IT Security Analyst II
Job in
Lawrenceville, Gwinnett County, Georgia, 30243, USA
Listed on 2026-10-01
Listing for:
Capital Health
Full Time, Part Time
position Listed on 2026-10-01
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
CH IT Lawrenceville:
Full time:
Posted Today:
JR110946
Capital Health is the region's leader in providing progressive, quality patient care with significant investments in our exceptional physicians, nurses and staff, as well as advanced technology. Capital Health is a dynamic health care resource accredited by the DNV that includes two hospitals, an outpatient center, satellite ED, and an expansive network of primary and specialty care. Capital Health Medical Group is made up of more than 600 physicians and other providers who offer primary and specialty care, as well as hospital-based services, to patients throughout the region.
Capital Health recognizes that attracting the best talent is key to our strategy and success as an organization. As a result, we aim for flexibility in structuring competitive compensation offers to ensure we can attract the best candidates.
The listed pay range or pay rate reflects compensation for a
** full-time equivalent (1.0 FTE)
** position. Actual compensation may differ depending on assigned hours and position status (e.g., part-time).
** Pay Range:**$ - $
** Scheduled Weekly
Hours:
** 40
* * Position Overview**## SUMMARY (Basic Purpose of the Job):
The IT Security Analyst II independently owns and manages core information security programs, including third-party risk management (TPRM), Security Awareness Training, and Application Security Assessments. This role serves as a trusted resource for staff and leaders regarding information security policy implementation, interpretation, and compliance, and drafts and maintains information security policies, standards, and procedures. Building on the foundation of the IT Security Analyst I role, this position operates with greater autonomy, owns end-to-end programs and initiatives, and provides mentorship and guidance to less experienced team members.
The position assesses and prioritizes information security and cybersecurity risk across the organization, facilitates compliance with regulatory requirements and information security policies, and develops and reports on information security metrics.##
MINIMUM REQUIREMENTS:
*
* Education:
** Bachelor's degree in a relevant field or equivalent experience.
*
* Experience:
** Three years demonstrated experience in cybersecurity, GRC, vulnerability management, TPRM, or related roles, including experience gained as an IT Security Analyst I or in an equivalent role required. Working knowledge of NIST CSF, HIPAA, or other security/regulatory frameworks required. CompTIA Security+ required. One or more mid-level certifications such as CompTIA CySA+ or ISACA CRISC preferred (or equivalent). Progress toward or attainment of ISACA CISM, CISA, or ISC2 CISSP is a plus.
** Knowledge and
Skills:
** Strong working knowledge of desktop, server, storage, virtualization, networking, and security technologies. Demonstrated ability to independently lead risk assessments, vendor risk reviews, and vulnerability remediation efforts, and to translate technical findings into business risk language for non-technical stakeholders.
** Special Training:
** A+, Network+, Security+, CySA+, CRISC, or other relevant IT security certifications are a plus.
** Mental, Behavioral and Emotional Abilities:
** Ability to work independently with minimal supervision, exercise sound judgment on risk-based decisions, mentor junior staff, and communicate effectively with both technical and non-technical audiences under time-sensitive conditions.## ESSENTIAL FUNCTIONS
* Owns and manages the third-party risk management (TPRM) program end-to-end, including vendor classification logic, risk scoring methodology, intake routing/workflows, assessment questionnaires, and reassessment tracking; serves as the primary point of contact for vendor risk questions across the organization.
* Independently drives vendor risk assessments from initial outreach through closure, including follow-up with unresponsive vendors, review of vendor-submitted documentation, and escalation of high-risk or unresolved vendor relationships to leadership.
* Administers the organization's enterprise phishing simulation program, including campaign design and scheduling, execution, data collection, results analysis, and reporting of metrics and trends to leadership.
* Performs Application Security Assessments for new and existing software, evaluating security posture and providing risk-based recommendations to stakeholders.
* Owns and manages the software request and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×