HCS Info Security Analyst Sr

UNC REX Healthcare

Morrisville (NC)

Hybrid

USD 61,000 - 88,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

UNC Health is seeking an Information Security Analyst Sr to support TRE initiatives, ensuring research systems, data, and third‑party services meet security, privacy, and regulatory requirements.

You will partner with researchers, IT, legal, and vendors to assess risks, implement controls, and guide secure handling of sensitive data across cloud and on‑prem environments.

Qualifications

  • Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent preferred.
  • Experience with TRE architecture and secure cloud workspaces.
  • Familiarity with HIPAA, NIST, SOC 2, HITRUST, CIS Benchmarks.

Responsibilities

  • Conduct security reviews of research projects, applications, and data environments.
  • Assess vendor security questionnaires, attestations, and compliance documentation.
  • Evaluate research systems for compliance with security standards and regulatory requirements.
  • Collaborate with researchers, project managers, infrastructure teams, and compliance stakeholders.
  • Review data flows, access controls, authentication methods, and encryption practices.
  • Document risks, recommendations, and mitigation plans.
  • Assist with incident response activities involving research systems or sensitive data.
  • Track remediation activities and provide security consultation throughout project lifecycles.
  • Support audits and reporting related to HIPAA, NIST, ISO 27001, SOC 2, and other applicable frameworks.

Skills

Azure Cloud Security
Microsoft Defender for Cloud
Azure TRE architecture
Purview (DLP, Information Protection)
KQL / scripting (PowerShell/Python)
DevSecOps & Secure SDLC
Security governance & compliance
Vendor risk management
Healthcare data security
Communication excellence

Education

Bachelor’s degree in Computer Science, Information Systems Management or related field

Tools

PowerShell
Python
Microsoft Purview
CI/CD security tooling

Job description

Description

Your passion belongs at UNC Health. Join more than 56,000 teammates working together to improve the health and well-being of the communities we serve across North Carolina.

Summary:

The Information Security Analyst Sr. supports research and Trusted Research Environment (TRE) initiatives by ensuring that research systems, data, and third-party services meet organizational security, privacy, and compliance requirements. This role partners with research teams, IT, legal, privacy, and vendors to assess risks, implement security controls, and support secure handling of sensitive data.

Responsibilities
  • Conduct security reviews of research projects, applications, and data environments. This can include software packages, In-house developed applications, Cloud architecture proposals.
  • Assess vendor security questionnaires, attestations, and compliance documentation.
  • Evaluate research systems for compliance with organizational security standards and regulatory requirements.
  • Collaborate with researchers, project managers, infrastructure teams, and compliance stakeholders.
  • Review data flows, access controls, authentication methods, and encryption practices.
  • Document risks, recommendations, and mitigation plans.
  • Assist with incident response activities involving research systems or sensitive data.
  • Track remediation activities and provide security consultation throughout project lifecycles.
  • Support audits and reporting related to HIPAA, NIST, ISO 27001, SOC 2, and other applicable frameworks.
Preferred Qualifications
  • Strong hands‑on experience in Azure Cloud Security and Information Security.
  • Practical experience with Microsoft Defender for Cloud and Azure security services.
  • Knowledge of healthcare data compliance frameworks (HIPAA, HITECH, NIST 800‑53, SOC, HITRUST, CIS Benchmarks).
  • Understanding cloud security concepts (Azure, AWS, or GCP).
  • Strong written and verbal communication skills.
  • Deep understanding of Azure TRE architecture, enclave boundaries, airlock mechanisms, and isolated cloud workspaces.
  • Advanced proficiency in Microsoft Purview (DLP, Information Protection, eDiscovery, Insider Risk Management).
  • Understanding of KQL log analytics and scripting (PowerShell/Python) for security automation.
  • Embed security into DevSecOps and Secure SDLC, including threat modelling, security requirements, code/IaC/container scanning, secrets management, vulnerability remediation, and CI/CD security gates.
  • Experience supporting healthcare, academic, or research environments.
  • Familiarity with research governance and handling of sensitive or regulated data.
  • Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent.
  • Experience with vendor risk management and third-party security reviews.
Other Information
Education Requirements

Bachelor’s degree in Computer Science, Information Systems Management or a related field (or an equivalent combination of education, training and experience) required.

Licensure/Certification Requirements
  • No licensure or certification required.
  • Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent are preferred.
Professional Experience Requirements

If a Bachelor's degree: Eight (8) years in professional IT positions, with 4 years of experience in related job functions required.

If an Associate's degree: Twelve (12) years in professional IT positions, with 4 years of experience in related job functions required.

If a high school diploma or GED: Sixteen (16) years in professional IT positions, with 4 years of experience in related job functions required.

Key Competencies
  • Risk assessment and analysis
  • Security governance and compliance
  • Vendor and third-party risk management
  • Research data protection
  • Stakeholder communication
  • Documentation and reporting
  • Project coordination
Success Measures
  • Timely completion of security reviews and risk assessments.
  • Effective identification and mitigation of security risks.
  • High-quality documentation and stakeholder engagement.
  • Compliance with organizational and regulatory requirements.
  • Successful support of research and TRE initiatives while maintaining security standards.
Job Details

Legal Employer: NCHEALTH

Entity: Shared Services

Organization Unit: ISD Information Security

Work Type: Full Time

Standard Hours Per Week: 40.00

Salary Range:$44.56 - $64.06 per hour (Hiring Range)

Pay offers are determined by experience and internal equity

Work Assignment Type: Hybrid

Work Schedule: Day Job

Location of Job: US:NC:Morrisville

Exempt From Overtime: Exempt: Yes

This position is employed by NC Health (Rex Healthcare, Inc., d/b/a NC Health), a private, fully‑owned subsidiary of UNC Health Care System, in a department that provides shared services to operations across UNC Health Care; except that, if you are currently a UNCHCS State employee already working in a designated shared services department, you may remain a UNCHCS State employee if selected for this job.

Qualified applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, disability, status as a protected veteran or political affiliation.

UNC Health makes reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as applicants and employees with disabilities. All interested applicants are invited to apply for career opportunities. Please email applicant.accommodations@unchealth.unc.edu if you need a reasonable accommodation to search and/or to apply for a career opportunity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

HCS Info Security Analyst Sr
HCS Info Security Analyst Sr

UNC Health Care • Morrisville (NC)

Hybrid
USD 61,000 - 88,000
Compliance Analyst III - Compliance and Privacy
Compliance Analyst III - Compliance and Privacy

UNC Health Care • Morrisville (NC)

Hybrid
USD 46,000 - 66,000
Security Analyst II - IS INFO SECURITY
Security Analyst II - IS INFO SECURITY

Kettering Health • Miamisburg (OH)

On-site
USD 70,000 - 100,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Homeland Talent Solutions • Knoxville (TN)

Hybrid
USD 112,000 - 146,000
Competitive salary
Comprehensive benefits package
Opportunities for professional growth
Compliance Analyst III - Compliance and Privacy
Compliance Analyst III - Compliance and Privacy

UNC REX Healthcare • Morrisville (NC)

Hybrid
USD 45,000 - 66,000
Senior Information Security Analyst
Senior Information Security Analyst

UMass Amherst • Amherst (MA)

Hybrid
USD 120,000 - 150,000
Information Security Specialist (Remote)
Information Security Specialist (Remote)

Harris Computer • North Dakota

On-site
USD 80,000 - 110,000
Competitive compensation package
Health Insurance (medical, dental, vision)
Paid Vacation
+1
IT Security Analyst
IT Security Analyst

University-of-California---SAN-Francisc • San Francisco (CA)

On-site
USD 120,000 - 175,000
IT Security Analyst
IT Security Analyst

University of California, San Francisco • San Francisco (CA)

On-site
USD 140,000 - 190,000
Lead Cyber Security Analyst
Lead Cyber Security Analyst

Insight Global • San Antonio (TX)

Hybrid
USD 100,000 - 115,000