IT Security Analyst II

Capital Health System, Inc.

Lawrenceville (GA)

On-site

USD 108,000 - 141,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical Plan
Dental Plan
Vision Plan
Paid Time Off
FSA

Job summary

Capital Health seeks an IT Security Analyst II to own and manage core information security programs, including TPRM, phishing awareness training and application security assessments. This role guides policy development, metrics reporting and risk remediation across the organization, mentoring junior staff and collaborating with the IT Manager.

The candidate will demonstrate strong ability to translate technical risks into business terms, oversee vendor risk, and drive security improvements while

Qualifications

  • Bachelor's degree in a relevant field or equivalent experience.
  • Three years cybersecurity experience including GRC, vulnerability management or TPRM; knowledge of NIST CSF, HIPAA or similar frameworks; CompTIA Security+ required.

Responsibilities

  • Owns the end-to-end third-party risk management (TPRM) program including risk scoring, intake workflows, assessments and reassessments.
  • Drives vendor risk assessments from outreach to closure and escalates high-risk relations to leadership.
  • Administers phishing simulation program; designs campaigns, schedules, executes and reports trends to leadership.
  • Performs Application Security Assessments and provides risk-based recommendations.
  • Manages software request/review process for security risk prior to approval and onboarding.
  • Supports overall GRC strategy with the IT Manager; contributes to phishing roadmaps and capacity planning.
  • Drafts and maintains information security policies, standards and procedures; reports remediation progress for HIPAA/NIST gaps.
  • Develops security awareness training content for staff and management; stays current with threats and controls.

Skills

Vendor risk management
GRC
NIST CSF
HIPAA
CompTIA Security+
Risk assessment
Stakeholder communication
Security policy drafting

Education

Bachelor's degree

Job description

Capital Health is the region's leader in providing progressive, quality patient care with significant investments in our exceptional physicians, nurses and staff, as well as advanced technology. Capital Health is a dynamic health care resource accredited by the DNV that includes two hospitals, an outpatient center, satellite ED, and an expansive network of primary and specialty care. Capital Health Medical Group is made up of more than 600 physicians and other providers who offer primary and specialty care, as well as hospital-based services, to patients throughout the region. Capital Health recognizes that attracting the best talent is key to our strategy and success as an organization. As a result, we aim for flexibility in structuring competitive compensation offers to ensure we can attract the best candidates.

The listed pay range or pay rate reflects compensation for a full-time equivalent (1.0 FTE) position. Actual compensation may differ depending on assigned hours and position status (e.g., part-time). Pay Range: $108,139.20 - $141,294.40 Scheduled Weekly Hours: 40

Position Overview SUMMARY (Basic Purpose of the Job)

The IT Security Analyst II independently owns and manages core information security programs, including third-party risk management (TPRM), Security Awareness Training, and Application Security Assessments. This role serves as a trusted resource for staff and leaders regarding information security policy implementation, interpretation, and compliance, and drafts and maintains information security policies, standards, and procedures. Building on the foundation of the IT Security Analyst I role, this position operates with greater autonomy, owns end-to-end programs and initiatives, and provides mentorship and guidance to less experienced team members. The position assesses and prioritizes information security and cybersecurity risk across the organization, facilitates compliance with regulatory requirements and information security policies, and develops and reports on information security metrics.

MINIMUM REQUIREMENTS
  • Education: Bachelor's degree in a relevant field or equivalent experience.
  • Experience: Three years demonstrated experience in cybersecurity, GRC, vulnerability management, TPRM, or related roles, including experience gained as an IT Security Analyst I or in an equivalent role required. Working knowledge of NIST CSF, HIPAA, or other security/regulatory frameworks required. CompTIA Security+ required. One or more mid-level certifications such as CompTIA CySA+ or ISACA CRISC preferred (or equivalent). Progress toward or attainment of ISACA CISM, CISA, or ISC2 CISSP is a plus.
  • Knowledge and Skills: Strong working knowledge of desktop, server, storage, virtualization, networking, and security technologies. Demonstrated ability to independently lead risk assessments, vendor risk reviews, and vulnerability remediation efforts, and to translate technical findings into business risk language for non-technical stakeholders.
  • Special Training: A+, Network+, Security+, CySA+, CRISC, or other relevant IT security certifications are a plus.
  • Mental, Behavioral and Emotional Abilities: Ability to work independently with minimal supervision, exercise sound judgment on risk-based decisions, mentor junior staff, and communicate effectively with both technical and non-technical audiences under time-sensitive conditions.
ESSENTIAL FUNCTIONS
  • Owns and manages the third-party risk management (TPRM) program end-to-end, including vendor classification logic, risk scoring methodology, intake routing/workflows, assessment questionnaires, and reassessment tracking; serves as the primary point of contact for vendor risk questions across the organization.
  • Independently drives vendor risk assessments from initial outreach through closure, including follow-up with unresponsive vendors, review of vendor-submitted documentation, and escalation of high-risk or unresolved vendor relationships to leadership.
  • Administers the organization’s enterprise phishing simulation program, including campaign design and scheduling, execution, data collection, results analysis, and reporting of metrics and trends to leadership.
  • Performs Application Security Assessments for new and existing software, evaluating security posture and providing risk-based recommendations to stakeholders.
  • Owns and manages the software request and review process, evaluating new software and vendor tools for security risk prior to approval and onboarding.
  • Provides broader support to overall GRC program strategy and planning, partnering with the IT Manager on initiatives such as multi-campaign phishing simulation roadmaps, TPRM process improvements, and team capacity/workload planning for a small, high-throughput GRC team.
  • Researches, drafts, and maintains information security policies, standards, procedures, and performs detailed policy reviews.
  • Tracks and reports on remediation progress for regulatory and framework-based gap assessments (e.g., HIPAA Security Rule), maintaining a remediation tracker and coordinating with control owners to close identified gaps.
  • Develops and maintains security awareness training content for staff and management audiences, including designing and updating training presentation materials with current statistics and emerging threat topics.
  • Coordinates examinations by qualified security assessors for regulations and frameworks such as HIPAA and NIST, working with control owners and external assessors to ensure evidence requests are completed timely and accurately.
  • Monitors security alerts, analyzes incidents, and contributes to incident response activities in coordination with the Security Operations team and IT Manager.
  • Manages the exception review and approval process, ensuring exceptions are documented, risk-rated, and reviewed on schedule.
  • Applies current threat intelligence and security trends to inform TPRM, awareness training, and policy work.
  • Collaborates closely with the IT Manager and Security Operations team on day-to-day operational challenges and contributes to effective, sustainable solutions as part of a small, high-throughput GRC team.
  • Mentors and provides guidance to IT Security Analyst I team members and other GRC support staff, including knowledge transfer, review of work products, and onboarding support; serves as a go-to resource for procedural and technical questions within the GRC team.
  • Maintains comprehensive documentation of TPRM activities, vendor assessments, security awareness training and phishing simulation activities, and policy review work.
  • Generates and analyzes regular reports on information security metrics (e.g., phishing simulation results, vendor assessment status, remediation tracking) for management review, identifying trends and improvement opportunities.
  • Fosters a culture of security awareness and best practices within the organization.
  • Stays informed of industry best practices, emerging threats, and advancements in cybersecurity, and pursues relevant certifications and training to enhance expertise.
  • Performs other duties as assigned.
PHYSICAL DEMANDS AND WORK ENVIRONMENT

Frequent physical demands include:

  • Standing
  • Walking
  • Climbing (e.g., stairs or ladders)
  • Carry objects
  • Push/Pull
  • Twisting
  • Bending
  • Reaching forward
  • Reaching overhead
  • Squat/kneel/crawl
  • Wrist position deviation
  • Pinching/fine motor activities

Continuous physical demands include:

  • Sitting
  • Keyboard use/repetitive motion

Lifting Floor to Waist 15 lbs. Lifting Waist Level and Above 10 lbs.

Sensory Requirements include:

  • Accurate Near Vision
  • Accurate Far Vision
  • Color Discrimination
  • Minimal Depth Perception
  • Accurate Hearing

Anticipated Occupational Exposure Risks Include the following: N/A

Benefits
  • Medical Plan
  • Prescription drug coverage & In-House Employee Pharmacy
  • Dental Plan
  • Vision Plan
  • Flexible Spending Account (FSA) - Healthcare
  • FSA - Dependent Care
  • FSA Retirement Savings and Investment Plan
  • Basic Group Term Life and Accidental Death & Dismemberment (AD&D) Insurance
  • Supplemental Group Term Life & Accidental Death & Dismemberment Insurance
  • Disability Benefits – Long Term Disability (LTD)
  • Disability Benefits – Short Term Disability (STD)
  • Employee Assistance Program
  • Commuter Transit
  • Commuter Parking
  • Supplemental Life Insurance - Voluntary Life
  • Spouse - Voluntary Life
  • Employee - Voluntary Life Child
  • Voluntary Legal Services
  • Voluntary Accident, Critical Illness and Hospital Indemnity Insurance
  • Voluntary Identity Theft Insurance
  • Voluntary Pet Insurance
  • Paid Time-Off Program

The pay range listed is a good faith determination of potential base compensation that may be offered to a successful applicant for this position at the time of this job advertisement and may be modified in the future. When determining base salary and/or rate, several factors may be considered including, but not limited to location, years of relevant experience, education, credentials, negotiated contracts, budget, market data, and internal equity. Bonus and/or incentive eligibility are determined by role and level. The salary applies specifically to the position being advertised and does not include potential bonuses, incentive compensation, differential pay or other forms of compensation, compensation allowance, or benefits health or welfare. Actual total compensation may vary based on factors such as experience, skills, qualifications, and other relevant criteria.

Welcome to Capital Health's new career opportunity page. Here you will have access to view and apply to career opportunities in our hospital and physician practice locations.

Equal Opportunity Employer Notice Capital Health Benefits

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Analyst II
IT Security Analyst II

Capital Health Screening Centre • Lawrenceville (NJ)

On-site
USD 108,000 - 141,000
Medical Plan
Dental Plan
Vision Plan
+1
IT Security Analyst II
IT Security Analyst II

Capital Health • Lawrenceville (GA), Northern (KY)

Hybrid
USD 108,000 - 141,000
Medical Plan
Dental Plan
Vision Plan
+2
IT Field Analyst I (100% On-Site)
IT Field Analyst I (100% On-Site)

Capital Health Screening Centre • Rockford (IL)

On-site
USD 2,400 - 65,000
Medical Plan
Dental Plan
Vision Plan
+9
IT Field Analyst I
IT Field Analyst I

Capital Health (US) • Trenton (NJ)

On-site
USD 32,442 - 42,154
Medical Plan
Dental Plan
Vision Plan
+2
IT Team Lead ERP
IT Team Lead ERP

Capital Health Screening Centre • Pennington (NJ)

On-site
USD 97,000 - 129,000
Medical Plan
Prescription drug coverage
Dental Plan
+8
IT Team Lead ERP
IT Team Lead ERP

Capital Health (US) • Pennington (NJ)

On-site
USD 97,947 - 127,982
IT Field Analyst I
IT Field Analyst I

Capital Health • United States

On-site
USD 3,246,000 - 4,215,000
Medical Plan
Prescription drug coverage
Dental Plan
+2
IT Product Engineer I
IT Product Engineer I

Capital Health (US) • Pennington (NJ)

On-site
USD 79,000 - 103,000
Medical Plan
Dental Plan
Vision Plan
+1
IT PMO And Innovations
IT PMO And Innovations

Capital Health (US) • Pennington (NJ)

On-site
USD 98,000 - 128,000
Medical Plan
Dental Plan
Vision Plan
+2
IT PMO And Innovations
IT PMO And Innovations

Capital Health Screening Centre • Pennington (NJ)

On-site
USD 98,000 - 128,000
Medical Plan
Dental Plan
Vision Plan
+2