> Markdown version of [/jobs/ext/1459072-it-medical-device-security-risk-assessment-analyst-12-month-contract](https://www.wearedevelopers.com/jobs/ext/1459072-it-medical-device-security-risk-assessment-analyst-12-month-contract). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT/Medical Device Security Risk Assessment Analyst - 12 Month Contract - **Company:** Optimum Healthcare IT, LLC - **Location:** Marshfield, WI, United States - **Experience:** Experienced - **Salary:** $156,000.0 - **Contract:** Temporary contract - **Skills:** Configuration Management Databases, Cyber Security, Data Transmissions, Network Architecture, Network Segmentation, Data Streaming, Systems Integration, EndPointSecurity, Information Technology, Patch Management, Enterprise Integration - **Published:** July 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=647db065796e4eff ## About the Role * 2-5+ years of experience in IT security, cybersecurity risk management, clinical engineering, biomedical technology, or a related field, preferably within a healthcare environment. * Working knowledge of medical device and Internet of Medical Things (IoMT) security, including network segmentation, legacy operating system risks, and vendor patch management. * Experience performing security risk assessments and managing assessment documentation through completion. * Strong organizational and project coordination skills with the ability to manage multiple priorities across several locations. * Experience collaborating with internal IT teams, Clinical Engineering, Biomedical staff, and third-party vendors to gather technical information. * Strong written and verbal communication skills with the ability to present technical information to both technical and non-technical stakeholders., * Experience supporting cybersecurity activities during healthcare mergers, acquisitions, or system integration initiatives. * Familiarity with HIPAA Security Rule requirements and healthcare security compliance practices. * Experience using Governance, Risk, and Compliance (GRC), CMDB, or enterprise asset management platforms to track security assessments and inventories., * biomedical device security: 4 years (Required) * IT security, risk assessment, clinical engineering: 4 years (Required) ## Description The IT & Medical Device Security Risk Management Analyst is responsible for overseeing the security risk assessment process for enterprise IT systems and network-connected medical devices at newly integrated healthcare facilities. This position ensures all required security assessments are completed, documentation is submitted, identified risks are addressed, and outstanding integration-related security activities are resolved in accordance with organizational standards., * Perform security risk assessments for all in-scope IT assets and connected medical devices at newly integrated healthcare sites, ensuring compliance with enterprise integration requirements. * Develop and maintain a comprehensive inventory of IT systems and medical devices, including asset ownership, network location, criticality, data flow, and device classification. * Review existing assessment documentation to identify missing, outdated, or incomplete security evaluations and coordinate completion efforts. * Partner with local IT teams, Clinical Engineering, Biomedical departments, equipment vendors, and manufacturers to collect the technical information required for security assessments, including network architecture, device specifications, operating system details, and patch status. * Manage and monitor all open risk assessment requests through completion, maintaining accurate tracking of submissions, progress, and closure by site and asset category. * Prioritize assessment activities based on overall risk, patient safety considerations, business impact, and project timelines. * Identify significant security concerns such as unsupported operating systems, insufficient network segmentation, or unprotected data transmissions, and provide remediation recommendations to security leadership. * Serve as the primary resource for IT and medical device security assessment questions throughout the acquisition and integration process. * Prepare recurring reports and dashboards outlining assessment progress, outstanding work, backlog status, and completion metrics for security leadership and integration stakeholders. * Recommend process improvements and document best practices to enhance future acquisition-related security assessment workflows. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [From Bedside Beeps to Interoperable Bytes – Getting your medical devices ready to talk the IEEE 11073 language](https://www.wearedevelopers.com/videos/771-from-bedside-beeps-to-interoperable-bytes-getting-your-medical-devices-ready-to-talk-the-ieee-11073-language) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)