Position Summary
The Senior Information Security Analyst plays a key role in protecting the organization’s healthcare systems, clinical technologies, and sensitive patient data. This position provides advanced technical expertise in threat detection, incident response, vulnerability management, and risk mitigation, while serving as a mentor to junior analysts. The Senior Analyst partners closely with IT, clinical leadership, compliance, and business stakeholders to ensure a strong security posture and adherence to healthcare regulatory requirements, including HIPAA and HITECH.
Key Responsibilities
- Lead investigation and response to complex security incidents involving healthcare systems, ePHI, and clinical applications
- Perform advanced threat analysis, correlation, and root cause analysis using SIEM, EDR, and other security tooling
- Serve as a subject matter expert for incident response, vulnerability management, and security operations processes
- Coordinate incident response across IT, clinical operations, legal, compliance, and leadership as required
- Conduct risk assessments and security reviews of enterprise, clinical, and third‑party systems
- Drive vulnerability remediation efforts and validate effectiveness of security controls
- Support and lead audit activities related to HIPAA, HITECH, SOC, or other regulatory and industry frameworks
- Develop, refine, and maintain security policies, standards, procedures, and incident response playbooks
- Mentor and provide technical guidance to Information Security Analyst I and II staff
- Partner with engineering and infrastructure teams on secure system design and architecture
- Stay informed on emerging healthcare cyber threats, ransomware trends, and regulatory changes
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience)
- 6–8+ years of progressive experience in information security or security operations
- Demonstrated experience leading incident response and handling complex security events
- Strong expertise in:
- SIEM, EDR, and security monitoring platforms
- Vulnerability management and risk assessment
- Endpoint, network, identity, and access security
- In‑depth knowledge of HIPAA Security Rule requirements and healthcare regulatory environments
- Solid understanding of Windows and Linux systems, networking concepts, and common attack techniques
- Strong communication skills with the ability to explain risk to technical and non‑technical audiences
- Proven ability to work independently and take ownership of security initiatives in a healthcare setting
Preferred Qualifications
- Experience in hospital, health system, payer, or clinical research environments
- Familiarity with EHR platforms, medical devices, and clinical workflows
- Experience securing cloud‑based healthcare environments (Azure, AWS, or GCP)
- Experience with Quantitative Risk Analysis and the FAIR model
- Scripting or automation experience (PowerShell, Python, or similar)
- Relevant certifications such as:
- CISSP, CISM, or HCISPP
- GCIH, GCED, or equivalent advanced security certifications