Cybersecurity Analyst
Job Description
PHI Health, LLC offers a competitive pay and benefits package designed to support teams in staying happy, healthy, and invested. This onsite role in Phoenix, AZ (5&2) helps strengthen cybersecurity governance and operational readiness through documented, measurable processes aligned with organizational and regulatory expectations.
What You’ll Do
The Cybersecurity Analyst supports PHI Health’s cybersecurity governance program by administering policy and documentation, coordinating risk management activities, and partnering across IT and business departments. The position helps maintain organized controls, tracks remediation through completion, and supports compliance-related evidence needs spanning internal audits, external audits, cyber insurance renewals, and customer security questionnaires.
- Coordinate and maintain the enterprise cybersecurity governance program.
- Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines, including periodic policy reviews.
- Maintain the enterprise cybersecurity risk register and track mitigation activities through completion.
- Conduct cybersecurity reviews for new technologies, software solutions, AI tools, and business initiatives using established risk assessment processes.
- Coordinate third-party security assessments and vendor cybersecurity reviews.
- Assist with HIPAA Security Rule, NIST Cybersecurity Framework, and other regulatory or contractual compliance activities.
- Coordinate cybersecurity evidence collection for internal audits, external audits, cyber insurance renewals, and customer security questionnaires.
- Administer the cybersecurity awareness program, including KnowBe4 campaigns, phishing simulations, and user education initiatives.
- Track cybersecurity metrics and key performance indicators, and prepare executive dashboards and management reports.
- Coordinate Cybersecurity Council meetings, document action items, and track completion of assigned tasks.
- Maintain cybersecurity documentation, including inventories, exception registers, standards, and supporting records.
- Support incident response activities through documentation, communications, lessons learned, and corrective action tracking.
- Assist in coordinating tabletop exercises, business continuity planning, and disaster recovery testing.
- Monitor cybersecurity project milestones to ensure governance deliverables are completed on schedule.
- Maintain inventory of cybersecurity tools, licensing, subscriptions, and service contracts.
- Support annual cybersecurity program reviews and continuous improvement initiatives.
- Perform other cybersecurity administrative and operational duties as assigned.
Primary Functional Ownership
- Cybersecurity Policies & Standards
- Governance Documentation
- Cybersecurity Risk Register
- AI Risk Intake Assessments
- Third-Party Risk Reviews
- Vendor Security Questionnaires
- Security Awareness Program
- KnowBe4 Administration
- Cyber Insurance Evidence
- Audit Coordination
- NIST Framework Tracking
- HIPAA Security Documentation
- Cybersecurity Metrics & Dashboards
- Cybersecurity Council Administration
- Business Continuity Documentation
- Security Program Reporting
What You Bring
- Bachelor's degree in Cybersecurity, Information Technology, Business Administration, Information Systems, or related field; or equivalent combination of education and experience.
- 1+ years experience preferred (One to three years of experience in cybersecurity, information technology, compliance, risk management, auditing, or related fields preferred.).
- Experience creating documentation, reports, or technical procedures.
- Experience coordinating projects or working across multiple departments preferred.
- Experience supporting regulated environments such as healthcare, aviation, or financial services is preferred but not required.
- Strong written communication skills and excellent organizational and documentation abilities.
- Ability to manage multiple projects simultaneously.
- Strong analytical and critical thinking skills, with attention to detail.
- Comfortable working with technical and non-technical stakeholders.
- Excellent presentation and communication skills, with ability to learn new technologies quickly.
- Strong customer service mindset and ability to maintain confidentiality.
Tools & Technical Areas
- Microsoft Defender Security Suite
- Microsoft Entra ID / Azure Active Directory
- KnowBe4
- Microsoft 365 Security
- SIEM and security monitoring platforms
- Vulnerability management tools
- Identity and Access Management (IAM)
- Multi-factor Authentication
- Privileged Access Management
- Network security principles
- Endpoint security
- Email security
- NIST Cybersecurity Framework
- Security hardening standards
- Incident response methodologies
Nice to Have
- Preferred but not required: Security+
- Preferred but not required: ISC2 Certified in Cybersecurity (CC)
- Preferred but not required: Microsoft Security Fundamentals
- Preferred but not required: Certified HIPAA Security Professional
- Preferred but not required: ITIL Foundation
Core & Behavioral Competencies
- Core Competencies: Safe. Efficient. Quality. Service.
- Behavioral Competencies: Show Real Grit, Perform with Integrity, Be a great team player, Give and Get Help.