Information Security Analyst I

Sonora Quest Laboratories / Laboratory Sciences of Arizona

Yakima (WA)

On-site

USD 90,000 - 120,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Sonora Quest Laboratories / Laboratory Sciences of Arizona is seeking an information security professional to implement policies and maintain secure systems across the organization. The role performs access audits, monitors security controls, and supports SOC operations and incident response.

Responsibilities include risk assessments, policy development, and ensuring compliance with healthcare regulations. The ideal candidate will work across facilities with strong communication and project

Qualifications

  • Associates degree in Information Security or related field.
  • 1 year of IT/InfoSec/Compliance/Risk Management experience.
  • Within 1 year, certification such as CISSP, SSCP, HCISSP, PCI-ISA, Security+ or similar.
  • General knowledge of IT and healthcare.
  • Experience in small-scale project planning and reporting.
  • Strong communication and presentation skills.
  • Ability to engage across facilities and levels; variable shifts may apply.

Responsibilities

  • Conduct security reviews, risk assessments and implement recommendations.
  • Monitor SOC communications and audit IT controls.
  • Develop and maintain security policies and procedures.
  • Provide guidance to ensure compliance with laws and guidelines.
  • Audit user access, endpoint controls and logs; investigate incidents.
  • Lead or contribute to security projects including scope, budgeting and planning.
  • Support incident response, threat hunting and cross-facility coordination.

Skills

Incident management
Root cause analysis
Change control
Network security
SIEM
Documentation
Communication skills
Project management
Healthcare knowledge
Vulnerability management
HIPAA/compliance

Education

Associate degree in Information Security
Security/IT certification within 1 year

Tools

Palo Alto
NIPS
SIEM
Firewalls
Patch management
Windows
Linux

Job description

Position Summary

This position is responsible for implementation of information security policies, standards, and procedures on all organizational information systems. This position is also responsible for auditing user access, security logs and user permissions. Duties include developing security processes, participating in security investigations, and maintaining documentation. This position supports and maintains the information security infrastructure, including both applications and networking components. This position performs ticket focused tactical incident support, monitors Security Operation Center (SOC) communications and audits Information Technology (IT) controls.

Performs all functions according to established policies, procedures, regulatory and accreditation requirements, as well as applicable professional standards.

Core Functions
  1. Conducts and participates in security reviews, evaluations, and risk assessments, assisting in the development and implementation of appropriate recommendations. Participates in the handling of security incidents, recoveries, breaches, intrusions, and system abuses.
  2. Analyzes the company’s information security architecture, including hardware and software components, with the objective of standardizing security throughout company’s infrastructure. Maintains Information Security controlled applications/systems, updating and monitoring for compliance.
  3. Evaluates and assists in the development of security policies and procedures. Evaluates security risk assessments of new systems and upgrades to determine impact to Information Security/Risk Management and the enterprise.
  4. Provides technical expertise and support for security software, including operational aspects of the software. Participates in, and on occasion, leads information security projects, including the development of project scope requirements, budgeting, and project planning.
  5. Provides guidance, direction, and oversight for compliance with all federal, state, and local mandated information security laws, rules, and guidelines. Remain current with the latest industry technical information.
  6. Performs audits of users’ system access and work areas. Performs audits of endpoint security controls. Mitigates any issues with systems that are not in compliance. Monitors anti-virus/malware systems, DLP, encryption, network logs, and users’ Internet access.
    1. Participates in problem resolution and incident support. Investigates security incidents that may negatively impact the company (including hacking attempts, intrusions, virus infections, mishandling of information, and other security threats); provide support during large incidents and investigations; participate in threat hunting activities.
    2. Monitors Service Operations Center (SOC) communications from Information Security applications.
Knowledge, Skills and Abilities
  • Receptive to learning and mentoring
  • Actively completes routine tasks of moderate complexity and small scope
  • Demonstrates competency in appropriate range of technical skills
  • Understands incident management, root cause analysis and change control process
  • Refers to and applies appropriate documentation and Knowledge Bases
  • Strong verbal/written communication skills
  • Excellent interpersonal skills
  • Troubleshooting and complex problem-solving ability
  • Good judgement and decision-making ability
  • Effective time management skills
  • Project management and organizational skills
Minimum Qualifications
  • Associates degree in Information Security, Computer Information Systems, or another relevant field, or have equivalent education and experience.
  • One (1) year of relevant experience of any combination of IT, Information Security, Compliance, or Risk Management experience.
  • Certification in one of the following areas within in one year of entering the position: Certified Information Systems Security Professional (CISSP), Systems Security Certified Practitioner (SSCP), HealthCare Information Security & Privacy Practitioner (HCISSP), Payment Card Industry - Internal Security Assessor (PCI-ISA), CompTIA Security+, HIPAA Security, Information Security Technology Fundamentals, Internet Security or ITAA Information Security Awareness.
  • Must demonstrate general knowledge of information technology and healthcare.
  • Needs experience in small scale project planning and reporting either individually or in a team.
  • Requires communication and presentation skills to engage technical and non-technical audiences.
  • Requires ability to communicate and interact across facilities and at various levels. As is typical in this industry, variable shifts and hours and carrying/responding to cell phone may be required.
Preferred Qualifications
  • Palo Alto and endpoint product experience
  • Firewalls, Network-based Intrusion Prevention System (NIPS), and web filter experience
  • Vulnerability scanning and patch management experience
  • Security Information and Event Management (SIEM) experience
  • Windows & Linux experience
  • HIPAA, PCI-DSS, or previous healthcare experience
  • Security+, GIAC Security Essentials (GSEC), Associate of (ISC)2, CompTIA A+ and/or Network+ certification and training
  • Additional related education and/or experience.
EEO Statement

Our organization supports a drug-free work environment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Analyst I
Information Security Analyst I

Sonora Quest Laboratories/ Laboratory Sciences of Arizona • Phoenix (AZ)

On-site
USD 90,000 - 130,000
Information Security Analyst I
Information Security Analyst I

Banner Health • Phoenix (AZ), Northern (KY)

Hybrid
USD 65,000 - 90,000
Information Security Analyst
Information Security Analyst

New Mexico Water Service Company • San Jose (NM)

On-site
USD 110,000 - 140,000
IT Security Engineer, Level III
IT Security Engineer, Level III

SherlockTalent • Fort Lauderdale (FL)

Hybrid
USD 90,000 - 120,000
Senior IT Security Analyst
Senior IT Security Analyst

TridentCare • United States

On-site
USD 110,000 - 150,000
Sr Information Security Analyst
Sr Information Security Analyst

NKC Health • North Kansas City (MO)

On-site
USD 80,000 - 110,000
Sr Information Security Analyst
Sr Information Security Analyst

NKC Health • Kansas City (MO)

On-site
USD 95,000 - 120,000
Senior Information Security Analyst
Senior Information Security Analyst

Marotta Controls • Parsippany-Troy Hills (NJ)

On-site
USD 120,000 - 160,000
Information Security Engineer
Information Security Engineer

International Executive Service Corps • Lenexa (KS), Northern (KY)

Hybrid
USD 95,000 - 180,000
Medical, Dental, Vision
Life/AD&D
Supplemental Life/AD&D
+6
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth Corporate Support Center • Louisville (KY)

On-site
USD 180,000 - 240,000