Information Security Analyst
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Information Security
The Delaware Health Information Network (DHIN) is the nation’s first statewide health information exchange. Established by statute as a not-for-profit public instrumentality, DHIN’s statutory mission is to facilitate the design and implementation of an integrated, statewide health data system to support the information needs of consumers, health plans, policymakers, providers, purchasers, and researchers to improve the quality and efficiency of health care services in Delaware.
DHIN thus serves as an aggregator of health data from disparate sources and provides services to make that data useful in a variety of settings and to a variety of users. DHIN has collected and aggregated clinical data since 2007, and additionally administers Delaware’s All Payer Claims Database, with claims data from 2013 forward. Participation in DHIN by the health care community of Delaware is nearly universal, with expansion beyond state borders now also established.
The Information Security Analyst will be an integral part of delivering DHIN’s services to the Delaware healthcare community and beyond. Specifically, this position will have a role in developing and implementing security measures to protect DHIN’s computer networks and systems. This position will also manage security incidents, vulnerability remediation and provide feedback into the Continuous Service Improvement process so that DHIN continues to improve in all aspects of securing the services offered by DHIN.
DHIN continues to focus on implementing industry best practices as defined by the IT Infrastructure Library (ITIL). After joining DHIN, all staff are required to pass the ITIL v4 Foundations certification exam. This position is required to understand both the standard and DHIN specific ITIL v4 Information Security Management and Risk Management practices.
In addition, DHIN dedicates itself to maintaining a high level of security for all the organization’s data. DHIN will obtain and maintain HITRUST certification to demonstrate this dedication. This position will participate in that ongoing certification effort. While delivering services, all DHIN staff interact with Delaware healthcare community stakeholders. The successful candidate should be able to communicate concepts clearly, concisely, and professionally to a variety of audiences.
DHIN’s main office is located in Dover, DE. While this position will have the flexibility to work remotely, some in-office work is required.
Duties and Responsibilities- Develop and maintain in-depth knowledge of the HITRUST CSF, HIPAA/HITECH Privacy and Security Rules, and all other applicable laws, regulations, and contractual requirements affecting DHIN’s privacy and security practices.
- Collaborate with Information Security Management and DHIN leadership to recommend policy updates that strengthen DHIN’s commitment to privacy and security.
- Identify endpoint, system, and software vulnerabilities, risks, and threats; recommend and implement remediation actions.
- Monitor, triage, investigate, report, and recommend remediation for potential, emerging, and active security threats or incidents.
- Participate in regular security risk assessments.
- Evaluate software products and services to identify risks and recommend mitigation strategies for both internal and third-party technologies.
- Work with staff to assess security risks in current and proposed projects.
- Participate in system testing prior to production deployment to identify and resolve security-related issues.
- Assist system owners and business teams in defining and applying appropriate security controls and permissions.
- Investigate suspicious activities, correlate and validate alerts, coordinate response activities with management, and document all findings.
- Implement approved changes and improvements to the security infrastructure, including patches, updates, reports, and alert tuning.
- Monitor and report on compliance with information security policies and procedures.
- Maintain required security documentation.
- Conduct regular security awareness training and phishing simulations; analyze outcomes and recommend corrective actions.
- Collaborate with management and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).