Information Security Analyst
Listed on 2026-08-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Serve as a champion for effective information security processes and behaviors across the enterprise.
- Triage information security alerts generated throughout the information security solution stack (i.e., MDR, CRI, XDR).
- Monitor systems that support the Mercyhealth information security posture; including, but not limited to, malware detection systems, spyware and adware detection systems, and spam filtering systems to identify trends and behaviors that increase risk.
- Investigate incidents and create accurate and timely incident reports, escalating to the appropriate persons as necessary.
- Evaluate bug reports, security exploit reports, and other security notices issued by vendors, manufacturers, government agencies, professional associations, and other organizations as needed, make recommendations to internal management and technical resources to take precaution steps and track remediation.
- Develop, maintain, and communicate key metrics to measure information security program effectiveness.
- Represent the information security program through attendance in departmental and team meetings throughout the enterprise to inform, train and promote information security topics.
- Assist in fulfilling evidence requests in response to regulatory compliance audits (i.e., SOC, HIPAA/HITECH).
- Evaluate acquired or developed systems and architectures to ensure alignment with Mercyhealth's information security requirements.
- Conduct regular audits of information systems to ensure compliance with security policies and identify areas for improvement.
- Assess the security posture of third-party vendors providing products and services to the organization.
- Identify and develop content to support the information security awareness and training program.
- Serve as an active, supporting role to the Security Incident Response Team (SIRT) and participate in security incident response efforts.
To perform the job successfully, an individual should demonstrate the following behavior expectations:
Quality - Follows policies and procedures; adapts to and manages changes in the environment;
Demonstrates accuracy and thoroughness giving attention to details;
Looks for ways to improve and promote quality;
Applies feedback to improve performance;
Manages time and prioritizes effectively to achieve organizational goals.
Service - Responds promptly to requests for service and assistance;
Follows the Mercyhealth Critical Moments of service;
Meets commitments;
Abides by MH confidentiality and security agreement;
Shows respect and sensitivity for cultural differences; and effectively communicates information to partners;
Thinks system wide regarding processes and functions.
Partnering - Shows commitment to the Mission of Mercyhealth and Culture of Excellence through all words and actions;
Exhibits objectivity and openness to other's views;
Demonstrates a high level of participation and engagement in day-to-day work;
Gives and welcomes feedback;
Generates suggestions for improving work:
Embraces teamwork, supports and encourages positive change while giving value to individuals.
Cost - Conserves organization resources;
Understands fiscal responsibility;
Works within approved budget;
Develops and implements cost saving measures; contributes to profits and revenue.
- Associate's degree and a minimum of two years of professional work experience in IT operations or IT security role.
- Certifications (e.g., CompTIA Security+) preferred.
- 1+ years of experience working in at least one of the following regulatory settings: ISO 27001, SOX, HIPAA, HITECH, CLIA, CAP desirable.
- Knowledge of common security exploits, vulnerabilities, and countermeasures.
- Demonstrated ability to perform the Essential Duties of the position with or without accommodation.
- Authorization to work in the United States without sponsorship.
Information security or cyber security certification(s) is preferred.
ADDITIONAL REQUIREMENTSPassing the Driver's License Check and/or Credit Check (for those positions requiring).
Must be able to follow written/oral instructions.
OTHERSKILLS AND ABILITIES
- Demonstrate effective communication and a highly collaborative work ethic.
- Analyze, identify, and resolve problems using critical thinking.
- Demonstrates a sense of urgency and a commitment to high standards of ethics, regulatory compliance, customer service and business integrity.
- Hands-on experience with SIEM implementation and administration.
- Information security in a public/private cloud infrastructure (Azure, AWS) environment.
- Completion or coursework toward information security certifications.
Partner may access patient care information, financial data, human resource data and strategic and planning data needed to perform their job duties as directed by the director.
WORK CONTACT GROUPPartners, physicians, vendors
SPECIAL PHYSICAL DEMANDSThe Special Physical Demands are considered Essential Job…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).