Security and IT Systems Analyst
Role details
Job location
Tech stack
Job description
The IT Security & Systems Analyst designs, secures, and maintains infrastructure and tools that support Provation's healthcare SaaS platforms. This hybrid role blends IT engineering and systems administration expertise with strong cybersecurity capabilities to ensure systems remain secure, scalable, and compliant across multi-cloud environments. This position will support secure system design, cloud operations, infrastructure automation, identity and access management, and the integration of security practices across IT and engineering operations. This role also contributes to the secure adoption of AI-enabled technologies across the organization. Success requires hands-on technical skills, analytical thinking, problem-solving, and cross functional collaboration with engineering, product, compliance, legal, and operations teams. -on technical skills, analytical thinking, problem-solving, and cross-functional collaboration with engineering, product, compliance, legal, and operations teams., IT Engineering & Systems Administration
- Deploy, administer, and optimize infrastructure across AWS, Azure, and GCP.
- Maintain core IT systems including IAM, access controls, logging, monitoring, and endpoint tools.
- Troubleshoot and resolve complex infrastructure, networking, and performance issues.
- Support environment provisioning, system integrations, and reliability improvements
- Maintain accurate documentation, runbooks, architecture diagrams, and operational procedures.
Cybersecurity, Risk Management and Compliance
- Implement and automate, security controls across systems and workflows.
- Conduct vulnerability assessments, risk evaluations, and participate in incident response.
- Ensure adherence to HIPAA, HITECH, FedRAMP, CMMC, SOC 2, GDPR.
- Contribute to secure architecture design, penetration testing efforts, and audit readiness.
- Use SIEM and monitoring tools to detect, investigate, and remediate threats.
- Support Zero Trust initiatives, identity governance, and privileged access control.
DevSecOps & Security Automation
- Automate security scanning and compliance checks into CI/CD pipelines (GitHub Azure DevOps).
- Develop and maintain Policy-as-Code guardrails.
- Automate provisioning, configuration and security posture enforcement.
- Improve system observability and reliability using monitoring tools.
AI-Enabled IT & Security Innovation
- Support secure evaluation and deployment of AI tools.
- Assist in designing secure workflows for AI-based operations
- Help develop responsible AI adoption plans across the organization.
- Use AI to enhance automation, analytics, and threat detection.
Collaboration & Communication
- Collaborate with engineering, product, compliance, and leadership to align technical and security solutions with business needs.
- Communicate complex technical security concepts to non-technical audiences
- Contribute to planning, technical reviews, and governance processes.
- Participate in Agile/Scrum teams and support iterative delivery., Builds Extraordinary Teams: Actively fosters collaboration by contributing positively, supporting shared goals, helping others succeed, and celebrating team achievements together.
Courageous: Shows strength through action-moves quickly toward goals, embraces uncertainty, speaks up, and perseveres through challenges with confidence and integrity.
Delivers Results: Sets high standards and consistently delivers by focusing priorities and overcoming obstacles, and upholding organizational values.
Adaptable: Applies rigor by working thoroughly and following processes without cutting corners while remaining adaptable.
Lead with FBS: Goes to Gemba-observes real-world processes, not just meetings. Embraces FBS by applying its fundamentals to improve work, engage in kaizen, and continuously grow knowledge and usage.
Requirements
Education & Experience Guidelines
- Bachelor's degree in IT related field, Computer Science, Cybersecurity, or comparable work experience
- 1-3 years of relevant work experience, specifically in IT engineering, systems admin, DevSecOps, or other related fields.
- Hands-on experience with cloud platforms, associated security controls, and underlying IT infrastructure.
- Experience solving complex IT and security challenges in regulated environments.
- Exposure to EHR or healthcare IT systems is beneficial.
- Occasional travel may be required.
Other Preferred Knowledge, Skills, Abilities or Certifications:
Security
- Security+, CISSP, CISM, CCSP, CEH, CySA+, HITRUST Practitioner.
Cloud
- AWS Solutions Architect, Azure Fundamentals (AZ-900), Azure AI Engineer (AI-102).
IT & DevOps Tools
- Docker, Kubernetes, GitHub, Jenkins, security scanning tools (Rapid7, Veracode, etc.).
- Secrets management tools (Vault, AWS Secrets Manager, Azure Key Vault).
Healthcare & Compliance
- CPHIMS, CAHIMS or experience with healthcare security frameworks.
Process & Methodology
- ITIL Foundation, experience in Agile environments.
Fortive 9 Behaviors by Level:
Executing and Contributing
Customer Obsessed: Understands the customer's needs through observation, questioning and going to Gemba.
Strategic: Uses data to make informed decisions while anticipating future trends and aligning actions with organizational goals.
Innovation for Impact: Proactively explores new perspectives and experiments to solve day-to-day problems.