Information Security Risk Analyst

Avera Health

Sioux Falls (SD)

On-site

USD 71,000 - 107,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

PTO from day 1
Employer 5% retirement match
Career development & mentorship

Job summary

Avera Health is seeking a security-focused professional to assess IT risk, design controls, and support audits in a dynamic healthcare environment. You will evaluate control design, monitor deficiencies, and help implement remediation strategies across IT and business units.

The role emphasizes working with cross-functional teams to ensure compliance with federal and state regulations, while contributing to business continuity and incident response planning.

Qualifications

  • Bachelor's degree in a related field is required.
  • CISA certification is preferred.
  • CISSP certification is preferred.
  • 4–6 years of experience in IT, project management, compliance or security.

Responsibilities

  • Assess and evaluate the adequacy of the security strategy and identify risks.
  • Plan, design, and coordinate business continuity/disaster recovery plans.
  • Test and review IT controls and document remediation results.
  • Review security policies and ensure compliance with laws and regulations.
  • Support internal/external IT audits and risk assessments.

Skills

Risk assessment
IT security controls
Security auditing

Education

Bachelor's in related area

Job description

Location: Avera Downtown Building-Sioux Falls Worker Type: Regular Work Shift: Day Shift (United States of America) Pay Range: The pay range for this position is listed below. Actual pay rate dependent upon experience.

$70,720.00 - $106,600.00

Position Highlights

You Belong at Avera Be part of a multidisciplinary team built with compassion and the goal of Moving Health Forward for you and our patients. Work where you matter.

A Brief Overview

Assists in risk identification, development, and evaluation of information technology security controls including risk mitigation strategies as they apply to both IT and business environments. Delivers and supports evaluation of control designs, evaluation of control operation, reporting of control deficiencies, and remediation strategies. Reviews current processes for improvements in control documentation & testing for effectiveness and efficiency. Also collects and monitors information on security alerts, control failures/unmitigated risks and remediation results to build compliance reports for IT and business management. Provides advisory services for IT controls to projects, teams, and audits by ensuring consistent control implementation through documented processes for identifying control requirements prior to their implementation into production IT environments.

What you will do
  • Actively participates in assessing and evaluating the current adequacy of the security strategy along with identifying and reporting on risks and controls in the IT and business environments.
  • Assists with the planning, design, and coordination of business continuity/disaster recovery plans along with threats to the systems/organization, and calculating the impact of potential adverse events.
  • Identifies, performs, and evaluates the current testing of controls while maintaining and improving the process for evaluation of IT controls through a combination of automated testing and interviewing.
  • Identifies, analyzes and initiates changes in Information Security policies, procedures, guidelines and standards as needed to ensure overall compliance with federal, state, and local laws and regulations.
  • Identifies and reviews current advances in all areas of information technology concerning vulnerabilities, security breaches or malicious attacks and current security risk areas for IT.
  • Coordinates the planning, design, and implementation of legacy application record retention. This includes working with operational owners in evaluating and documenting the risks associated with proposed alternatives.
  • Assists with internal technology teams on supporting internal and external IT audits.
  • Assists with and performs internal security and risk assessments as requested by management. Audits and assessments must be continual, as the threat profiles change constantly.
  • Coordinates implementation of processes and procedures to achieve industry accepted security audit certifications such as SOC.
  • Assists with simulated emergency exercises as needed for security and business continuity related functions.
  • Assists with Technology Intake Process in reviewing security aspects of vendor supplied products/service.
  • Collects information on control failures/unmitigated risks, including a clear description of the risk and its likelihood along with remediation results to build compliance reports for IT and business management.
Essential Qualifications

The individual must be able to work the hours specified. To perform this job successfully, an individual must be able to perform each essential job function satisfactorily including having visual acuity adequate to perform position duties and the ability to communicate effectively with others, hear, understand and distinguish speech and other sounds. These requirements and those listed above are representative of the knowledge, skills, and abilities required to perform the essential job functions. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential job functions, as long as the accommodations do not cause undue hardship to the employer.

Preferred Education, License/Certification, or Work Experience
  • Bachelor's in related area
  • Certified Information Systems Auditor (CISA) - ISACA
  • Certified Information Systems Security Professional (CISSP) - International Information System Security Certification Consortium (ISC2)
  • 4-6 years Related experience in IT, project management, compliance or security areas
Expectations and Standards

Commitment to the daily application of Avera’s mission, vision, core values, and social principles to serve patients, their families, and our community. Promote Avera’s values of compassion, hospitality, and stewardship. Uphold Avera’s standards of Communication, Attitude, Responsiveness, and Engagement (CARE) with enthusiasm and sincerity. Maintain confidentiality. Work effectively in a team environment, coordinating work flow with other team members and ensuring a productive and efficient environment. Comply with safety principles, laws, regulations, and standards associated with, but not limited to, CMS, The Joint Commission, DHHS, and OSHA if applicable.

Benefits

You Need & Then Some Avera is proud to offer a wide range of benefits to qualifying part-time and full-time employees. We support you with opportunities to help live balanced, healthy lives. Benefits are designed to meet needs of today and into the future.

  • PTO available day 1 for eligible hires.
  • Up to 5% employer matching contribution for retirement
  • Career development guided by hands-on training and mentorship

Avera is an Equal Opportunity Employer - Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, Veteran Status, or other categories protected by law.

If you are an individual with a disability and would like to request an accommodation for help with your online application, please call 1-605-504-4444 or send an email to talent@avera.org.

At Avera, the way you are treated as an employee translates into the compassionate care you deliver to patients and team members. Because we consider health care a ministry, you can live out your faith, uphold the dignity and respect of all persons while not compromising high-quality services. Join us in making a positive impact on moving health forward.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Risk Analyst
Information Security Risk Analyst

Sioux Center Health • Sioux Falls (SD)

On-site
USD 71,000 - 107,000
Information Security Risk Analyst
Information Security Risk Analyst

Avera • Sioux Falls (SD)

On-site
USD 71,000 - 107,000
PTO from day 1
Retirement matching up to 5%
Career development & mentorship
+1
Informatics Analyst
Informatics Analyst

Avera Health • Sioux Falls (SD)

On-site
USD 64,000 - 96,000
PTO day one
Retirement match (up to 5%)
Mentorship program
Security Officer
Security Officer

Avera McKennan • Steelton (OH)

On-site
USD 28,000 - 36,000
PTO from day 1
Retirement matching up to 5%
Career development & mentorship
+2
Security Officer | Nights
Security Officer | Nights

Sioux Center Health • Sioux Falls (SD)

On-site
USD 29,000 - 34,000
PTO day 1 for eligible hires
Employer matching retirement up to 5%
Career development & mentorship
IT Service Desk Analyst
IT Service Desk Analyst

Avera Health • Sioux Falls (SD)

On-site
USD 29,000 - 43,000
PTO available day 1 for eligible hires
Up to 5% employer matching retirement
Facilities coordinator
Facilities coordinator

Avera Marshall • United States

On-site
USD 60,174,000 - 100,289,000
PTO available day 1 for eligible hires
Up to 5% employer matching retirement
Career development through hands-on培训
Registered Nurse (RN) | Pre-Post Operative
Registered Nurse (RN) | Pre-Post Operative

Avera McKennan • Sioux Falls (SD)

On-site
USD 58,000 - 96,000
PTO day 1
Retirement matching up to 5%
Career development & mentorship
Patient Care Assistant
Patient Care Assistant

Avera St. Mary's • Pierre (SD)

On-site
USD 25,000 - 32,000
You Need & Then Some
PTO day 1 for eligible hires
5% employer matching retirement
+1
Clinic Manager | Gastroenterology
Clinic Manager | Gastroenterology

Avera • Sioux Falls (SD)

On-site
USD 60,000 - 90,000
PTO available day 1 for eligible hires
Up to 5% employer matching retirement
Career development & mentorship