engineering Manager

What does your typical day look like?

Every day is a little bit different, which I really love and helps keep me engaged! Most days I have a combination of phone screens and meetings with my hiring managers or team. I also help manage a lot of our brand partnerships that have projects through out the year and play a part in helping construct Arcadia's company culture as we scale.

Julie

Talent Acquisition Manager

How do you make yourself accessible to the rest of the team?

It's as easy as making time. I meet with my team members for one on ones to understand where their stressors are. Sometimes it's personal and I support with flexibility, time, or PeopleOps other times it's professional and these I tactically work with the team to coach or intervene.

Geo

Director, Engineering

How does the company support your career growth?

Arcadia is incredibly generous when it comes to career growth. I receive regular mentorship from my manager and leadership team. I also have a continuing education stipend that I use to take courses and attend conferences to further my skillset. My career path is mapped out and regularly adjusted with my professional interests and personal growth.

Mike

Senior Manager, Content

What are Arcadia Perks + Benefits

Arcadia Benefits Overview

Flexible working options, hybrid teams, and unlimited vacations are only a few of the incredible benefits you'll get at Arcadia. As a leader in HealthIT and data, we're making a mark on the standards of work-life balance. Take a look at some of the incredible perks of being an Arcadian.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Pair programming
Employee resource groups
Employee-led culture committees
Employee awards
Flexible work schedule
Remote work program
Diversity
Highly diverse management team
Diversity manifesto
Hiring practices that promote diversity
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Team workouts
We offer biweekly Yoga and guided cardio workout sessions as well as have a Fitness and Fun video library with prior classes for reference.
Mental health benefits
We have an EAP (Employee Assistance Program) in place and an ongoing webinars focusing on mental health, coping with COVID, and emotional well-being.
Financial & Retirement
401(K)
401(K) matching
Performance bonus
Child Care & Parental Leave
Generous parental leave
Family medical leave
Company sponsored family events
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid holidays
Paid sick days
Flexible time off
Bereavement leave benefits
Office Perks
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Pet friendly
Fitness stipend
Home-office stipend for remote employees
We work with all of our employees to ensure they have an functional and comfortable home office with a focus on ergonomics.
Professional Development
Job training & conferences
Tuition reimbursement
Lunch and learns
Promote from within
Continuing education available during work hours
Online course subscriptions available
Customized development tracks
Paid industry certifications

Additional Perks + Benefits

At Arcadia we create programs and opportunities that allow connection with one another and bridge the work from home gap. We host themed events, contests with prizes, and provide resources for shared personal and professional interests.

More Jobs at Arcadia

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about ArcadiaFind similar jobs like this