JOB OBJECTIVE SUMMARY:
The Information Security Analyst is a key associate at Hope Network whose primary responsibilities include: The Information Security Analyst plays a key role in safeguarding Hope Network’s systems and data. This position is responsible for developing, implementing, and maintaining security measures aligned with industry best practices and healthcare compliance requirements. The role emphasizes proactive risk identification, continuous monitoring, and ensuring adherence to regulatory standards such as HIPAA and HITECH.
ESSENTIAL FUNCTIONS AND RESPONSIBILITIES:
This is not intended to be an exhaustive listing of job functions. This job description in no way states or implies that these are the only duties to be performed by this employee. The employee is required to follow any other instructions and to perform any other duties as assigned.
- Regular and predictable attendance is an essential requirement of this position.
- Develop security standards and best practices for the organization.
- Investigate IT security incidents.
- Conduct regular internal penetration testing.
- Research the latest information technology (IT) security trends.
- Recommend security enhancements to management or senior IT staff.
- Review third-party application security vulnerabilities and recommend updates.
- Coordinate and execute IT security projects including security assessments and manage remediation of findings.
- Document, maintain and coordinate Business Continuity processes and testing.
- Research, test, and deploy additional security processes and products in response to identified vulnerabilities.
- Conduct regular vulnerability scans and penetration testing.
- Review firewall rules and monitor logs.
- Manage Intrusion Detection (IDS), Prevention (IPS), Data Loss Prevention (DLP) and Cryptography/Encryption solutions.
Addendum for Essential Functions if Applicable for multiple departments:
- Coordinate with Corporate Compliance department to ensure compliance with various regulations.
Position Qualifications:
- Bachelor’s degree in Computer Science or relevant IT security business experience.
- 3 years of experience in an IT position involving security administration.
- Experience with HIPAA Security Rule and HITECH Act and how it affects IT security.
- General knowledge of information security frameworks, standards, and best practices.
- Technical knowledge of network security solutions management and analysis.
- Preferred certifications: Security+, CISA, CISSP, CISM, or CEH.
- Strong communication skills and the ability to translate technical concepts for non-technical audiences.
- Ability to work independently and with cross-functional teams.
- Strong understanding of Active Directory, LDAP, DB, Azure, Office 365/M365 administration, and compliance.