Jobs and Careers
AM

Security Analyst, Detection and Response - Remote

American Cancer Society
PA Home Based, United StatesRemotefull_timeVerifiedPosted 1 Aug 2024
💰 $100,000/yr($70,000/yr$100,000/yr)

About the role

At the American Cancer Society, we're leading the fight for a world without cancer. Our employees and 1.5 million volunteers are raising the bar every single day. We actively seek candidates from diverse backgrounds including communities of color, the LGBTQ community, veterans, and people with disabilities. The greater the diversity of our people, the better we can serve our communities.

The people who work at the American Cancer Society focus their diverse talents on our lifesaving mission. It is a calling. And the people who answer it are fulfilled.

Detection and Response is a position within the American Cancer Society (ACS) IT Security team with primary focus on advancing the ACS' security posture in the following security functions, Cloud Security, Vulnerability Management, and Incident Response. The role handles identifying, evaluating, and responding to defend cloud applications and infrastructure from account compromise, insider threat, and access misuse. This role delivers consolidated visibility and data-driven analytics to detect, investigate, and mitigate threats in the cloud. This role will collaborate with a team of security analysts within the IT Security team and IT security leadership to ensure risk is appropriately managed to an acceptable level within the ACS environment. This position requires strong written and oral communication skills to communicate risk impact and likelihood to non-technical stakeholders.

***This is a remote position that can be home based anywhere within the United States.***

MAJOR RESPONSIBILITIES

Vulnerability Management

  • Assess and maintain the incoming flow of vulnerability cases including CVE notifications, Cloud based vulnerabilities, Cloud Misconfigurations, and access control issues.

  • Analyze business unit remediation and case closure metrics providing for guardrails on case and remediation quality.

  • Identify, evaluate, and communicate cloud-related risks and vulnerabilities, and propose recommended remediations.

  • Contribute to the development of operational and security automation and integration processes and procedures.

  • Work closely with stakeholders on integration of security architecture into overall enterprise architecture.

  • Track and report on the effectiveness of cloud information security technology, controls, processes, and polices.

  • Continuous assessment of identified vulnerabilities and collaborate with other teams for remediation.

  • Prioritize vulnerabilities discovered along with remediation timeline(s).

  • Send and receive notifications to the SMEs (subject matter experts) of vulnerabilities within the environment.

  • Lead regular meetings with business partners to ensure remediation efforts adhere to corporate standards and policies.

  • Provides analysis/validation of remediation actions taken, opportunities for improvement and out of the box thinking for optimizations and solving roadblocks.

  • Develop communication channels with technology owners and the business to evangelize the evolving threat landscape.

  • Design and provide vulnerability management metric report to management and stakeholders as necessary.

  • Serve as administrator of ACS vulnerability management scanning tools and/or serve a primary contact for third-party vendor that provide MVM services to the American Cancer Society.

Detection and Response

  • Monitor alerts and investigate by pivoting between various data sources, correlating events, searching for indicators of compromise, and performing forensic analysis.

  • Coordinates analysis, containment, eradication, and recovery activities in response to security events affecting the company's information assets.

  • Monitor alerts and investigate by pivoting between various data sources, correlating events, searching for indicators of compromise, and performing forensic analysis.

  • Coordinate cyber incident response team activities during an incident to ensure a comprehensive and systematic response to, and escalation of security incidents within the ACS environment.

  • Prepare clear and detailed written report to be delivered to ACS leadership and key stakeholders summarizing cyber security incidents and actions taken by ACS in response.

  • Provide reports and metrics related to security events (real time, trends), security incident management tracking and follow up, to include documenting new risks surfaced through the Incident Response Processes.

  • Perform incident response services including, but not limiting to, collection, documentation, preservation, and analysis of incident evidence.

  • Provide threat detection and incident respon

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

American Cancer Society

View company profile →