Duke University - Durham, NC

posted 3 months ago

Full-time - Entry Level
Durham, NC
Educational Services

About the position

The Information Security Analyst at Duke Health plays a crucial role in supporting various operational and consultative functions within the Duke Information Security Office (ISO). This position is dedicated to the design, implementation, management, and monitoring of technical, administrative, and physical controls aimed at safeguarding the confidentiality, integrity, and availability of the organization's information assets. The analyst will collaborate closely with IT, clinical, research, and management staff across Duke to ensure robust security measures are in place. The role encompasses multiple domains of information security, with specific duties assigned based on the analyst's working title. The primary focus for this position, designated as Governance and Risk Security Analyst, involves regulatory compliance, particularly in highly regulated research environments associated with the Duke Health School of Medicine. Candidates with prior experience in an Academic Medical Center and familiarity with NIST SP 800-53 compliance are strongly preferred. In addition to governance and risk management, the analyst may engage in vendor risk assessments, exception management, and security policy management, ensuring alignment with HIPAA, NIST CSF, CIS, and other security frameworks. The position also includes responsibilities related to Identity and Access Management (IAM), penetration testing, vulnerability management, incident response, and business continuity planning. Analysts are expected to maintain a high level of communication and collaboration with various stakeholders to effectively address security vulnerabilities and implement necessary remediation measures. Overall, the Information Security Analyst is integral to advancing Duke Health's commitment to secure and innovative healthcare solutions, ensuring that all information security practices are not only compliant but also effective in mitigating risks associated with information technology.

Responsibilities

  • Design, implement, manage, and monitor technical, administrative, and physical controls to protect information assets.
  • Conduct vendor risk assessments and manage exceptions related to security policies.
  • Ensure compliance with regulatory frameworks such as HIPAA, NIST CSF, and CIS.
  • Assist in the implementation and administration of Identity and Access Management (IAM) solutions.
  • Perform comprehensive penetration tests and security assessments to identify vulnerabilities.
  • Analyze and interpret penetration test results and provide actionable remediation recommendations.
  • Identify and prioritize security vulnerabilities based on risk severity and impact.
  • Deploy, configure, and maintain security solutions and tools such as Endpoint Detection & Response and Data Loss Prevention.
  • Analyze findings from security monitoring systems to identify potential security incidents.
  • Design and deliver security awareness training for staff and promote security culture activities.
  • Coordinate Business Impact Assessments and develop continuity and recovery plans.

Requirements

  • Bachelor's degree in a related clinical or technical field, or four years of equivalent technical experience required.
  • For Level 3, a Master's degree in a related clinical or technical field is preferred.
  • Security+ or equivalent certification preferred for Level 1.
  • One or more information security industry certifications (e.g., CISSP, CISM, CISA, CEH) preferred for Level 2 and required for Level 3.
  • No experience required for Level 1; two years of related experience for Level 2; four years for Level 3.
  • Familiarity with information security practices, standards, and systems such as DLP, IDS/IPS, SIEM, VPN, and encryption technologies.

Nice-to-haves

  • Experience working in an Academic Medical Center with regulatory compliance to NIST SP 800-53.
  • Knowledge of additional regulatory compliance requirements and IT management frameworks such as FISMA, HITRUST, and PCI DSS.

Benefits

  • Health insurance coverage
  • Dental insurance coverage
  • 401k retirement savings plan
  • Paid holidays and vacation time
  • Tuition reimbursement for further education
  • Professional development opportunities
  • Flexible scheduling options
  • Employee discount programs
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service