[Remote] Senior Security Analyst - REMOTE
Note: The job is a remote job and is open to candidates in USA. Reflect Health is the evolution of S&S Health, a trusted independent third-party administrator focused on innovation and service excellence. They are seeking a Senior Security Analyst to contribute to their security and risk program by managing incident response, vulnerability management, and compliance initiatives while translating complex security concepts into business-focused recommendations.
Responsibilities
- Incident Response & Security Operations: Review, investigate, and adjudicate security incidents escalated from the Security Operations Center (SOC), including triage, root cause analysis, containment, remediation, and post-incident review while partnering with the SOC to improve detection logic, escalation workflows, and operational effectiveness
- Vulnerability Management & Application Security: Drive the vulnerability management lifecycle through identification, risk-based prioritization, remediation tracking, and reporting while coordinating penetration testing activities, supporting remediation efforts, and performing application security assessments and reviews
- Product & Production Security: Partner with engineering teams to identify, prioritize, and remediate security risks across production environments while contributing to secure configuration standards, monitoring coverage, security best practices, and the protection of AI-enabled workloads
- Security Program Operations: Support the ongoing maturation of the security program by improving security tools, processes, and operational capabilities while recommending enhancements that strengthen the organization's overall security posture
- Security Data & Monitoring: Ensure complete and reliable collection of security logs and telemetry into the SIEM while supporting security data architecture decisions, onboarding new data sources, validating monitoring coverage, and identifying visibility gaps across systems and environments
- Governance, Risk & Compliance: Support internal and external audits, including HITRUST, SOC 2, client assessments, and regulatory reviews while coordinating evidence collection, tracking remediation activities, conducting third-party risk assessments, maintaining risk registers, and supporting ongoing audit readiness
- Reporting & Analytics: Develop, analyze, and present security and risk metrics, KPIs, KRIs, dashboards, and executive-level reporting that translate technical findings into meaningful business insights and support organizational decision-making
- Cross-Functional Support: Partner with engineering, infrastructure, operations, compliance, risk management, and business stakeholders to support security initiatives, policy and control mapping efforts, risk remediation activities, and strategic security projects
Skills
- Proven experience in Information Security, Cybersecurity, Security Operations, Governance Risk & Compliance (GRC), ideally within the healthcare or TPA industry
- Hands-on experience with incident response, vulnerability management, penetration testing coordination, application security reviews, and security operations processes
- Experience working with SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, or similar security monitoring and analytics technologies
- Experience supporting security audits, assessments, and compliance frameworks including HITRUST, SOC 2, NIST, HIPAA, ISO 27001, or related standards
- Demonstrated experience conducting third-party and vendor risk assessments, maintaining risk registers, and supporting enterprise risk management initiatives
- Strong analytical, reporting, and problem-solving abilities with experience translating technical findings into actionable risk assessments and business recommendations
- Excellent verbal and written communication skills with the ability to collaborate effectively across technical and non-technical teams and present information to executive leadership
Company Overview