Information Security Analyst I

Sonora Quest Laboratories/ Laboratory Sciences of Arizona

Phoenix (AZ)

On-site

USD 90,000 - 130,000

Full time

7 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sonora Quest Laboratories / Laboratory Sciences of Arizona is seeking an Information Security specialist responsible for implementing security policies across the organization's information systems. The role includes auditing user access, monitoring security logs, and supporting incident response within the SOC framework.

Responsibilities include developing security processes, maintaining documentation, and ensuring compliance with applicable regulations while collaborating with IT teams across

Qualifications

  • Associates degree in Information Security or related field; equivalent experience accepted.
  • At least 1 year of IT, information security, compliance, or risk management experience.
  • Certification within 1 year: CISSP, SSCP, HCISSP, PCI-ISA, CompTIA Security+ or similar.
  • Understanding of healthcare information security regulations.

Responsibilities

  • Conduct security reviews, risk assessments, and implement recommendations.
  • Standardize security across the infrastructure and maintain compliant applications.
  • Develop and update security policies and procedures.
  • Lead security projects including scope, budgeting, and planning.
  • Ensure compliance with federal/state/local information security laws.
  • Audit user access, endpoint security, and monitor logs and network activity.
  • Respond to incidents, support threat hunting, and assist in investigations.
  • Monitor SOC communications and IT controls.

Skills

Security concepts
SOC operations
Incident response
Auditing & compliance
Communication skills
Problem solving
Documentation

Education

Associates degree in Information Security or related field
One year of IT/Security experience
Security certifications within 1 year (CISSP/SSCP/HCISSP/etc.)

Tools

Palo Alto
SIEM
Endpoint security
DLP
Encryption

Job description

Position Summary

This position is responsible for implementation of information security policies, standards, and procedures on all organizational information systems. This position is also responsible for auditing user access, security logs and user permissions. Duties include developing security processes, participating in security investigations, and maintaining documentation. This position supports and maintains the information security infrastructure, including both applications and networking components. This position performs ticket focused tactical incident support, monitors Security Operation Center (SOC) communications and audits Information Technology (IT) controls.

Primary City/State

Phoenix, Arizona

Department Name

IT Threat & Vulnerability Mgmt

Work Shift

Day

Job Category

Information Technology

Position Summary

This position is responsible for implementation of information security policies, standards, and procedures on all organizational information systems. This position is also responsible for auditing user access, security logs and user permissions. Duties include developing security processes, participating in security investigations, and maintaining documentation. This position supports and maintains the information security infrastructure, including both applications and networking components. This position performs ticket focused tactical incident support, monitors Security Operation Center (SOC) communications and audits Information Technology (IT) controls.

Performs all functions according to established policies, procedures, regulatory and accreditation requirements, as well as applicable professional standards.

Core Functions
  • Conducts and participates in security reviews, evaluations, and risk assessments, assisting in the development and implementation of appropriate recommendations. Participates in the handling of security incidents, recoveries, breaches, intrusions, and system abuses.
  • Analyzes the company's information security architecture, including hardware and software components, with the objective of standardizing security throughout company’s infrastructure. Maintains Information Security controlled applications/systems, updating and monitoring for compliance.
  • Evaluates and assists in the development of security policies and procedures. Evaluates security risk assessments of new systems and upgrades to determine impact to Information Security/Risk Management and the enterprise.
  • Provides technical expertise and support for security software, including operational aspects of the software. Participates in, and on occasion, leads information security projects, including the development of project scope requirements, budgeting, and project planning.
  • Provides guidance, direction, and oversight for compliance with all federal, state, and local mandated information security laws, rules, and guidelines. Remain current with the latest industry technical information.
  • Performs audits of users’ system access and work areas. Performs audits of endpoint security controls. Mitigates any issues with systems that are not in compliance. Monitors anti-virus/malware systems, DLP, encryption, network logs, and users’ Internet access.
  • Participates in problem resolution and incident support. Investigates security incidents that may negatively impact the company (including hacking attempts, intrusions, virus infections, mishandling of information, and other security threats); provide support during large incidents and investigations; participate in threat hunting activities.
  • Monitors Service Operations Center (SOC) communications from Information Security applications.
Knowledge, Skills And Abilities
  • Receptive to learning and mentoring
  • Actively completes routine tasks of moderate complexity and small scope
  • Demonstrates competency in appropriate range of technical skills
  • Understands incident management, root cause analysis and change control process
  • Refers to and applies appropriate documentation and Knowledge Bases
  • Strong verbal/written communication skills
  • Excellent interpersonal skills
  • Troubleshooting and complex problem-solving ability
  • Good judgement and decision-making ability
  • Effective time management skills
  • Project management and organizational skills
Minimum Qualifications
  • Associates degree in Information Security, Computer Information Systems, or another relevant field, or have equivalent education and experience.
  • One (1) year of relevant experience of any combination of IT, Information Security, Compliance, or Risk Management experience.
  • Certification in one of the following areas within in one year of entering the position: Certified Information Systems Security Professional (CISSP), Systems Security Certified Practitioner (SSCP), HealthCare Information Security & Privacy Practitioner (HCISSP), Payment Card Industry - Internal Security Assessor (PCI-ISA), CompTIA Security+, HIPAA Security, Information Security Technology Fundamentals, Internet Security or ITAA Information Security Awareness.
  • Must demonstrate general knowledge of information technology and healthcare.
  • Needs experience in small scale project planning and reporting either individually or in a team.
  • Requires communication and presentation skills to engage technical and non-technical audiences.
  • Requires ability to communicate and interact across facilities and at various levels. As is typical in this industry, variable shifts and hours and carrying/responding to cell phone may be required.
Preferred Qualifications
  • Palo Alto and endpoint product experience
  • Firewalls, Network-based Intrusion Prevention System (NIPS), and web filter experience
  • Vulnerability scanning and patch management experience
  • Security Information and Event Management (SIEM) experience
  • Windows & Linux experience
  • HIPAA, PCI-DSS, or previous healthcare experience
  • Security+, GIAC Security Essentials (GSEC), Associate of (ISC)2, CompTIA A+ and/or Network+ certification and training
  • Additional related education and/or experience.
EEO Statement

EEO/Disabled/Veterans

Our organization supports a drug-free work environment.

Privacy Policy
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst I
Information Security Analyst I

Banner Health • Phoenix (AZ), Northern (KY)

Hybrid
USD 65,000 - 90,000
Senior IT Security Analyst
Senior IT Security Analyst

TridentCare • United States

On-site
USD 110,000 - 150,000
IT Security Engineer, Level III
IT Security Engineer, Level III

SherlockTalent • Fort Lauderdale (FL)

Hybrid
USD 90,000 - 120,000
Senior Information Security Analyst
Senior Information Security Analyst

The University of Arizona Foundation • Tucson (AZ)

On-site
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
IT Security Engineer II
IT Security Engineer II

MedImpact Healthcare Systems Inc. • San Diego (CA)

On-site
USD 110,982 - 199,769
Medical, Dental, Vision, and Wellness
401K with Company match
PTO and Holidays
+4
IT Security Analyst IV
IT Security Analyst IV

Jobtailor • United States

On-site
USD 110,000 - 150,000
Information Security Analyst I
Information Security Analyst I

Laboratory Sciences of Arizona • United States

On-site
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Gifthealth Inc • Columbus (OH)

On-site
USD 70,000 - 100,000
Information Security Analyst, FT, Days
Information Security Analyst, FT, Days

Prisma Health • Greenville (SC)

On-site
USD 90,000 - 130,000