Information Security Analyst - Information Technology
Person Centered ServicesAbout the role
Why Work for Person Centered Services?
When you join the Person Centered Services team, you can make a difference in the lives of people with intellectual and developmental disabilities, while also reaching your own career goals.
Benefits for full-time positions include:
• 20 Days of paid time off (PTO) in your first year! Increasing to 25 Days in your second year!
• 13 Paid Holidays
• Comprehensive health insurance plans for you to choose what best fits your needs (Medical, Dental & Vision)
• 401(k) - the Company matches 50% of the first 6% up to a maximum of 3%
• Company paid benefits: basic life insurance, long-term disability, and a Lifestyle Spending Account with a benefit of up to $500 set aside for employees to spend on wellness eligible expenses!
• Employee Discount and Wellness Programs - Currently providing 3 paid hours per week for exercise, volunteering or personal wellness!
• Professional development opportunities including mentorship program options and ongoing coaching
INFORMATION SECURITY ANALYST
Department Information Technology Direct Care Non-Direct Care Non-Direct Care
FLSA Status
Exempt
Exemption Type
(HR Use Only – Check all that apply)
☐Executive ☒Computer
☐Administrative☐Professional
☐Outside Sales
Reports to Information Security Manager Supervises N/A
Primary Location
Corporate-Buffalo
Employment Status
☒Full Time ☐Part Time
☒Regular ☐Temporary
Original Date November 2022 Revised Date September 2025
JOB SUMMARY
The Information Security Analyst is responsible for protecting the integrity, confidentiality, and availability of systems and data within a fully cloud-based environment. This role requires a strong combination of technical proficiency, analytical thinking, and proactive engagement in cybersecurity operations. As a New York State-regulated entity, the organization adheres to strict compliance frameworks and internal protocols. The analyst must operate within established procedures and hierarchical guidance to ensure ongoing compliance and audit readiness.
ESSENTIAL FUNCTIONS
• Monitor, investigate, and respond to security events using Microsoft Azure and Microsoft 365 security services, including Azure Sentinel SIEM, Microsoft Defender XDR, Defender for Endpoint, Intune, Defender Vulnerability Management, Identity Protection, Cloud App Security, and Data & Security Governance.
• Apply structured methods to assess alerts, identify threats, and implement timely remediation, with clear documentation, ownership of outcomes, and proactive communication throughout.
• Detect threats using Kusto Query Language (KQL) in Sentinel and Defender XDR. Prior experience is preferred, but a strong willingness to learn and apply KQL is valued.
• Lead full-cycle incident response—from detection to recovery—minimizing impact through coordinated action and maintaining detailed, audit-ready documentation.
• Conduct and document detailed, legally defensible security risk assessments that define scope, findings, impact, and reportability of potential data breach incidents. Investigate potential PHI exposure thoroughly and ensure remediation is fully documented, complete, and well-communicated.
• Support phishing simulations and security awareness campaigns via platforms like KnowBe4, promoting a culture of accountability and vigilance.
• Collaborate on secure implementation of projects, applications, and services, ensuring alignment with security policies and clearly communicating risks and mitigations.
• Maintain accurate, accessible documentation for audits, service tickets, and project tracking, supporting transparency and readiness for review.
• Assist with annual audits by preparing evidence, validating controls, and responding to auditor inquiries with clarity and professionalism.
• Ensure compliance with NIST SP 800-53 and the New York State System Security Plan (SSP), proactively identifying and communicating gaps or risks.
• Provide timely, thoughtful security guidance to internal teams, helping them navigate risks and implement secure solutions with confidence.
• Deliver engaged training sessions and author internal security updates that reinforce best practices and foster shared ownership of security.
• Research, plan, and lead security projects from concept to completion, with clear objectives, stakeholder coordinat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s