IT Security Analyst
Job in
Red Bank, Monmouth County, New Jersey, 07701, USA
Listed on 2026-09-08
Listing for:
ARSA - Advanced Reconstructive Surgery Alliance
Full Time
position Listed on 2026-09-08
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
ARSA is seeking an IT Security Analyst to serve as the operational engine behind the organization’s cybersecurity program. This role is responsible for executing the annual IT Security Work Plan across a multi-pillar physician management organization supporting approximately 1,000 Microsoft 365 users and a distributed MSP Alliance model. The IT Security Analyst reports to the Director of Information Technology and works closely with the Corporate Compliance team, external MSP and SOC partners, and pillar-level IT stakeholders.
Responsibilities- Conduct and document the annual HIPAA Security Risk Assessment in accordance with 45 CFR §164.308(a)(1).
- Maintain and update the IT security policy library, ensuring alignment with HIPAA, HITECH, NIST CSF, and organizational requirements.
- Coordinate and support internal and third-party security audits; track findings through remediation.
- Support the IT Security Sub-Committee of the Corporate Compliance Committee with documentation, reporting, and follow-up.
- Assist with vendor risk assessments, BAA review coordination, and third-party security questionnaires.
- Administer and harden M365 tenant security settings including Conditional Access policies, Entra , Defender for Office 365, Purview, and Intune.
- Monitor Microsoft Secure Score and implement recommended controls appropriate to ARSA’s risk profile.
- Support M365 tenant migration and consolidation efforts across the multi-pillar MSP Alliance structure.
- Manage role-based access control (RBAC), privileged identity management (PIM), and MFA enforcement across tenants.
- Assist in configuring and reviewing Microsoft Defender alerts, DLP policies, and audit log monitoring.
- Serve as the internal point of coordination for Tier 1 SOC escalations.
- Participate in security incident investigations, containment activities, and post-incident documentation.
- Assist with tabletop exercises and Incident Response Plan (IRP) maintenance.
- Monitor threat intelligence relevant to healthcare and physician practice environments.
- Support rogue AI/unauthorized tool detection initiatives in coordination with MSP partners.
- Coordinate and review results from vulnerability scanning (Nessus) and penetration testing (Vohani) engagements.
- Track remediation of identified vulnerabilities; elevate unresolved critical findings to the IT Director.
- Work with MSP Alliance partners to ensure consistent vulnerability management practices across pillar environments.
- Administer the KnowBe4 security awareness platform, including phishing simulations, training campaigns, and reporting.
- Analyze phishing simulation results; identify trends and recommend targeted training interventions.
- Support development and delivery of security awareness content for onboarding and annual training requirements.
- Assist in security hardening of Azure services including Key Vault, Private Endpoints, NSG rules, Log Analytics, and AI Foundry configurations.
- Apply least-privilege access controls and network segmentation standards to new Azure service deployments.
- Support Entra
-based authentication requirements and flag SQL authentication or non-compliant credential patterns in vendor integrations.
- Support the AI tool use case approval process by conducting security and privacy assessments for proposed AI tools, including review of vendor security documentation, BAA status, and data handling practices.
- Lead and maintain rogue and shadow AI detection efforts, including DNS-layer blocking, port-level controls, and threat hunting coordination with SOC and MSP partners to identify unauthorized AI tool usage across the environment.
- Evaluate the security posture of agentic and autonomous AI systems, including review of action scope, audit logging, least-privilege access, and PHI exposure risk prior to deployment approval.
- Monitor approved AI platforms (e.g., Microsoft Copilot, Claude Enterprise) for policy compliance, data handling anomalies, and alignment with CO-IS-AI requirements; elevate findings to the IT Director and Compliance as…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×