Quick Overview
Job Description
Job Type: Contract
Work Arrangement: Local Candidates Only
Interview: Face-to-Face Interview Required
Experience: 3+ Years IT Experience
Industry: Healthcare / EHR
Location: Richmond, VA
Position Overview
We are seeking an experienced EHR Security Analyst to support security, access management, role-based permissions, and user provisioning within a Cerner Millennium EHR environment.
This role will work closely with the EHR Application Team, EHR Security Officer, Information Security Office (ISO), EHR Core Team, IT Technical Team, Support Team, and HIPAA Compliance stakeholders to ensure appropriate access controls and security practices are implemented and maintained.
The ideal candidate will have hands-on experience with Cerner Millennium, OHPAC security groups, EHR access controls, user provisioning, Active Directory, SSO, MFA, identity management, HIPAA/HITECH compliance, and healthcare application security.
Candidates must be local and available for a face-to-face interview.
Key Responsibilities
- Manage and maintain EHR user access, security policies, role-based permissions, and application security controls.
- Map and maintain EHR position definitions, including Cerner Millennium Positions, Preferences, and OHPAC Security Groups.
- Monitor and enforce appropriate use of EHR access-control positions and policies based on user roles and job responsibilities.
- Work with the EHR Security Officer, IT, Support, and EHR Core teams to define, improve, and automate user provisioning and offboarding processes.
- Investigate and troubleshoot EHR security and access-related issues.
- Monitor EHR access and user activity to identify inappropriate access, unusual behavior, security risks, and potential incidents.
- Use tools such as P2Sentinel to monitor user behavior, identify trends, and assist with security investigations.
- Conduct internal security reviews and audits of the EHR application to identify and mitigate security risks and vulnerabilities.
- Assist with internal and external healthcare security audits and provide required documentation and evidence.
- Develop and maintain EHR security policies, procedures, standards, and operational guidelines.
- Work with the EHR Security Officer and ISO team to maintain security documentation and downtime procedures in accordance with applicable organizational and VDH security guidelines.
- Assist in investigating and responding to EHR-related security incidents, including documentation, escalation, reporting, and resolution.
- Collaborate with EHR implementation and optimization teams to incorporate security controls into new functionality, upgrades, integrations, and third-party applications.
- Participate in Cerner/OHPAC upgrades, security patches, system maintenance, and application security activities.
- Participate in EHR domain strategy and security planning.
- Stay current on healthcare security threats, EHR security practices, regulatory requirements, and emerging technologies.
- Recommend improvements to the EHR security environment based on security trends, vulnerabilities, operational findings, and industry best practices.
Required Qualifications
- 3+ years of IT experience; healthcare IT experience strongly preferred.
- Strong understanding of EHR systems and healthcare application security.
- Hands-on experience with Cerner Millennium and/or OHPAC security.
- Understanding of HIPAA, HITECH, and healthcare information security requirements.
- Experience managing or supporting role-based access control, user permissions, and application security.
- Experience with Active Directory (AD), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and identity management solutions.
- Strong analytical, problem-solving, troubleshooting, and investigative skills.
- Ability to troubleshoot Cerner/OHPAC security, access, and permission-related issues.
- Strong communication skills and ability to work with technical teams, security teams, compliance officers, application teams, and end users.
- Familiarity with healthcare IT infrastructure, including networking, firewalls, and database security.
- Knowledge of Cerner Discern and CCL.
- Ability to work independently while collaborating across multiple technical and business teams.
Core Technical Skills
EHR / Cerner Security
- Cerner Millennium
- OHPAC
- Cerner Positions
- Cerner Preferences
- OHPAC Security Groups
- EHR Access Control
- Role-Based Access Control (RBAC)
- EHR User Provisioning
- User Offboarding
- EHR Security Policies
- Cerner Security Administration
- Cerner Upgrades and Security Patches
- Discern
- CCL
Identity & Access Management
- Active Directory
- SSO – Single Sign-On
- MFA – Multi-Factor Authentication
- Identity Management
- User Provisioning
- Access Reviews
- Role-Based Permissions
- Authentication / Authorization
Healthcare Security & Compliance
- HIPAA
- HITECH
- Healthcare Information Security
- EHR Security
- Security Audits
- Security Policies & Procedures
- Security Documentation
- Incident Response
- Risk Identification & Mitigation
- Vulnerability Management
Similar jobs
- NT
Cyber Network Defense Analyst III with Security Clearance
NewGen Technologies
Arlington, VA🇺🇸On-site5 days agoSplunkTCP/IPDNS+1Technology - AG
Information Systems Security Engineer 0 (ISSE0) (Government) with Security Clearance
NewAT&T Government Solutions
Columbia, MD🇺🇸$72k - $167.9k/yrOn-site10 hours agoFiberSplunkLESSTechnology - DO
IT CYBERSECURITY SPECIALIST (INFOSEC) with Security Clearance
NewDepartment of the Air Force
Hoonah, AK🇺🇸HybridYesterdayLESSTechnology - SM
Information Security Analyst (SOC Analyst) (5456) (TS/SCI CI Pol with Security Clearance
Smartronix, LLC
Fort Liberty, NC🇺🇸On-site5 days agoSplunkTechnology - AK
QA Reviewer, Cyber Security Analyst III with Security Clearance
NewAkima
Rockville, MD🇺🇸$110k - $135k/yrOn-siteYesterdayTechnology - GT
Physical Security/Information Assurance (PS/IA) Specialist with Security Clearance
NewgTANGIBLE Corporation
Suitland, MD🇺🇸HybridYesterdayAdministrative