The Lead Cybersecurity Analyst provides advanced technical expertise and lead-level coordination for the protection of Billings Clinic’s information systems, digital assets, networks, applications, and data. This position supports the proactive assessment, monitoring, analysis, and response to cybersecurity threats and vulnerabilities. The Lead Cybersecurity Analyst serves as a technical resource for cybersecurity operations, incident response, threat analysis, security controls, risk mitigation, and security best practices. This role partners with Information Technology teams, operational leaders, vendors, compliance, privacy, and other stakeholders to evaluate cybersecurity risks, support secure technology solutions, and strengthen the organization’s security posture. The position provides guidance to cybersecurity team members, supports prioritization of work, assists with escalation of complex issues, and promotes consistent cybersecurity practices across the organization. Essential Job Functions • Cybersecurity Operations and Threat Monitoring Leads and supports daily cybersecurity operations, including monitoring, analysis, investigation, and response to security events, alerts, vulnerabilities, and emerging threats. Analyzes cybersecurity events and determines potential impact to systems, operations, users, and the organization. Maintains awareness of the current cybersecurity threat landscape by reviewing threat intelligence, industry alerts, security advisories, internet postings, and other relevant sources. Identifies trends, recurring issues, and potential risks, and recommends actions to reduce exposure to malicious cyber activity. Maintains and supports cybersecurity tools, monitoring systems, and related technologies used to protect the environment. • Incident Response and Escalation Determines whether monitored security events should be escalated to incidents and follows applicable incident response and reporting processes. Leads or supports cybersecurity incident response activities, including triage, containment, investigation, documentation, escalation, communication, and remediation follow-up. Provides technical guidance during cybersecurity events, system compromises, vulnerability concerns, and other high-risk security situations. Supports post-incident reviews and assists with identifying root causes, lessons learned, and process improvements. Coordinates with Information Technology, Compliance, Privacy, leadership, vendors, and other stakeholders during cybersecurity incidents as appropriate. • Security Controls, Risk Reduction, and Technical Consultation Implements, monitors, and evaluates security controls to protect Billings Clinic systems, networks, data, applications, and digital assets. Provides cybersecurity consultation on IT initiatives, business projects, application changes, infrastructure changes, and technology implementations. Evaluates security tools, technologies, and processes and makes recommendations to address identified risks or security needs. Supports vulnerability assessment, system hardening, access controls, network security, endpoint protection, and other security risk-reduction efforts. Reviews security implications of proposed technical solutions and provides recommendations consistent with organizational policies, standards, and industry best practices. • Lead Responsibilities and Team Support Provides lead-level guidance, mentoring, and technical support to cybersecurity analysts and other team members. Assists with prioritizing team workload, coordinating response to security events, and ensuring timely follow-through on assigned work. Supports development and maintenance of cybersecurity procedures, playbooks, standards, documentation, and operational workflows. Serves as an escalation point for complex cybersecurity issues, investigations, and technical questions. Assists leadership with identifying training needs, process gaps, tool improvements, and opportunities to strengthen team effectiveness. Promotes a culture of accountability, collaboration, continuous improvement, and service excellence within the cybersecurity team. • Collaboration, Compliance, and Organizational Support Works closely with Information Technology operations, network teams, system administrators, application teams, business stakeholders, and other appropriate groups to evaluate and respond to cybersecurity risks. Supports organizational compliance with applicable policies, procedures, HIPAA, confidentiality requirements, cybersecurity standards, and regulatory expectations. Assists with audits, security reviews, risk assessments, documentation requests, and reporting as needed. Communicates cybersecurity risks, technical issues, recommendations, and status updates clearly to both technical and non-technical audiences. Supports and models behaviors consistent with Billings Clinic’s mission, vision, values, code of business conduct and service expectations. Meets all mandatory organizational and departmental requirements. Maintains competency in all organizational, departmental and outside agency standards as it relates to the environment, employee, patient safety or job performance. Performs all other duties as assigned or as needed to meet the needs of the department/organization.