Information Security Analyst I
Role details
Job location
Tech stack
Job description
The Information Security Analyst I participates in the identification, implementation, maintenance, and support of technologies designed to protect the confidentiality, integrity or availability of UHS and affiliates' information systems. Works with technical and non-technical staff to insure that deployed technologies are effectively and efficiently providing the intended controls consistent with established policies and procedures. Where appropriate, trains and supports technical staff in UHS affiliated locations to deploy, manage and support selected technologies. May oversee the technical aspects of tasks assigned to less experienced staff or contractors on projects, systems or applications assigned., * Assists with the design and architecture of Cloud and Artificial Intelligence information security technologies within guidelines of policies, accepted best practices, and in keeping with good project management principles.
- Assists with the security of applications and AI at UHS. This include application threat modeling, red teaming, and adversarial testing.
- Periodically reviews deployed security technologies to ensure that the solutions continue to provide the intended protections efficiently and effectively. Provides input to UHS Security Standards and Policies.
- Identifies gaps in protection and recommends solutions to remediate or mitigate the risks associated with the protection gaps.
- Document findings and assist in creating reports and metrics for technical and non-technical audiences.
- Stays current on the latest cloud and AI security trends.
- Works with staff at all levels in the organization, vendors and contractors to ensure protections are effective, efficient and non-disruptive to the appropriate duties, rights and mission of the individuals and the organization(s).
- Monitors the resolution of maintenance or enhancement issues assigned by the UHS Customer Support Center.
Requirements
- Bachelor's degree in Information Systems Security and Risk Management, Computer Science, or related field required.
- Minimum of 1-3 years' experience with desktop, server and/or network security administration in a mixed computing environment.
- Experience managing and supporting some or all of the following or similar information security technologies or processes:
- Anti-malware protections and analysis
- Web filtering and security
- Vulnerability scanning and management
- Encryption technologies for data at rest and data in transit
- Mobile device and removable media protection or management systems
- Authentication - including various forms of SSO and MFA
- Cloud application security
- Security Information and Event Management (SIEM) systems
- Interpreting Common Vulnerabilities and Exposures (CVE ) data
- Device control
- Data Loss Prevention (DLP)
- Forensic analysis
- Familiarity with risk assessment and risk management concepts or processes.
- Working knowledge of various regulatory security requirements - particularly Sarbanes-Oxley (SOX), HIPAA, and HITECH.
- Working knowledge of common cyber security frameworks such as HITRUST, NIST, CSC20, or others.
- Working knowledge of scripting languages such as Python, PowerShell, and VB is a plus.
- Ability to prioritize multiple tasks and be detail oriented.
- An information security certification is a plus -- to demonstrate proficiency and knowledge of information security best practices and concepts.
- Excellent communication, interpersonal and project management skills
***Significant relevant experience (4 years) in addition to an Associate's Degree may be considered in lieu of the educational requirement. ***
Travel Requirements: Up to 5% - 10% US - to field locations may be necessary to complete assigned projects
Benefits & conditions
paid time off, 401(k), * Challenging and rewarding work environment
- Growth and development opportunities within UHS and its subsidiaries
- Competitive Compensation
- Excellent Medical, Dental, Vision and Prescription Drug Plan
- 401k plan with company match
- Generous Paid Time Off
*UHS is a registered trademark of UHS of Delaware, Inc., the management company for Universal Health Services, Inc. and a wholly-owned subsidiary of Universal Health Services, Inc. Universal Health Services, Inc. is a holding company and operates through its subsidiaries including its management company, UHS of Delaware, Inc. All healthcare and management operations are conducted by subsidiaries of Universal Health Services, Inc. To the extent any reference to "UHS or UHS facilities" on this website including any statements, articles or other publications contained herein relates to our healthcare or management operations it is referring to Universal Health Services' subsidiaries including UHS of Delaware. Further, the terms "we," "us," "our" or "the company" in such context similarly refer to the operations of Universal Health Services' subsidiaries including UHS of Delaware. Any employment referenced in this website is not with Universal Health Services, Inc. but solely with one of its subsidiaries including but not limited to UHS of Delaware, Inc.