
Risk Analyst II - InfoSec
Valhalla, NYFull-time$111–139K/yrSeen todaySeen in employer's feed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Valhalla, NY, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Requirements
Credentials this posting asks for.
Job overview
The Risk Analyst II is a senior-level member of the Information Security team, responsible for designing, implementing, and managing enterprise security solutions. The role oversees network security policies and security systems, supports incident response and remediation, and coordinates with IT teams on projects and end-user support. It also assists junior team members with complex work and requires understanding business needs across clinical, administrative, ancillary, and financial areas.
Skills & qualifications
Skills
Qualifications
Benefits
Full job description
Risk Analyst II - InfoSec
Company: NorthEast Provider Solutions Inc.
City/State: Valhalla, NY
Category: Finance/Info Systems
Department: Info Technology-WMC Health
Union: No
Position: Full Time
Hours: M-F 8:30a -5:00p
Shift: Day
Req #: 50237
Posted Date: Oct 07, 2026
Hiring Range: $110,564-$138,996
Apply Now
External Applicant link (https://pm.healthcaresource.com/cs/wmc1/#/preApply/34410) Internal Applicant link
Job Details:
Job Summary:
The Risk Analyst II position within the Digital Transformation Information Services Information Security team is a senior level position. The Risk Analyst II is responsible for designing, implementing and managing enterprise level security solutions. They oversee and enforce network security policies through a host of activities and practices. Included among these are the configuration, optimization and monitoring of network firewalls; zero-trust/SASE infrastructure, administration of email security measures to identify and filter phishing attempts, malware and data loss; monitoring and managing remote connections; implementing cloud controls; Administration of identify and access management controls; monitoring and responding to alerts from EDR/XDR and other endpoint detection and responses. The Risk Analyst II is also responsible for the oversight of security software and systems upgrades, troubleshooting issues and verifications of system availability and performance. An understanding of business requirements across areas involved, e.g. clinical, ancillary, administrative and financial areas, is necessary. They will document activities, resolutions, and other outcomes throughout the life cycle of a security breach, problem or related response. The Risk Analyst II will coordinate and collaborate with other WMC IT Teams in support 11of system, project rollout, problem resolution, and end user support. This senior team member will assist junior members of the team on more complex aspects of the aforementioned areas for growth and knowledge.
Responsibilities:
-
Design, implement, and manage enterprise security solutions, including Cisco security platforms (Secure Network Analytics/Stealthwatch, Identity Services Engine (ISE), AnyConnect, Firepower, and Umbrella).
-
Configure, maintain, and optimize Palo Alto Networks firewalls to enforce network security policies.
-
Administer and enhance email security and filtering solutions to protect against phishing, malware, and data loss.
-
Design and maintain cloud security controls, including policy enforcement, continuous monitoring, and compliance validation.
-
Architect and support network segmentation initiatives aligned with zero-trust architecture principles.
-
Deploy and manage zero-trust/SASE secure remote access solutions, including zero-trust solutions.
-
Administer Identity and Access Management (IAM) controls, ensuring strong authentication, least privilege, and secure access governance.
-
Manage Microsoft EntraID capabilities, including Conditional Access policies and Microsoft Authenticator for MFA.
-
Deploy, monitor, and respond to alerts from CrowdStrike (Endpoint Detection & Response – EDR).
-
Support OT/IoT/Medical device security initiatives to enhance visibility, vulnerability identification, remediation, and risk reduction
-
• Investigate security alerts, support incident response efforts, and coordinate remediation with IT and infrastructure teams.
-
Maintain security documentation, system configurations, and operational runbooks.
Qualifications/Requirements:
Experience:
-
Minimum 5-7 years IT Infrastructure or IT Security experience, required
-
Hands-on experience with Cisco security technologies, including:
-
Cisco Secure Network Analytics (SNA) / Stealthwatch
-
Cisco Identity Services Engine (ISE)
Education:
- Bachelor’s degree in information technology, Information Security, or related/relevant discipline.
Equivalent combination of experience and education may be substituted for degree requirements
Licenses / Certifications:
- CISSPor equivalent industry certification, required
Other:
-
Knowledge of computer systems and applications in meeting medical data reporting requirements Knowledge of program planning and evaluation techniques
-
Ability to compile, analyze and interpret InfoSec data and forecast trends
-
Ability to work well with other technology and medical professionals
-
Ability to communicate effectively, both orally and in writing; ability to effectively use computer applications such as spreadsheets, word processing, calendar, e-mail and database software in performing work assignments
-
Good judgment, initiative, accuracy, thoroughness and physical condition commensurate with the demands of the position.
Special Requirements:
-
Experience configuring and managing Palo Alto Networks firewalls.
-
Experience with enterprise email security and filtering platforms.
-
Strong understanding of cloud security fundamentals, including monitoring, policy enforcement, and compliance controls.
-
Knowledge of network segmentation strategies and zero-trust architecture concepts.
-
Practical experience with Microsoft Entra, including Conditional Access and Microsoft Authenticator deployment.
-
Experience managing or supporting CrowdStrike (or similar EDR solutions).
-
Familiarity with OT/IoT/Medical device security platforms, preferably Claroty xDome.
-
Experience in designing, implementing, and maintaining Zero Trust architecture and operating principle. Experience with Netskope preferred.
-
Solid understanding of IAM principles, authentication methods (MFA, SSO), and least privilege access.
-
Strong analytical, troubleshooting, and incident response skills.
About Us:
NorthEast Provider Solutions Inc.
Benefits:
We offer a comprehensive compensation and benefits package that includes:
-
Health Insurance
-
Dental
-
Vision
-
Retirement Savings Plan
-
Flexible Savings Account
-
Paid Time Off
-
Holidays
-
Tuition Reimbursement
Apply Now
External Applicant link (https://pm.healthcaresource.com/cs/wmc1/#/preApply/34410) Internal Applicant link
Talent Community
Search Jobs
Hiring Events (https://wmchealthjobs.org/job-events-list/)
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Customer Service AnalystDepartment of State Headquarters · Hot Springs, AR · $90–173K/yrPosted 1w agoPosted 1w ago
Macro And Alternatives Trade Support AnalystPoint72 · Stamford, CT · $90–115K/yrPosted 2w agoPosted 2w ago
Nurse (Clinical Analyst)Veterans Health Administration · Bronx, NY · $108–180K/yrPosted 1 day agoPosted 1 day ago
Senior Tax AnalystInternal Revenue Service · Anchorage, AK · $126–197K/yrPosted 3 days agoPosted 3 days ago
Budget Analyst NF-03U.S. Military Academy · West Point, NY · $69–79K/yrPosted 1w agoPosted 1w ago
You've read the whole posting — now see how you match it.