> Markdown version of [/jobs/ext/2196289-information-security-risk-analyst](https://www.wearedevelopers.com/jobs/ext/2196289-information-security-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Analyst - **Company:** Avera Queen of Peace - **Location:** Sioux City, IA, United States - **Experience:** Experienced - **Salary:** $70,720.0 - $106,600.0 - **Contract:** Permanent contract - **Skills:** Automation of Tests, Cyber Security, Information Systems, Data Security, Document Management Systems, Disaster Recovery, Information Security Management, Information Technology Audit, Information Systems Security Architecture Professional, Information Technology Security Auditing, IT General Controls (ITGC), Information Technology - **Published:** August 23, 2026 - **Apply:** https://www.careerbuilder.com/job-details/information-security-risk-analyst-sioux-falls-sd--51ed2cc2-e430-4543-adb2-8e3a1af52f53 ## About the Role Essential QualificationsThe individual must be able to work the hours specified. To perform this job successfully, an individual must be able to perform each essential job function satisfactorily including having visual acuity adequate to perform position duties and the ability to communicate effectively with others, hear, understand and distinguish speech and other sounds. These requirements and those listed above are representative of the knowledge, skills, and abilities required to perform the essential job functions. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential job functions, as long as the accommodations do not cause undue hardship to the employer.Preferred Education, License/Certification, or Work Experience: * Bachelor's in related area * Certified Information Systems Auditor (CISA) - ISACA * Certified Information Systems Security Professional (CISSP) - International Information System Security Certification Consortium (ISC2) * 4-6 years Related experience in IT, project management, compliance or security areas Expectations and Standards * Commitment to the daily application of Avera's mission, vision, core values, and social principles to serve patients, their families, and our community. * Promote Avera's values of compassion, hospitality, and stewardship. * Uphold Avera's standards of Communication, Attitude, Responsiveness, and Engagement (CARE) with enthusiasm and sincerity. * Maintain confidentiality. * Work effectively in a team environment, coordinating work flow with other team members and ensuring a productive and efficient environment. * Comply with safety principles, laws, regulations, and standards associated with, but not limited to, CMS, The Joint Commission, DHHS, and OSHA if applicable., Adverse Events, Analysis Skills, Auditing, CISA - Certified Information Systems Auditor, CISSP - Certified Information Systems Security Professional, Communication Skills, Computer Hacking, Computer Security, Design Evaluation, Disaster Recovery, Document Management, Documentation, External Audit, Federal Laws and Regulations, ISACA (Information Systems Audit and Control Association), Information Technology & Information Systems, Information Technology/Systems Audit, Information/Data Security (InfoSec), Internal Audit, International Information Systems Security Certification Consortium (ISC)2, Maintain Compliance, Operational Audit, Process Improvement, Process Management, Production Systems, Project/Program Management, Regulations, Risk, Risk Analysis, Risk Management, Safety Compliance, Security Analysis, Security Attacks, Security Auditing, Security Monitoring, State Laws and Regulations, Team Player, Technology Analysis, Test Automation, Testing ## Description Be part of a multidisciplinary team built with compassion and the goal of Moving Health Forward for you and our patients. Work where you matter. A Brief OverviewAssists in risk identification, development, and evaluation of information technology security controls including risk mitigation strategies as they apply to both IT and business environments. Delivers and supports evaluation of control designs, evaluation of control operation, reporting of control deficiencies, and remediation strategies. Reviews current processes for improvements in control documentation & testing for effectiveness and efficiency. Also collects and monitors information on security alerts, control failures/unmitigated risks and remediation results to build compliance reports for IT and business management. Provides advisory services for IT controls to projects, teams, and audits by ensuring consistent control implementation through documented processes for identifying control requirements prior to their implementation into production IT environments.What you will do * Actively participates in assessing and evaluating the current adequacy of the security strategy along with identifying and reporting on risks and controls in the IT and business environments. * Assists with the planning, design, and coordination of business continuity/disaster recovery plans along with threats to the systems/organization, and calculating the impact of potential adverse events. * Identifies, performs, and evaluates the current testing of controls while maintaining and improving the process for evaluation of IT controls through a combination of automated testing and interviewing. * Identifies, analyzes and initiates changes in Information Security policies, procedures, guidelines and standards as needed to ensure overall compliance with federal, state, and local laws and regulations. * Identifies and reviews current advances in all areas of information technology concerning vulnerabilities, security breaches or malicious attacks and current security risk areas for IT. * Coordinates the planning, design, and implementation of legacy application record retention. This includes working with operational owners in evaluating and documenting the risks associated with proposed alternatives. * Assists with internal technology teams on supporting internal and external IT audits. Assists with and performs internal security and risk assessments as requested by management. Audits and assessments must be continual, as the threat profiles change constantly. * Coordinates implementation of processes and procedures to achieve industry accepted security audit certifications such as SOC. * Assists with simulated emergency exercises as needed for security and business continuity related functions. Assists with Technology Intake Process in reviewing security aspects of vendor supplied products/service. * Collects information on control failures/unmitigated risks, including a clear description of the risk and its likelihood along with remediation results to build compliance reports for IT and business management. ## Related Videos - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [IT Salaries in Austria](https://www.wearedevelopers.com/magazine/286-it-salaries-in-austria)