S&S Health

Senior Security Analyst - REMOTE

S&S Health  •  $120k - $140k/yr  •  Cincinnati, OH (Remote)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Reflect Health is the evolution of S&S Health, a trusted independent third-party administrator founded in 1994 to meet the growing need for access, simplified connectivity, and benefits administration. Headquartered in Mason, OH, we have built a reputation based on innovation, service excellence, and a deep understanding of how to drive better outcomes at lower cost. Over the years, we grew into a national presence serving employers, TPAs, health systems, and benefit consultants across all 50 states. We developed proprietary claims technology, expanded our offerings to include level-funded and fully funded programs, and delivered tangible savings and enhanced experiences for millions of members. W

We are seeking a Senior Security Analyst to serve as a senior technical and analytical contributor across our security and risk program. This role will play a key part in incident response, vulnerability management, application and product security, governance and compliance initiatives, third-party risk management, and security data operations. The ideal candidate is experienced across both technical security operations and governance, risk, and compliance functions, with the ability to translate complex security concepts into clear, business-focused recommendations and drive continuous improvement across the organization.

Responsibilities

  • Incident Response & Security Operations: Review, investigate, and adjudicate security incidents escalated from the Security Operations Center (SOC), including triage, root cause analysis, containment, remediation, and post-incident review while partnering with the SOC to improve detection logic, escalation workflows, and operational effectiveness
  • Vulnerability Management & Application Security: Drive the vulnerability management lifecycle through identification, risk-based prioritization, remediation tracking, and reporting while coordinating penetration testing activities, supporting remediation efforts, and performing application security assessments and reviews
  • Product & Production Security: Partner with engineering teams to identify, prioritize, and remediate security risks across production environments while contributing to secure configuration standards, monitoring coverage, security best practices, and the protection of AI-enabled workloads
  • Security Program Operations: Support the ongoing maturation of the security program by improving security tools, processes, and operational capabilities while recommending enhancements that strengthen the organization's overall security posture
  • Security Data & Monitoring: Ensure complete and reliable collection of security logs and telemetry into the SIEM while supporting security data architecture decisions, onboarding new data sources, validating monitoring coverage, and identifying visibility gaps across systems and environments
  • Governance, Risk & Compliance: Support internal and external audits, including HITRUST, SOC 2, client assessments, and regulatory reviews while coordinating evidence collection, tracking remediation activities, conducting third-party risk assessments, maintaining risk registers, and supporting ongoing audit readiness
  • Reporting & Analytics: Develop, analyze, and present security and risk metrics, KPIs, KRIs, dashboards, and executive-level reporting that translate technical findings into meaningful business insights and support organizational decision-making
  • Cross-Functional Support: Partner with engineering, infrastructure, operations, compliance, risk management, and business stakeholders to support security initiatives, policy and control mapping efforts, risk remediation activities, and strategic security projects

Qualifications

  • Security Experience: Proven experience in Information Security, Cybersecurity, Security Operations, Governance Risk & Compliance (GRC), ideally within the healthcare or TPA industry
  • Technical Security Expertise: Hands-on experience with incident response, vulnerability management, penetration testing coordination, application security reviews, and security operations processes
  • Security Platforms & Tools: Experience working with SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, or similar security monitoring and analytics technologies
  • Governance & Compliance Knowledge: Experience supporting security audits, assessments, and compliance frameworks including HITRUST, SOC 2, NIST, HIPAA, ISO 27001, or related standards
  • Risk Management Experience: Demonstrated experience conducting third-party and vendor risk assessments, maintaining risk registers, and supporting enterprise risk management initiatives
  • Analytical Skills: Strong analytical, reporting, and problem-solving abilities with experience translating technical findings into actionable risk assessments and business recommendations
  • Communication Skills: Excellent verbal and written communication skills with the ability to collaborate effectively across technical and non-technical teams and present information to executive leadership

Reflect Health is committed to providing a safe and secure workplace for all employees. All final candidates will be subject to background checks and drug screening as part of the hiring process.

S&S Health

About S&S Health

S&S Health is a premier healthcare administration company. We offer self, level and fully funded solutions that lower costs while improving outcomes with a consumer centric experience. Our integrated benefits, services and technology platform have been developed to serve the needs of Employers, TPAs, and Health Systems. The company has a nationwide presence with the ability to sell and service in every state. Currently, we maintain offices in Ohio, Connecticut, Florida and Nevada.

Industry
Finance & Insurance
Company Size
51-200 employees
Headquarters
Cincinnati, Ohio
Year Founded
1994
Social Media