From Specialized Dental's posting. “We” and “our” refer to the employer.
Overview
Job Summary:
The Cybersecurity Operations Analyst II supports and operates our enterprise cybersecurity program. This role is responsible for day-to-day threat monitoring, detection and response, Microsoft Defender EDR/XDR administration, vendor risk management, employee security awareness, compliance support, and remediation of identified security gaps.
This position combines hands-on security operations with ownership of several ongoing cybersecurity programs. The Cybersecurity Operations Analyst II will independently investigate common security events, manage third-party security risk assessments, maintain employee security education, support HIPAA compliance and HITRUST e1 readiness, and work directly with infrastructure engineers to incorporate security into day-to-day technology operations.
This is a hands-on cybersecurity role with meaningful program ownership, not an alert-monitoring or ticket-routing position.
About Us
Specialized Dental Partners is a doctor-led network of 275+ specialty dental practices and 450+ doctors across multiple states. We offer the scale, resources, and professional connections that help specialists and teammates thrive, while maintaining the supportive culture and local relationships that define our organization.
Our purpose, We Care More
, shapes how we support our doctors, teammates, and patients every day. We care more about patient outcomes, doctor success, teammate growth, meaningful relationships, and the communities we serve. By combining clinical excellence with a people-first culture, we create an environment where specialists can build rewarding careers while making a lasting impact.
At Specialized Dental Partners, you'll find more than a job. You'll find a community committed to helping you succeed.
From mentorship and career development to clinical collaboration and leadership opportunities, we are committed to helping our people grow personally and professionally.
If you're looking for an organization where your expertise is valued, your growth is supported, and your work makes a meaningful difference, we'd love to meet you!
Responsibilities
Responsibilities:
Security Operations & Incident Response
Monitor enterprise security systems for malicious, suspicious, or abnormal activity
Triage and investigate security alerts involving endpoints, identities, email, cloud services, and other enterprise systems
Determine the scope, severity, and potential impact of identified threats and perform or coordinate containment and remediation actions
Serve as a technical escalation point for cybersecurity issues requiring deeper investigation
Maintain investigation notes, evidence, timelines, and incident documentation and participate in post-incident reviews
Microsoft Defender EDR/XDR
Own day-to-day administration and operation of Microsoft Defender EDR/XDR
Investigate and respond to Defender-generated alerts and incidents
Tune security controls and workflows to improve detection effectiveness and operational efficiency
Identify endpoint security gaps and coordinate remediation with engineering and support teams
Maintain platform standards, documentation, and operational procedures
Vendor Risk Management
Own the enterprise vendor cybersecurity risk management program
Perform security assessments of prospective and existing third-party vendors
Evaluate vendor security controls, policies, technical posture, and identified weaknesses
Produce written vendor risk assessment reports and clearly document findings
Provide technical guidance and risk-based recommendations to senior leadership regarding vendor approval, remediation, acceptance, or rejection
Work with vendors and internal stakeholders to resolve identified concerns and track remediation through completion or formal risk acceptance
Maintain assessment records and evidence required for compliance and audit activities
Security Awareness & Education
Own the ongoing employee cybersecurity awareness and education program
Administer recurring security awareness training and phishing simulation campaigns
Track completion, participation, and program effectiveness and provide targeted education where appropriate
Develop security communications related to phishing, credentials, emerging threats, and other relevant security topics
Maintain training documentation and evidence supporting compliance requirements
Security Engineering & Risk Remediation
Work directly with Infrastructure Engineering and other technology teams to incorporate security into normal operational and engineering activities
Provide security guidance for endpoint, identity, network, cloud, and infrastructure changes
Review findings from risk assessments, vulnerability reviews, incidents, and security testing
Translate identified security gaps into actionable technical remediation and coordinate corrective actions with system owners
Identify recurring control weaknesses and recommend broader technical, process, or automation improvements
Compliance & Security Governance
Support the organization's ongoing HIPAA security compliance program
Assist with implementation, validation, and maintenance of administrative and technical safeguards
Support the organization's target of achieving and maintaining HITRUST e1 readiness and certification objectives
Participate in security risk assessments, control reviews, evidence collection, audits, and remediation activities
Help map operational security practices and technical controls to applicable compliance requirements
Maintain documentation and evidence demonstrating control implementation and effectiveness
Qualifications
Requirements:
5+ years of overall IT experience across cybersecurity, networking, systems engineering, infrastructure, or related technical disciplines
2+ years of direct cybersecurity operations, security monitoring, investigation, or incident response experience
1+ year(s) Experience administering or operating EDR/XDR technologies, including Microsoft Defender EDR/XDR
1+ year(s) Experience producing written security findings and recommendations
1+ year(s) Working knowledge of Windows security, Microsoft 365, Active Directory, and Entra ID
Experience operating endpoint detection and response technologies and investigating security alerts
Experience conducting technical security or vendor risk assessments
Working knowledge of Windows security, Microsoft 365, Active Directory, and Entra ID
Familiarity with vulnerability management, common attacker techniques, and security risk
Experience supporting security or compliance activities in a regulated environment
Ability to translate technical findings into clear business risk and recommendations
Proven ability to communicate effectively with engineers, vendors, business stakeholders, and senior leadership
Preferred Qualifications:
Microsoft Entra ID, Conditional Access, and Identity Protection
Microsoft 365 security technologies
PowerShell scripting and security automation
Vendor and third-party cybersecurity risk management
Security awareness and phishing simulation program management
Threat hunting and vulnerability management
MITRE ATT&CK and NIST Cybersecurity Framework
Experience conducting vendor security assessments or technical risk reviews
HITRUST e1 readiness, assessment, or control implementation experience
Experience supporting healthcare IT environments
Experience translating technical security findings into executive-level recommendations
Familiarity with HIPAA security requirements and security compliance activities
Strong technical troubleshooting, analytical, documentation, and business communication skills
Specialized Dental Partners, its affiliates, related companies and independently owned supported clinical practices are proud to be Equal Opportunity Employers. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
The salary range for this role is $75,000 to $105,000 per year. At Specialized Dental Partners, its affiliates, related companies and independently owned supported clinical practices, we are committed to ensuring fair and equitable pay for all employees. We adhere to all applicable federal, state, and local laws regarding pay equity and non-discrimination.
Our compensation practices are designed to ensure that employees are paid fairly based on their role, experience, performance, and contributions to the company, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. We regularly review our compensation practices and conduct pay equity audits to identify and address any disparities.
By fostering a culture of transparency and fairness, we aim to create an inclusive workplace where all employees feel valued and respected.
Responsibilities
Responsibilities:
Security Operations & Incident Response
Monitor enterprise security systems for malicious, suspicious, or abnormal activity
Triage and investigate security alerts involving endpoints, identities, email, cloud services, and other enterprise systems
Determine the scope, severity, and potential impact of identified threats and perform or coordinate containment and remediation actions
Serve as a technical escalation point for cybersecurity issues requiring deeper investigation
Maintain investigation notes, evidence, timelines, and incident documentation and participate in post-incident reviews
Microsoft Defender EDR/XDR
Own day-to-day administration and operation of Microsoft Defender EDR/XDR
Investigate and respond to Defender-generated alerts and incidents
Tune security controls and workflows to improve detection effectiveness and operational efficiency
Identify endpoint security gaps and coordinate remediation with engineering and support teams
Maintain platform standards, documentation, and operational procedures
Vendor Risk Management
Own the enterprise vendor cybersecurity risk management program
Perform security assessments of prospective and existing third-party vendors
Evaluate vendor security controls, policies, technical posture, and identified weaknesses
Produce written vendor risk assessment reports and clearly document findings
Provide technical guidance and risk-based recommendations to senior leadership regarding vendor approval, remediation, acceptance, or rejection
Work with vendors and internal stakeholders to resolve identified concerns and track remediation through completion or formal risk acceptance
Maintain assessment records and evidence required for compliance and audit activities
Security Awareness & Education
Own the ongoing employee cybersecurity awareness and education program
Administer recurring security awareness training and phishing simulation campaigns
Track completion, participation, and program effectiveness and provide targeted education where appropriate
Develop security communications related to phishing, credentials, emerging threats, and other relevant security topics
Maintain training documentation and evidence supporting compliance requirements
Security Engineering & Risk Remediation
Work directly with Infrastructure Engineering and other technology teams to incorporate security into normal operational and engineering activities
Provide security guidance for endpoint, identity, network, cloud, and infrastructure changes
Review findings from risk assessments, vulnerability reviews, incidents, and security testing
Translate identified security gaps into actionable technical remediation and coordinate corrective actions with system owners
Identify recurring control weaknesses and recommend broader technical, process, or automation improvements
Compliance & Security Governance
Support the organization's ongoing HIPAA security compliance program
Assist with implementation, validation, and maintenance of administrative and technical safeguards
Support the organization's target of achieving and maintaining HITRUST e1 readiness and certification objectives
Participate in security risk assessments, control reviews, evidence collection, audits, and remediation activities
Help map operational security practices and technical controls to applicable compliance requirements
Maintain documentation and evidence demonstrating control implementation and effectiveness
Qualifications
Requirements:
5+ years of overall IT experience across cybersecurity, networking, systems engineering, infrastructure, or related technical disciplines
2+ years of direct cybersecurity operations, security monitoring, investigation, or incident response experience
1+ year(s) Experience administering or operating EDR/XDR technologies, including Microsoft Defender EDR/XDR
1+ year(s) Experience producing written security findings and recommendations
1+ year(s) Working knowledge of Windows security, Microsoft 365, Active Directory, and Entra ID
Experience operating endpoint detection and response technologies and investigating security alerts
Experience conducting technical security or vendor risk assessments
Working knowledge of Windows security, Microsoft 365, Active Directory, and Entra ID
Familiarity with vulnerability management, common attacker techniques, and security risk
Experience supporting security or compliance activities in a regulated environment
Ability to translate technical findings into clear business risk and recommendations
Proven ability to communicate effectively with engineers, vendors, business stakeholders, and senior leadership
Preferred Qualifications:
Microsoft Entra ID, Conditional Access, and Identity Protection
Microsoft 365 security technologies
PowerShell scripting and security automation
Vendor and third-party cybersecurity risk management
Security awareness and phishing simulation program management
Threat hunting and vulnerability management
MITRE ATT&CK and NIST Cybersecurity Framework
Experience conducting vendor security assessments or technical risk reviews
HITRUST e1 readiness, assessment, or control implementation experience
Experience supporting healthcare IT environments
Experience translating technical security findings into executive-level recommendations
Familiarity with HIPAA security requirements and security compliance activities
Strong technical troubleshooting, analytical, documentation, and business communication skills
Specialized Dental Partners, its affiliates, related companies and independently owned supported clinical practices are proud to be Equal Opportunity Employers. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
The salary range for this role is $75,000 to $105,000 per year. At Specialized Dental Partners, its affiliates, related companies and independently owned supported clinical practices, we are committed to ensuring fair and equitable pay for all employees. We adhere to all applicable federal, state, and local laws regarding pay equity and non-discrimination.
Our compensation practices are designed to ensure that employees are paid fairly based on their role, experience, performance, and contributions to the company, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. We regularly review our compensation practices and conduct pay equity audits to identify and address any disparities.
By fostering a culture of transparency and fairness, we aim to create an inclusive workplace where all employees feel valued and respected.
About this listing
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.