Security Analyst - Must reside in CA, or be willing to relocate
Institute on Aging · San Francisco, CA, United States
About The Role
IOA is on the forefront of revolutionary healthcare models, reshaping the way people can age in place. Our innovative models transform lives, enhance communities, and save healthcare systems millions of dollars. Rather than focusing on archaic outdated design, we strive to consistently question the “status-quo” and create new and more innovative ways to help aging adults and adults with disabilities maintain their quality of life.
With over 23 programs, we offer multiple ways to aid seniors maintain their health, well-being, independence and participation in the community, fulfilling our mission.
The Security Analyst is responsible for assessing information risk and facilitates remediation of identified vulnerabilities for IT security and risk across the agency. Key duties and responsibilities of the position include, but may not be limited to:
- Assessing information risk and facilitates remediation of identified vulnerabilities with IOA’s network, systems, and applications
- Performing vulnerability assessments utilizing IT security tools and methodologies
- Performing assessments of the IT security/risk posture within the network, systems, and software applications, in addition to assessments within the Vendor Management Program
- Identifying opportunities to reduce risk and documents remediation options regarding acceptance or mitigation of risk scenarios
- Facilitating and monitoring the performance of risk remediation tasks and changes related to risk mitigation
- Reporting findings and making recommendations for corrective action
- Maintaining oversight of IT and vendors regarding the security maintenance of their systems and applications
- Providing regular status reports that include outstanding issues
- Assisting in all IT audits, risk assessments and regulatory compliance matters
- Performing IT security and risk assessments across the enterprise (e.g., data systems, network and/or web). This includes Data Loss Prevention, Advanced Threat Detection, Identity Access Management, End-Point Security, and Forensic Analysis
- Facilitating and monitoring IT Security incident management and response
- Addressing questions from internal and external audits and examinations
- Providing guidance and best practice recommendations for IT security policies, procedures, and standards that meet regulatory requirements, including HIPAA, SOC2, HITRUST, and PCI
- Creating and facilitating IT security/risk training curriculum for the enterprise
- Serving as project manager/lead for IT security projects
- Leading IT architecture security risk assessments and developing solutions/processes
REQUIRED QUALIFICATIONS
- Associates degree or higher in Information Systems, Computer Science, Information Security, or related discipline
- 4+ years of IT security or information security experience
- 2+ years of experience conducting IT compliance assessments (e.g., HIPAA, HITRUST, PCI, etc.)
- 2+ years of experience administering IT security controls
- Demonstrated knowledge of technical infrastructure, networks, databases, and systems in relation to IT Security and IT Risk
- Experience with IPS/IDS and SIEM technologies
- Windows workstation and server administration experience
- Experience producing and reviewing security reports, findings, and metrics
- Excellent interpersonal, oral, and written communication skills
- Excellent MS Office skills
COMPENSATION
Range: $ 130,000 to $134,000/annual
This amount is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific employee, which is always dependent on actual experience, education and other factors.
This range does not include any additional equity, benefits, or other non-monetary compensation which may be included.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
