HCS Info Security Analyst Sr


UNC Health Care
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- Privacy
- Security Controls
- Software Packaging
- Cloud Architecture
- Collaboration
- Data Flow
- Access Control
- Authentication
- Encryption
- Incident Management
- Auditing
- ISO/IEC 27001:2005
- HIPAA
- HITECH
- NIST 800-53
- System On A Chip
- Cloud Security
- Amazon Web Services
- Google Cloud Platform
- Google Cloud
- Microsoft Azure
- Cloud Computing
- Microsoft
- DLP
- Electronic Discovery
- Analytics
- Scripting
- Windows PowerShell
- Python
- DevSecOps
- Software Development Methodology
- Threat Modeling
- Management
- Continuous Integration
- Continuous Delivery
- Computer Science
- IT Management
- Training
- CISSP
- CISM
- ISACA
- Security+
- Information Security Governance
- Risk Management
- Data Security
- Communication
- Reporting
- Project Coordination
- Risk Assessment
- Documentation
- Stakeholder Engagement
- Regulatory Compliance
- Research
- Legal
- Information Security
- Recruiting
- Health Care
- Shared Services
Summary
Description
Your passion belongs at UNC Health. Join more than 56,000 teammates working together to improve the health and well-being of the communities we serve across North Carolina.
Summary:
The Information Security Analyst Sr. supports research and Trusted Research Environment (TRE) initiatives by ensuring that research systems, data, and third-party services meet organizational security, privacy, and compliance requirements. This role partners with research teams, IT, legal, privacy, and vendors to assess risks, implement security controls, and support secure handling of sensitive data.
Responsibilities:
- Conduct security reviews of research projects, applications, and data environments. This can include software packages, In-house developed applications, Cloud architecture proposals.
- Assess vendor security questionnaires, attestations, and compliance documentation.
- Evaluate research systems for compliance with organizational security standards and regulatory requirements.
- Collaborate with researchers, project managers, infrastructure teams, and compliance stakeholders.
- Review data flows, access controls, authentication methods, and encryption practices.
- Document risks, recommendations, and mitigation plans.
- Assist with incident response activities involving research systems or sensitive data.
- Track remediation activities and provide security consultation throughout project lifecycles.
- Support audits and reporting related to HIPAA, NIST, ISO 27001, SOC 2, and other applicable frameworks.
Preferred Qualifications:
- Strong hands-on experience in Azure Cloud Security and Information Security.
- Practical experience with Microsoft Defender for Cloud and Azure security services.
- Knowledge of healthcare data compliance frameworks (HIPAA, HITECH, NIST 800-53, SOC, HITRUST, CIS Benchmarks).
- Understanding cloud security concepts (Azure, AWS, or Google Cloud Platform).
- Strong written and verbal communication skills.
- Deep understanding of Azure TRE architecture, enclave boundaries, airlock mechanisms, and isolated cloud workspaces.
- Advanced proficiency in Microsoft Purview (DLP, Information Protection, eDiscovery, Insider Risk Management).
- Understanding of KQL log analytics and scripting (PowerShell/Python) for security automation.
- Embed security into DevSecOps and Secure SDLC, including threat modelling, security requirements, code/IaC/container scanning, secrets management, vulnerability remediation, and CI/CD security gates.
- Experience supporting healthcare, academic, or research environments.
- Familiarity with research governance and handling of sensitive or regulated data.
- Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent.
- Experience with vendor risk management and third-party security reviews.
Other Information
Education Requirements:
Bachelor's degree in Computer Science, Information Systems Management or a related field (or an equivalent combination of education, training and experience) required.
Licensure/Certification Requirements:
- No licensure or certification required.
- Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent are preferred.
Professional Experience Requirements:
If a Bachelor's degree: Eight (8) years in professional IT positions, with 4 years of experience in related job functions required.
If an Associate's degree: Twelve (12) years in professional IT positions, with 4 years of experience in related job functions required.
If a high school diploma or GED: Sixteen (16) years in professional IT positions, with 4 years of experience in related job functions required.
Knowledge/Skills/and Abilities Requirements:
Key Competencies:
- Risk assessment and analysis
- Security governance and compliance
- Vendor and third-party risk management
- Research data protection
- Stakeholder communication
- Documentation and reporting
- Project coordination
Success Measures:
- Timely completion of security reviews and risk assessments.
- Effective identification and mitigation of security risks.
- High-quality documentation and stakeholder engagement.
- Compliance with organizational and regulatory requirements.
- Successful support of research and TRE initiatives while maintaining security standards.
Job Details
Legal Employer: NCHEALTH
Entity: Shared Services
Organization Unit: ISD Information Security
Work Type: Full Time
Standard Hours Per Week: 40.00
Salary Range: $44.56 - $64.06 per hour (Hiring Range)
Pay offers are determined by experience and internal equity
Work Assignment Type: Hybrid
Work Schedule: Day Job
Location of Job: US:NC:Morrisville
Exempt From Overtime: Exempt: Yes
This position is employed by NC Health (Rex Healthcare, Inc., d/b/a NC Health), a private, fully-owned subsidiary of UNC Health Care System, in a department that provides shared services to operations across UNC Health Care; except that, if you are currently a UNCHCS State employee already working in a designated shared services department, you may remain a UNCHCS State employee if selected for this job.
Qualified applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, disability, status as a protected veteran or political affiliation.
UNC Health makes reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as applicants and employees with disabilities. All interested applicants are invited to apply for career opportunities. Please email [email protected] if you need a reasonable accommodation to search and/or to apply for a career opportunity.
- Dice Id: 10105580
- Position Id: 18193950
- Posted 3 hours ago
Company Info
UNC Health has been named by Forbes one of America’s Best Employers for Women. The top 400 companies made the list, including 35 hospitals and healthcare systems. UNC Health is Forbes’ top-ranked healthcare system employer for women in the entire Southeast. UNC Health is #10 overall among health systems and #1 in the southeast!
Also, did you know that FORTUNE has recognized UNC Health as One of America’s Most Innovative Companies?
UNC Health is an award-winning, not-for-profit integrated health care system. Become part of an inclusive organization with over 40,000 diverse employees, whose mission is to improve the health and well-being of the unique communities we serve!
UNC Health for Me:
Learn how UNC Health is supporting teammates, both personally and professionally, throughout their journey with UNC Health. "UNC Health for Me" is UNC Health's commitment to teammates from recruitment to retirement that includes ways we welcome, engage, develop, care for, include, and value our teammates. As part of our ONE UNC Health initiative, "UNC Health for Me" employs strategies to strengthen our world-class team and ensure we achieve our mission.


Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs