Security Analyst
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Support
Role Summary
At Notable, securing the sensitive health data our customers trust us with is critically important. As a Security Analyst, you’ll help keep our internal Information Security Management System policies and procedures up to date with the latest best practices and security standards, help drive external security audits, and interface with our customers’ information security teams. You’ll work closely with Notable’s Product Management, Engineering, Sales, Operations, and Customer Success teams to ensure that information security is embedded throughout the organization and embedded in every decision we make.
WhatYou’ll Do
- Update, and maintain Notable’s comprehensive ISMS policy and procedure documentation
- Assist with internal and external security audits (HITRUST, SOC 2, ISO, PCI)
- Provide guidance to Notable teams to ensure compliance with the ISMS, address risk assessments
- Assess external vendors for compliance with the ISMS
- Lead internal audits and investigations
- Complete customer infosec questionnaires and documentation requests
- Successful in a fast-paced, collaborative environment
- Experience managing security compliance projects in GCP/ AWS cloud environments
- Ability to create and administer effective security awareness training and materials (Security training, PHI handling, HIPAA training compliance)
- Experience with third party vendor management
- Business continuity planning and incident response experience
- Vulnerability management and coding processes
- You work with empathy
- You have regulated industry experience (healthcare, finance, government)
- You’re curious and don’t mind wearing a lot of hats
We value in-person collaboration and connection. For Bay Area–based employees, this role requires being in our San Mateo office at least three days a week. For remote employees, occasional travel to headquarters is expected for company-wide events and onsite gatherings.
Beware of job scam fraudsters! Our recruiters use email addresses exclusively. We do not conduct interviews via text or instant message, to purchase equipment through us, or to provide sensitive personally identifiable information such as bank account or social security numbers. If you have been contacted by someone claiming to be me from a different domain about a job offer, please report it as potential job fraud to law enforcement and contact us here.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).