IT Security Analyst
Job Description
The IT Security Analyst helps protect healthcare information systems, data, and infrastructure through proactive risk management, continuous monitoring, and regulatory-aligned controls. The role supports HIPAA-focused access governance, vendor risk oversight, incident response, and policy development within a healthcare environment.
Responsibilities
- Annually assess changes to cyber insurance requirements and coordinate with the Director of Information Security to implement necessary policy, technical, or procedural updates.
- Complete annual attestation forms and applications required for cyber insurance renewal.
- Implement, monitor, and maintain security protocols and controls across the environment.
- Perform regular audits of user accounts, security groups, and MFA compliance.
- Coordinate periodic penetration testing and vulnerability assessments with an approved third‑party vendor; track and remediate identified deficiencies.
- Manage the security vendor quotation and evaluation process.
- Support the HIPAA-aligned risk analysis, contribute to the risk register, and track remediation owners and timelines.
- Verify and maintain encryption standards for electronic protected health information (ePHI) at rest and in transit across endpoints, servers, and email.
- Review information system activity, including audit logs and security incident reports, to detect unauthorized or anomalous ePHI access.
- Implement and test audit controls that record activity in information systems containing or using ePHI.
- Manage remote monitoring and management tools, SIEM, antivirus, and EDR platforms, including alert triage and incident reporting.
- Support technical incident response activities, including investigation, containment, and coordination with the Compliance Manager on breach risk determination and notification requirements.
- Administer and monitor the Proofpoint email security platform.
- Oversee Windows endpoint patch management and associated compliance reporting.
- Adjust firewall rules as needed to support security requirements.
- Maintain an inventory of networked, biomedical, and IoMT devices that create, store, or transmit ePHI; monitor for vulnerabilities and support network segmentation to isolate high‑risk devices.
- Configure and verify technical access controls on systems containing ePHI, including unique user identification and emergency access procedures.
- Verify that ePHI backups are encrypted, stored offline or in immutable form, and that restoration testing is conducted regularly.
- Assist in developing and maintaining policies and procedures supporting the cybersecurity posture and HIPAA regulatory requirements.
- Support security controls and audit processes for the EHR system and other systems containing ePHI; participate in access reviews to enforce least privilege.
- Support vendor security risk assessments and due diligence for third parties with access to ePHI, in coordination with the Compliance Manager.
- Ensure BAAs are executed and current for all third parties handling ePHI, in collaboration with the Compliance Manager.
- Support physical safeguards and device controls, including secure disposal and tracking of hardware and media containing ePHI.
- Assist with provisioning and deprovisioning access upon hire, role change, and termination, and help enforce workforce security policies.
- Maintain security documentation and evidence for HIPAA retention requirements, and participate in Business Continuity and Disaster Recovery planning and testing.
- Monitor healthcare-specific threat intelligence and translate alerts into defensive actions.
- Manage employee security awareness training programs and track completion and compliance.
- Research and participate in security conferences and continuing education opportunities.
- Maintain cyber insurance attestations and policy updates to stay current and audit-ready.
- Document and track penetration testing, vulnerability assessments, and remediation timelines to closure.
- Contribute updates to the HIPAA risk register with clear ownership and remediation timelines.
- Review audit logs, access reports, and security incident tracking regularly and escalate anomalies as needed.
- Maintain proper configuration and monitoring of SIEM, EDR, antivirus, and email security platforms with defined response windows.
- Maintain Windows endpoint patch compliance against organizational targets.
- Support incident response with timely documentation and coordination on breach risk determination.
- Keep an accurate inventory of devices and monitor known vulnerabilities, addressing them as appropriate.
- Document backup encryption and restoration testing results and ensure timely verification.
- Support policy development, access reviews, and vendor risk assessments aligned with HIPAA deadlines and audit expectations.
- Maintain security documentation and six-year retention of evidence.
- Participate in Business Continuity/Disaster Recovery planning, testing, and after-action reporting.
- Track security awareness training completion and report progress.
- Demonstrate professional communication across IT, compliance, and vendor stakeholders and escalate issues promptly as needed.
- Stay current on cybersecurity threats and technologies through ongoing professional development.
Qualifications and Experience
- Minimum of 3 years of relevant security experience.
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Strong verbal and written communication skills.
- Ability to collaborate across IT and compliance functions while managing competing priorities.
Certifications and Licenses
- CompTIA Security+ or higher required.
- Preferred: CompTIA CySA+, GIAC GSEC, or CISSP.
Technologies
- Microsoft 365 security stack (Entra ID / Azure AD, Exchange Online, Microsoft Defender, Conditional Access, Purview / DLP)
- PowerShell scripting
- SIEM, EDR, Proofpoint, and Remote Monitoring and Management (RMM) tools
Location, Schedule, and Compensation
Location: Hanover, Maryland. This is a hybrid role with three on-site days per week and two remote days. Salary is USD 95,000 to 125,000 annually.
Physical Demands
The role requires sitting with occasional standing and light lifting up to 30 pounds. Visual acuity and manual dexterity are needed for keyboard use and related tasks.
Working Conditions
Typically performed in a corporate office or clinic environment with potential interaction with staff and patients. Some travel to affiliated locations may be required. On-call availability may be necessary to support security incident response.