IT Security Analyst II
Tokio Marine HCCAbout the role
Tokio Marine HCC (TMHCC) brings 50 years of service to the specialty insurance industry, today offering over 100 products to commercial customers in 180 countries worldwide. Organic growth and over 60 successful acquisitions have grown our 2022 Gross Written Premium (GWP) to $5 Billion. Our workforce has grown to 4,300 worldwide … big, but not so big that you cannot make a difference. Our Good Company values, including integrity, empowerment, and commitment to customer service, and a culture of innovation, communication, and collaboration make TMHCC a great workplace.
TMHCC Stop Loss, a $2 billion division within TMHCC, leads the way in providing medical stop loss insurance sold to employers. Medical Stop Loss provides an added layer of insurance protection to employers who choose to self-fund their health benefit plans. Self-funding can incur risks from catastrophic claims, and Medical Stop Loss insurance from Tokio Marine HCC is designed to protect employers from that risk.
This is hybrid role located onsite in Kennesaw, GA
Position Summary:
Under supervision, monitors, evaluates, and maintains security systems, including on-prem and cloud-based applications, infrastructure, workstations, and servers. Ensures the confidentiality, integrity, and availability of the organization’s information assets and helps drive the mitigation of security gaps and/or incidents. The role also involves proactive identification of vulnerabilities and improvements to security controls, working closely with cross-functional teams to enhance the security posture of the organization.
Key Responsibilities:
Research vulnerabilities, perform vulnerability scanning (e.g., Qualys) and produce a daily Vulnerability Reports—as well as seek ways to improve on all through automation and dashboarding.
Monitor and review security dashboards (e.g., CrowdStrike, Dynatrace, GitHub Advanced Security, Varonis) and drive issue remediation activities.
Manage and support authentication and access systems (e.g., CyberArk, Microsoft Active Directory, Okta, cloud-based IAM).
Collaborate with the IT and security teams to respond to security incidents and ensure timely mitigation of threats.
Analyze security systems for continuous improvement opportunities.
Maintain and update the Application Inventory system (e.g., LeanIX) to accurately track software deployed in the environment.
Perform and assist in the creation of recurring standard operating procedures, such as security audits and security posture checks.
Assist in the developing and enforcing security policies, standards, and procedures to protect information assets.
Assist with security-related projects, as well as lead small-scale projects.
Education, Experience & Knowledge
Bachelor’s Degree in Computer Science, Cybersecurity, or a related field; or equivalent combination of education and experience.
2 years of relevant and progressive IT security experience, with a focus on vulnerability management.
Hands-on experience with security tools for intrusion detection, filtering, event management, and vulnerability management (e.g., CrowdStrike, Qualys, Varonis).
Nice to have:
Industry-relevant certifications, such as CompTIA Security+ or SANS security certifications. ISC2 CISSP is a plus.
Experience with authentication and access management tools (e.g., CyberArk, Okta, MFA solutions, Microsoft Active Directory).
Experience with system logging and event correlation tools (e.g. SEIM).
Knowledge of regulatory frameworks such as Sarbanes-Oxley (SOX), Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), and data privacy laws (e.g., GDPR, CCPA).
Experience following and implementing information security policies, standards, and procedures to ensure compliance and security best practices.
Familiarity with security principles, such as the CIA triad (Confidentiality, Integrity, Availability), principle of least privilege, separation of duties, and defense in depth.
General knowledge of multi-platform information security, including networks, Windows, Linux, cloud environments, and application security.
Strong written and verbal communication skills, with an emphasis on confidentiality, tact, and diplomacy.
Advanced organizational and analytical skills; demonstrated ability to manage multiple tasks and priorities effectively.
Ability to stay updated on industry changes, legal requirements, and technical developments relevant to information security.
Intermediate
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s