Why This Role Stands Out
This hybrid Senior Security Analyst role offers a fantastic opportunity to make a significant impact on critical healthcare security initiatives, with the potential for extensive skill development in a reputable organization. You'll thrive here if you're a proactive, hands-on professional ready to drive control implementation and risk assessment within a dynamic environment. Apply today to contribute your expertise and grow your career in a flexible, rewarding setting.
Quick Overview
Job Description
Visa: USC/EAD
Experience: 10+ Years
Position Overview
The HIPAA Security Program supporting Innovative Medicine Commercial Patient Support Program for the customer’s Healthcare Systems and Patient Service Center requires experienced senior-analyst capacity for a defined 90-day period to maintain momentum on control implementation, risk assessment, audit evidence collection, and regulatory alignment activities while the team is short-staffed.
This is a hands-on execution role, not an advisory-only role. The contractor will work directly with the Sr. Manager, Cybersecurity – HIPAA Security and will be expected to produce audit-ready documentation, control assessments, and remediation tracking with minimal supervision. The right candidate is a self-starter comfortable operating in a regulated, fast-paced pharmaceutical commercial environment and able to translate the HIPAA S.
Key Responsibilities
HIPAA Control Assessment: Assess and document the implementation of HIPAA Security Rule administrative, physical, and technical safeguards across in-scope applications, platforms, and third parties.
Risk Assessment: Evaluate findings of security risk assessments for systems and vendors handling PHI; develop treatment plans, and residual risk in the program's GRC tooling.
Audit & Evidence Readiness: Collect, validate, and organize control evidence for internal and external audits and assessments; maintain finding-by-finding tracking and closure documentation with citations to the applicable policy or control.
Security Control Implementation-to-Control Mapping: Map enterprise information asset protection policies and HIPAA requirements to technical control implementations and recognized frameworks (e.g., NIST 800-53r5), maintaining crosswalk matrices and justification detail.
Security Controls: Review and validate security configuration and control coverage in Salesforce, Microsoft 365, AWS, etc., — including identity and access management, least privilege and role design, encryption, logging and monitoring, data retention, and third-party/connected application review.
Remediation Support: Partner with technology teams, application owners, and vendors to define, track, and verify remediation of control gaps and audit findings through to closure.
Secure by Design for Projects: Provide consulting support on active high-risk projects — design reviews, control requirements definition, and ensure control implementation prior to go-live.
Documentation & SOPs: Assist in drafting and updating standard operating procedures, control narratives, and process documentation to a standard suitable for auditor review.
Incident & Resilience Support: Support IAPP and HIPAA security incident handling, breach-analysis documentation, and business continuity / disaster recovery tabletop exercise preparation and write-ups.
Training & Awareness: Assist in the preparation and delivery of HIPAA Security Rule awareness material for business and technology partners.
Reporting: Produce concise status reporting and metrics suitable for senior leadership consumption.
Required Experience and Skills
5+ years in information security, IT risk management, or security compliance, with demonstrable hands-on control assessment experience.
Direct, practical experience applying the HIPAA Security Rule — safeguard interpretation, risk analysis, control implementation, and audit support in a covered entity or business associate environment.
Security Controls: Experience implementing security controls based on policies to achieve both security best practices and compliance objectives
Microsoft 365 security understanding: Entra ID / conditional access, Purview data protection and DLP, audit and unified logging, Defender suite, and tenant-level configuration review.
AWS security controls: IAM and role design, KMS/encryption, logging (CloudTrail, CloudWatch), network segmentation, S3 and data-store protection, and control baseline assessment.
Experience producing audit-ready documentation — evidence packages, control narratives, risk registers, and finding closure matrices.
Working knowledge of a recognized control framework (NIST 800-53 / CSF, ISO 27001, HITRUST, or equivalent) and the ability to crosswalk requirements across frameworks.
Strong written communication; able to produce material that goes to senior leadership without rework.
Ability to work independently across virtual, cross-functional and global teams, and to manage multiple concurrent workstreams.
Preferred
Experience in pharmaceutical, healthcare, payer, or patient-services environments handling PHI.
Salesforce security: profiles, permission sets, sharing and field-level security, Shield/encryption concepts, event monitoring, connected apps, and third-party integration review.
Hands-on experience with a GRC platform for control and issue management (e.g., LogicGate or equivalent).
Familiarity with SIEM/monitoring operations (e.g., Microsoft Sentinel) and security logging requirements.
Exposure to AI governance or securing AI/agent-based capabilities in a regulated setting.
Awareness of state-level pharmacy cybersecurity and privacy requirements in addition to federal HIPAA obligations.
Certifications such as CISSP, CCSP, CISA, CRISC, or CISM; cloud certifications (AWS Security Specialty, Microsoft SC-series) are a plus.
BA/BS in Computer Science, Engineering, Information Security, or equivalent practical experience.
Similar jobs
- AD
Security Engineering Lead with Security Clearance
NewAgile Defense, LLC
Reston, VA🇺🇸$165k - $201k/yrHybrid21 hours agoAgileAdministrative - TC
Cyber Network Defense Analyst with Security Clearance
NewTEKsystems c/o Allegis Group
San Antonio, TX🇺🇸$90k - $120k/yrOn-site21 hours agoSplunkTechnology - E-
Security Engineer with Security Clearance
NewE-INFOSOL LLC
Washington, DC🇺🇸Hybrid21 hours agoDockerFastAPIAWS+11Technology - AM
Cyber Systems Engineer/ Information System Security Engineer (IS with Security Clearance
NewAmentum
Washington, DC🇺🇸Hybrid21 hours agoConfluenceGitTechnology - SI
OH - IT Security Analyst/ Supply Chain Risk Consultant - 812707
NewSR International Inc.
Columbus, OH🇺🇸Hybrid21 hours agoTechnology - MI
Sr AI Security Engineer - Remote
NewMergen IT LLC
United States🇺🇸Remote21 hours agoAWSOWASPAzure+3Technology