Cybersecurity Analyst

Lompoc Valley Medical Center
Lompoc, CA, United States
3 months ago
Apply on healthjobsnationwide.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$81,245.0 - $112,008.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Health Informatics CompTIA Security+ Cyber Security Information Systems Network Architecture Phishing Electronic Medical Records Information Technology Patch Management Vulnerability Analysis

Job description

  • The Cybersecurity Analyst reports to the Director of Information Systems.
  • Responsible for supporting information security operations including vulnerability scanning, security monitoring, incident response support, compliance documentation, and access reviews.
  • Performs assigned security tasks within established procedures and escalates findings to the as appropriate.
  • Works effectively under deadlines and maintains professional, respectful working relationships with patients, families, medical and nursing staff, and co-workers.

District Responsibility:

  • Supports the District mission and values.
  • Demonstrates respect, professionalism and courtesy to all patients, visitors, other providers and co-workers, as delineated in the LVMC “Commitment to Care”.
  • Constantly use C-I-CARE principles when communicating with others.
  • Participates in performance improvement activities.
  • Engages in ongoing professional development.

Position Duties/Responsibility:

  • Perform recurring vulnerability scans across servers, endpoints, and network infrastructure; document findings and escalate for remediation coordination.
  • Track remediation status from security risk assessments and audit findings in the risk register; flag overdue items for follow-up.
  • Support security incident documentation including privacy breaches, unauthorized access, malware detections, and phishing events.
  • Assist with periodic access reviews across clinical and administrative systems including EHR, practice management, and Active Directory; document findings and submit for evaluation.
  • Monitor security tooling for alerts; perform initial triage and escalate per established incident response procedures.
  • Assist with vendor risk documentation including tracking BAA status and supporting security questionnaire completion as directed.
  • Administer and monitor Microsoft 365 tenant security.
  • Participate in disaster response and incident response activations as assigned, including ransomware response team duties.
  • Support HIPAA Security Rule compliance activities including audit control documentation, patch management tracking, and encryption validation as directed.
  • Perform other duties as assigned., + Establishes and maintains effective, positive working relations with departmental employees, hospital staff, medical staff and patients.
  • Assures safe practices and techniques are used in the department, including secure handling of credentials, access controls, and endpoint protection.
  • Communicates policies to hospital employees including security awareness, acceptable use, and incident reporting procedures.
  • LVMC reserves the right to modify the minimum requirements depending on the needs of the organization.

Requirements

  • Education: Associate’s degree in information technology, cybersecurity, or related field, or equivalent combination of education and experience. Bachelor’s degree preferred.
  • Experience: Minimum three years in information technology in a hands-on technical role. Prior exposure to security tools, compliance activities, or security operations preferred. Healthcare IT experience preferred.
  • Certifications: CompTIA Security+ or equivalent required.
  • Skills/Ability:
  • Strong communication skills, both written and verbal, with the ability to convey technical security concepts to non-technical audiences.
  • Knowledge of state and federal regulations including HIPAA Security Rule, HIPAA Privacy Rule, and California health data privacy requirements.
  • Safety requirements including safe handling and protection of sensitive data, PHI, and security findings.
  • Quality improvement principles applied to information security processes and incident reduction.
  • Maintain records in an organized manner, including incident documentation, vulnerability tracking, risk register entries, and compliance evidence that must withstand regulatory scrutiny.
  • Maintain the department’s CMS and California state accreditation requirements related to information security and data protection.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on healthjobsnationwide.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all