Threat Defense Analyst
Listed on 2026-05-31
-
IT/Tech
Cybersecurity, Network Security, Security Manager, Information Security
The Fortified Threat Defense Center provides 24x7x365 managed security services for healthcare customers. Members of the Threat Defense team are responsible for monitoring and alerting on key security technologies within each customer environment, identifying security events, performing analysis, creating new and fine-tuning existing detection rules, and integrating with client’s incident response activities. In this role, the Senior Threat Defense Analyst will monitor, detect, analyze, and report on security alerts discovered within Fortified Health Security’s customer infrastructures.
They will monitor various security technologies within these environments and report all investigated and validated findings to the proper customer in accordance with the approved communication plan.
- Partner with clients on service delivery execution of all LOBs including but not limited to:
- Managed SIEM, Phishing, EDR, IoMT, & DLP
- Create, maintain, and mature Standard Operating Procedures (SOPs) and training documentation.
- Mentor, coach, and audit the activities of level I and II analysts.
- Perform advanced incident investigation.
- Ability to take lead on incident research when appropriate.
- Present alerts, metrics, and remediation tasks to customers via approved communication plans.
- Work with team members and manager to continually improve security services.
- Proactively and iteratively search through logs to detect advanced threats that are unknown to the current security solutions.
- Exercise multi-tasking skills by managing events in multiple systems, applications, and other priorities.
- Respond to incidents and client requests in a timely and professional manner.
- Generate end-of-shift reports for documentation and knowledge transfer to subsequent analysts on duty.
- Remain up to date on latest security threats and events.
- Create advanced rules based on latest security threats and events.
- Act as the SME for all technology used in service delivery.
- Improve skillset through training & certification acquisition.
- 4+ years’ hands-on experience with security tools such as scanners, monitoring and detection, malware protection, security analysis tools and compliance tools (both network and host-based solutions).
- 4+ years' technical experience in the security aspects of multiple computer platforms, operating systems, products, network protocols and system architecture or equivalent training and knowledge through education.
- 4+ years' technical experience in the security aspects of multiple computer platforms, operating systems, products, network protocols and system architecture or equivalent training and knowledge through education.
- Significant experience managing cases with enterprise SIEM and EDR systems.
- 4+ years of direct Info Sec experience and/or a bachelor’s degree in CS / MIS preferred.
- Intermediate understanding of the following subject matters/skills:
Incident Response, Team building, Motivating, Arbitration & Consensus, Compliance Frameworks (NIST, HIPAA, HITRUST, PCI) - Proficient understanding of the following subject matters/skills:
Incident response, relationship management, technical presentation, detection & suppression rule management, scripting (Python, Bash, Power Shell), attack frameworks, documentation, written and verbal communication, security platform health management, security platform log analysis, Linux OS & events, Windows OS & events, & healthcare operational knowledge - Common detection tools & attack techniques in the following areas:
Endpoint security - Network security
- Data security
- Proficient understanding of network security concepts and defense in depth.
- Proficient understanding of security incident and event management (SIEM), log analysis, network traffic analysis, malware investigation/remediation, SIEM correlation logic and alert generation.
- Advanced understanding of the following subject matters/skills:
- Attack frameworks, written and verbal communication, security platform health management, security platform log analysis, healthcare operational knowledge, endpoint security knowledge, user security knowledge, network…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).