×
Register Here to Apply for Jobs or Post Jobs. X

HCS Info Security Analyst Sr

Job in Morrisville, Wake County, North Carolina, 27560, USA
Listing for: UNC REX Healthcare
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 44.56 - 64.06 USD Hourly USD 44.56 64.06 HOUR
Job Description & How to Apply Below

Description

Your passion belongs at UNC Health. Join more than 56,000 teammates working together to improve the health and well-being of the communities we serve across North Carolina.

Summary:

The Information Security Analyst Sr. supports research and Trusted Research Environment (TRE) initiatives by ensuring that research systems, data, and third-party services meet organizational security, privacy, and compliance requirements. This role partners with research teams, IT, legal, privacy, and vendors to assess risks, implement security controls, and support secure handling of sensitive data.

Responsibilities
  • Conduct security reviews of research projects, applications, and data environments. This can include software packages, In-house developed applications, Cloud architecture proposals.
  • Assess vendor security questionnaires, attestations, and compliance documentation.
  • Evaluate research systems for compliance with organizational security standards and regulatory requirements.
  • Collaborate with researchers, project managers, infrastructure teams, and compliance stakeholders.
  • Review data flows, access controls, authentication methods, and encryption practices.
  • Document risks, recommendations, and mitigation plans.
  • Assist with incident response activities involving research systems or sensitive data.
  • Track remediation activities and provide security consultation throughout project life cycles.
  • Support audits and reporting related to HIPAA, NIST, ISO 27001, SOC 2, and other applicable frameworks.
Preferred Qualifications
  • Strong hands‑on experience in Azure Cloud Security and Information Security.
  • Practical experience with Microsoft Defender for Cloud and Azure security services.
  • Knowledge of healthcare data compliance frameworks (HIPAA, HITECH, NIST 800‑53, SOC, HITRUST, CIS Benchmarks).
  • Understanding cloud security concepts (Azure, AWS, or GCP).
  • Strong written and verbal communication skills.
  • Deep understanding of Azure TRE architecture, enclave boundaries, airlock mechanisms, and isolated cloud work spaces.
  • Advanced proficiency in Microsoft Purview (DLP, Information Protection, eDiscovery, Insider Risk Management).
  • Understanding of KQL log analytics and scripting (Power Shell/Python) for security automation.
  • Embed security into Dev Sec Ops  and Secure SDLC
    , including threat modelling, security requirements, code/IaC/container scanning, secrets management, vulnerability remediation, and CI/CD security gates.
  • Experience supporting healthcare, academic, or research environments.
  • Familiarity with research governance and handling of sensitive or regulated data.
  • Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent.
  • Experience with vendor risk management and third-party security reviews.
Other Information Education Requirements

Bachelor’s degree in Computer Science, Information Systems Management or a related field (or an equivalent combination of education, training and experience) required.

Licensure/Certification Requirements
  • No licensure or certification required.
  • Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent are preferred.
Professional Experience Requirements

If a Bachelor's degree:
Eight (8) years in professional IT positions, with 4 years of experience in related job functions required.

If an Associate's degree:
Twelve (12) years in professional IT positions, with 4 years of experience in related job functions required.

If a high school diploma or GED:
Sixteen (16) years in professional IT positions, with 4 years of experience in related job functions required.

Key Competencies
  • Risk assessment and analysis
  • Security governance and compliance
  • Vendor and third-party risk management
  • Research data protection
  • Stakeholder communication
  • Documentation and reporting
  • Project coordination
Success Measures
  • Timely completion of security reviews and risk assessments.
  • Effective identification and mitigation of security risks.
  • High-quality documentation and stakeholder engagement.
  • Compliance with organizational and regulatory requirements.
  • Successful support of research and TRE initiatives while maintaining security standards.
Job Details

Legal

Employer:

NCHEALTH

Entity:
Shared Services

Organiza…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary