Base Career helps you apply smarter for this job.
Key skills for this role
We are seeking an Information Security Analyst to support the day-to-day operation of the organization's security program, with a focus on security monitoring, incident response, vulnerability management, endpoint security, email security, and operational security processes. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.
This role works across Security, IT, Engineering, and other business teams to identify and investigate security risks, coordinate remediation activities, and help ensure security controls remain effective and operational. The ideal candidate is technically curious, comfortable investigating security events, and able to move between hands-on security work, documentation, and coordination with internal teams.
At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.
We are seeking an Information Security Analyst to support the day-to-day operation of the organization's security program, with a focus on security monitoring, incident response, vulnerability management, endpoint security, email security, and operational security processes. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.
This role works across Security, IT, Engineering, and other business teams to identify and investigate security risks, coordinate remediation activities, and help ensure security controls remain effective and operational. The ideal candidate is technically curious, comfortable investigating security events, and able to move between hands-on security work, documentation, and coordination with internal teams.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Columbus, USA
, USA
, USA
, USA
, USA
, USA
, USA
Columbus, USA
, USA
Monitor and investigate security alerts generated by endpoint, identity, email, cloud, and other security technologies.
Perform initial triage and investigation of suspected security incidents.
Escalate security events based on established severity and incident response procedures.
Support containment, remediation, recovery, and post-incident activities.
Maintain accurate records of security investigations, findings, and response actions.
Assist with the development and maintenance of security incident response procedures and playbooks.
Participate in security exercises and tabletop exercises.
Review vulnerability scan results and help prioritize findings based on severity, exploitability, asset criticality, and business risk.
Coordinate remediation activities with IT, Engineering, Infrastructure, and system owners.
Track vulnerabilities through remediation, mitigation, or approved risk acceptance.
Validate remediation where appropriate.
Identify recurring vulnerability trends and opportunities to improve preventative controls.
Support the administration and monitoring of endpoint detection and response, email security, identity security, and related security platforms.
Investigate suspicious endpoint, authentication, phishing, and email activity.
Assist with phishing investigations and response.
Review security tool configurations and identify opportunities to improve detection or reduce unnecessary alerting.
Security Monitoring and Detection:
Assist with maintaining and improving security monitoring and detection capabilities.
Review logs and security telemetry during investigations.
Help develop or tune detection rules and alerts.
Identify gaps in security visibility and recommend improvements.
Work with managed security providers and other security vendors when applicable.
Track security activities through established ticketing and workflow systems.
Perform security reviews of new software, tools, and vendor requests submitted by employees or business teams, including assessing data handling, access requirements, and integration risk before approval, and document findings in the vendor risk register.
Maintain operational security metrics and dashboards.
Document recurring security processes and procedures.
Support security audits, assessments, and compliance activities by providing technical evidence when needed.
Identify opportunities to automate repetitive security tasks.
Security alerts and incidents are investigated and documented consistently.
Vulnerabilities are accurately prioritized and actively driven toward remediation.
Security tickets and investigations have clear ownership and timely follow-up.
Security monitoring provides useful and actionable detection coverage.
Operational security metrics accurately reflect the current security environment.
Security procedures and playbooks become increasingly repeatable and documented.
Recurring manual security activities are identified and automated where practical.
Location: Not specified in the source job description; to be confirmed with the hiring manager.
Schedule: Full-time; standard business hours.
May require availability outside standard hours for active security incidents or urgent escalations.
Regular collaboration with Security, IT, Engineering, and other business teams to ensure alignment.
Must be able to work at a computer for extended periods, including during active incident response
Must be able to communicate effectively, verbally and in writing, with Security, IT, Engineering, and other business teams
Must be able to handle and access sensitive security and system data in compliance with organizational data handling requirements
Must be able to respond to security incidents outside standard working hours when required
Status: Full-time
FLSA: Exempt
Equal Employment Opportunity (EEO) Statement
Gifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.
We celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply!
Disclaimer
Digital pharmacy and patient-access platform fulfilling prescriptions and supporting biopharma brands, clinics, prescribers, and patients.
Visit company websiteJobs and hiring trendsUSD 73000-86000 yearly / year
Full-time
Entry · 2+ years experience
Remote
Apply faster on company sites with our extension.