remote
IS Security Operations Analyst - Benson Tower - Ochsner Health
Systems Engineer
Security Operations Analyst responsible for real‑time monitoring, detection, and response to cyber threats across a large healthcare network using SIEM tools, IDS/IPS, and scripting for automation.
About the role
Key Responsibilities
- Monitor security alerts and events in the SOC using SIEM platforms to identify potential threats.
- Investigate and triage incidents, performing root‑cause analysis and coordinating containment and remediation actions.
- Configure, tune, and maintain IDS/IPS and endpoint detection tools to improve detection accuracy.
- Develop and execute PowerShell and Python scripts for log parsing, automation of repetitive tasks, and threat hunting.
- Collaborate with IT and clinical teams to ensure security controls align with regulatory and compliance requirements.
- Document incident findings, produce post‑incident reports, and contribute to continuous improvement of security processes.
Requirements
- 2+ years of experience in a Security Operations Center or similar environment.
- Hands‑on experience with SIEM solutions (e.g., Splunk, QRadar, ArcSight) and IDS/IPS technologies.
- Proficiency in Windows and Linux operating systems, including log analysis and system hardening.
- Strong scripting skills in PowerShell and Python for automation and data manipulation.
- Knowledge of incident response frameworks, threat intelligence, and healthcare compliance standards (HIPAA, HITECH).