IT/Medical Device Security Risk Assessment Analyst - 12 Month Contract

Optimum Healthcare IT, LLC
Marshfield, WI, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$156,000.0
Working hours
Regular working hours
Job source

Tech stack

Configuration Management Databases Cyber Security Data Transmissions Network Architecture Network Segmentation Data Streaming Systems Integration EndPointSecurity Information Technology Patch Management Enterprise Integration

Job description

The IT & Medical Device Security Risk Management Analyst is responsible for overseeing the security risk assessment process for enterprise IT systems and network-connected medical devices at newly integrated healthcare facilities. This position ensures all required security assessments are completed, documentation is submitted, identified risks are addressed, and outstanding integration-related security activities are resolved in accordance with organizational standards., * Perform security risk assessments for all in-scope IT assets and connected medical devices at newly integrated healthcare sites, ensuring compliance with enterprise integration requirements.

  • Develop and maintain a comprehensive inventory of IT systems and medical devices, including asset ownership, network location, criticality, data flow, and device classification.
  • Review existing assessment documentation to identify missing, outdated, or incomplete security evaluations and coordinate completion efforts.
  • Partner with local IT teams, Clinical Engineering, Biomedical departments, equipment vendors, and manufacturers to collect the technical information required for security assessments, including network architecture, device specifications, operating system details, and patch status.
  • Manage and monitor all open risk assessment requests through completion, maintaining accurate tracking of submissions, progress, and closure by site and asset category.
  • Prioritize assessment activities based on overall risk, patient safety considerations, business impact, and project timelines.
  • Identify significant security concerns such as unsupported operating systems, insufficient network segmentation, or unprotected data transmissions, and provide remediation recommendations to security leadership.
  • Serve as the primary resource for IT and medical device security assessment questions throughout the acquisition and integration process.
  • Prepare recurring reports and dashboards outlining assessment progress, outstanding work, backlog status, and completion metrics for security leadership and integration stakeholders.
  • Recommend process improvements and document best practices to enhance future acquisition-related security assessment workflows.

Requirements

  • 2-5+ years of experience in IT security, cybersecurity risk management, clinical engineering, biomedical technology, or a related field, preferably within a healthcare environment.
  • Working knowledge of medical device and Internet of Medical Things (IoMT) security, including network segmentation, legacy operating system risks, and vendor patch management.
  • Experience performing security risk assessments and managing assessment documentation through completion.
  • Strong organizational and project coordination skills with the ability to manage multiple priorities across several locations.
  • Experience collaborating with internal IT teams, Clinical Engineering, Biomedical staff, and third-party vendors to gather technical information.
  • Strong written and verbal communication skills with the ability to present technical information to both technical and non-technical stakeholders., * Experience supporting cybersecurity activities during healthcare mergers, acquisitions, or system integration initiatives.
  • Familiarity with HIPAA Security Rule requirements and healthcare security compliance practices.
  • Experience using Governance, Risk, and Compliance (GRC), CMDB, or enterprise asset management platforms to track security assessments and inventories., * biomedical device security: 4 years (Required)
  • IT security, risk assessment, clinical engineering: 4 years (Required)

Benefits & conditions

4.14.1 out of 5 stars Marshfield, WI 54404 Hybrid work $75 an hour - Contract, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance, * 401(k)
  • Dental insurance
  • Health insurance
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:50 min

Lowering pipeline latency with data streaming

Nathaniel Okenwa Nathaniel Okenwa · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:10 min

Navigating medical device certification and clinical trials

Alexandre Guenoun Alexandre Guenoun +3 · World Congress 2026 Europe

2:13 min

Modernizing legacy applications for real-time streaming data consumption

Farooq Sheikh Farooq Sheikh +3 · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

Videos

See all

Related articles

See all