Associate Epic IT Security Specialist
Role details
Job location
Tech stack
Job description
Understands and applies technology tools, systems, policies, and processes to protect data assets, PHI, and PII. Ensures compliance with the Sarbanes-Oxley Act (SOX). Develops and implements strategies to safeguard sensitive information. Monitors and audits user access to ensure compliance, data protection, and enforcement of separation of duties. Identifies and mitigates security risks related to data assets, PHI, and PII. Collaborates with internal and external stakeholders to maintain security standards. Provides staff training on security policies, access procedures, and best practices. Conducts regular reviews and updates of security protocols. Responds to security incidents and breaches promptly and effectively. Maintains documentation of security measures and compliance efforts. Utilizes encryption and other security technologies to protect data. Ensures access controls are properly implemented and maintained. Participates in a 24/7 rotating on-call schedule for support coverage. Other duties as assigned.
Requirements
-
Epic proficiency with honors, certification, accreditation or ability to complete certification within 3 months of completing classes. [Required]
-
Knowledge of methods of access control to applications/systems, including role-based, rule-based, attribute-based, and management of exceptions. [Required]
-
Supported multiple security platforms using various user interfaces. [Required]
-
Basic knowledge of HIPAA, HITECH, PCI and SOX regulations as it pertains to application access controls [Required]
-
Basic knowledge of security frameworks including HITRUST. [Required]
-
Aptitude to quickly learn new systems with little or no documentation. [Required]
-
Strong interpersonal skills with a positive and enthusiastic "can do" attitude. [Required]
-
Demonstrates creative problem-solving approach and strong analytical skills. [Required]
-
Comfortable working independently with general direction and in a team setting. [Required]
-
Excellent change management, oral and written communication, time management and project management skills. [Required]
-
Create, maintain and communicate organized documentation. [Required]
-
Applies best practice techniques in troubleshooting, testing, and quality assurance. [Required]
-
Ability to travel occasionally as needed to support project implementation and assist with assessment of local workflow processes as needed. [Required]
-
In order to support and maintain the technology systems and services in our hospitals, must have the ability to receive calls and text messages 24 hours a day, seven days per week. [Required]
-
Application security training and experience in EPIC, Cerner, Active Directory, Identity Management, another major EHR system, or other major system architecture. [Preferred]
-
Knowledge of security requirements specific to Healthcare including HIPAA, HITECH, and SOX. [Preferred]
-
Knowledge of security frameworks including HITRUST, ISO, and NIST. [Preferred]
-
Knowledge of Microsoft suite of products. [Preferred]
-
Working knowledge of healthcare or clinical physician clinical practice. [Preferred]
-
Ability to work well with people of varying levels of technical abilities. [Preferred]
-
Fundamental knowledge of SQL queries. [Preferred]
Education
-
Bachelor's degree from an accredited institution in Information Technology, Information Security, Health Informatics, Computer Science, or a related field.
-
Equivalent combination of accredited coursework and progressive experience may be considered in place of a degree.
Experience (related field)
-
Minimum 3 years of hands-on experience in healthcare IT, identity and access management, or application security, with direct work in an Epic environment strongly preferred.
-
Demonstrated experience administering role-based access, security classes, sub-templates, and user provisioning at enterprise scale.
-
Experience supporting security operations in an environment subject to HIPAA and audit requirements.
Certification
-
Active Epic security certification (Security & Classroom, or the module-specific certification aligned to this role) is required within 3 months of hire. Sponsorship and training time are provided; failure to certify within the window is grounds for review of continued employment.
-
Existing Epic certification at time of application is preferred and may offset the experience requirement.
Technical and functional skills
-
Working knowledge of RBAC principles, least-privilege design, and segregation-of-duties enforcement.
-
Familiarity with audit tooling, access recertification, and break-the-glass workflows.
-
Ability to translate operational and clinical access needs into secure, maintainable Epic security build.
Preferred
-
Prior experience in a large multi-facility health system (10k+ Epic users).
-
Security certifications such as Security+, CISSP, or CISM.
Benefits & conditions
$60,151.66 - $111,886.39
Background Screening Requirement (Florida Law)
Certain positions are subject to Florida Level 2 background screening , including fingerprinting, as required by state law.