The role of the security analyst can span all areas of security operations, and interface with security architecture, offensive security, cloud platforms and DevSecOps. The analyst is not expected to perform all of the below, but to have a broad understanding and expertise to operate across a number of the noted areas of security.
Security operation - Vulnerability Management:
o Gather and document service and product information from application and system owners to assist in threat risk analysis.
o Implement, administer, and support web application and infrastructure vulnerability scanning tools working with vendors as required.
o Work directly with application and system owners to perform web application and infrastructure vulnerability scans, including performing pre-scan risk assessments to determine suitability for same.
o Implement and support host-based web-specific security solutions to secure web hosting environments.
o Security assessments through code reviews, automation and security architecture audits
o Manage and implement various types of scanning (SAST, DAST, SCA,IAST, RASP) in TELUS Health CI/CD pipelines and ensure results are appropriately surfaced working collaboratively with developers
Security operation - Threat management:
o Monitor and research external threat intelligence and vulnerability feeds to identify new risks directly applicable to applications and application platforms in use by TELUS Health.
o Notify designated product managers of new or suspected critical or high risk vulnerabilities in enterprise systems.
o Report on vulnerabilities found in web applications and infrastructure for system owners and administrators, providing recommendations for mitigation. Work with the support teams to prioritize remediation to align with security SLAs.
Security operation - Threat prevention:
o Manage and configure web application firewalls working with product development teams to define protection rules to mitigate identified vulnerabilities.
o Manage the policy and playbooks interfacing with managed security prevention services spanning EDR, NDR, and MDR.
o Manage the policy and implementation for threat prevention tooling spanning at least 3 of the following; endpoint security, network security, identity and access, application security and data security.
o Configure and manage Advanced Threat Protection modules within the TELUS Health Unified Threat Management security devices.