IT Security Analyst
Physicians Management Group LLC
Description PHYSICIANS MANAGEMENT GROUP JOB DESCRIPTION IT Security Analyst REPORTS TO: Director of Information Systems SCHEDULE: HYBRID GENERAL SUMMARY: Maryland Primary Care Physicians, LLC (MPCP) is an independent, physician-owned network comprised of approximately 100 board certified providers across 10 locations, servicing 130,000 patients. MPCP's operations and financial management are performed by Physicians Management Group, LLC (PMG). The IT Security Analyst is responsible for safeguarding the organization's information systems, data, and infrastructure through proactive risk management, continuous monitoring, and compliance tracking. This role supports the Compliance Manager's formal risk analysis and risk register, contributes to the cybersecurity insurance renewal process, manages the core security toolset, and assists with incident response and breach risk determination. The Analyst also supports HIPAA-aligned access governance and vendor risk oversight for systems and third parties handling electronic protected health information (ePHI), partnering closely with the Director of Information Systems on policy development and overall security posture. The ideal candidate combines strong technical expertise with sound judgment, clear communication, and a proactive approach to identifying and mitigating security risks in a healthcare environment where ransomware, phishing, third-party/vendor compromise, and connected medical device (IoMT) threats are persistent and escalating. Responsibilities span the administrative, physical, and technical safeguards required by the HIPAA Security Rule. This list of duties is representative and not exhaustive; additional responsibilities may be assigned as business needs evolve. SUPERVISION EXERCISED: None. Typical Physical Demands: Requires sitting, some standing, stooping, and stretching. Occasionally may lift up to 30 pounds. Requires sufficient hand-eye coordination and manual dexterity to operate a keyboard, photocopier, telephone, calculator, and other office equipment. Requires normal range of hearing and eyesight to record, prepare, and communicate appropriate reports. Typical Working Conditions: Work is typically performed in a corporate office / clinic setting and could involve contact with staff and/or patients. Hybrid schedule: three days per week on-site and two days remote. Occasional travel to affiliated MPCP locations as needed. On-call availability may be required to support security incident response. Primary Duties/Responsibilities Include but not Limited to: Cyber Insurance & Risk Management Annually analyze changes to cyber insurance requirements and partner with the Director of IS to implement necessary policy, technical, or procedural changes Complete annual attestation forms and applications required for cyber insurance renewal Security Operations & Compliance Monitoring Implement, monitor, and maintain security protocols and controls across the environment Conduct regular user account audits, security group audits, and MFA compliance reviews Coordinate periodic penetration testing and vulnerability assessments with an approved third-party vendor; track and remediate identified deficiencies Manage the security vendor quoting and evaluation process Support the formal HIPAA-aligned risk analysis, including contributing to the risk register and tracking of remediation owners and timelines Verify and maintain encryption standards for ePHI at rest and in transit across endpoints, servers, and email Perform regular review of information system activity – including audit logs, access reports, and security incident tracking reports – to detect unauthorized or anomalous access to ePHI (HIPAA 164.308(a)(1)(ii)(D)) Implement, maintain, and periodically test audit controls that record and examine activity in information systems that contain or use ePHI (HIPAA 164.312(b)) Systems & Tools Management Manage and monitor remote monitoring and management (RMM) tools Manage and monitor SIEM, antivirus, and EDR platforms, including alert triage, mitigation, and incident reporting Support technical incident response activities, including investigation, containment, and coordination with the Compliance Manager on HIPAA breach risk determination and notification requirements Administer and monitor the Proofpoint email security platform Oversee Windows endpoint patch management and compliance reporting Manage firewall rule adjustments as needed to support security requirements Maintain a current inventory of networked, biomedical, and Internet-of-Medical-Things (IoMT) devices that create, store, or transmit ePHI; monitor them for known and exploited vulnerabilities and support network segmentation to isolate high-risk devices Configure and verify technical access controls on systems containing ePHI, including unique user identification, automatic logoff, and emergency access procedures (HIPAA 164.312(a)) Verify that ePHI is backed up, that backups are encrypted and maintained in an offline or immutable form, and that restoration is regularly tested to ensure recovery from ransomware or destructive attacks Policy & Compliance Support Assist the Director of IS and Compliance Manager in developing and maintaining policies and procedures supporting the organization's cybersecurity posture Support development of policies and procedures aligned with HIPAA regulatory requirements and risk management standards Support security controls and audit processes for the Electronic Health Record (EHR) system and all systems containing ePHI Support periodic access reviews for systems containing ePHI to ensure alignment with least-privilege and minimum-necessary access principles Support vendor security risk assessments and due diligence for third parties with access to ePHI, in coordination with the Compliance Manager Confirm that Business Associate Agreements (BAAs) are executed and current for all third parties that create, receive, maintain, or transmit ePHI, in coordination with the Compliance Manager Support physical safeguards and device and media controls, including secure disposal, re-use, sanitization, and tracking of hardware and media containing ePHI (HIPAA 164.310) Support timely provisioning and deprovisioning of access upon hire, role change, and termination, and assist with enforcement of the workforce security and sanction policies for security violations (HIPAA 164.308(a)) Support periodic technical and non-technical evaluations of the security program against the HIPAA Security Rule and maintain required security documentation and evidence for at least six years (HIPAA 164.308(a)(8), 164.316) Business Continuity & Organizational Support Participate in Business Continuity and Disaster Recovery planning, testing, and tabletop exercises Monitor healthcare-specific threat intelligence (e.g., Health-ISAC, HHS HC3, and CISA advisories) and translate relevant alerts into defensive actions Manage and monitor employee security awareness training programs and track completion/compliance Research and attend relevant security conferences, training, and continuing education opportunities Performance Requirements: Maintains cyber insurance attestations, applications, and required policy/control updates on schedule to keep the organization's coverage current and audit-ready Completes user account, security group, and MFA compliance audits on a regular, defined cadence, with findings documented and remediated within established timeframes Ensures penetration testing and vulnerability assessments are scheduled, completed, and tracked to closure, with identified deficiencies remediated according to risk-based timelines Contributes accurate, timely updates to the HIPAA risk register, including clear ownership and remediation timelines for each identified risk Reviews audit logs, access reports, and security incident tracking reports on a consistent basis, escalating unauthorized or anomalous ePHI access promptly Keeps SIEM, antivirus, EDR, and email security (Proofpoint) platforms properly configured and monitored, with alerts triaged and addressed within defined response windows Maintains Windows endpoint patch compliance at or above organizational targets Supports incident response activities with clear, timely documentation and coordination with the Compliance Manager on breach risk determination Maintains a current, accurate inventory of networked, biomedical, and IoMT devices, with known vulnerabilities tracked and addressed Verifies ePHI backup, encryption, and restoration testing occur on schedule, with results documented Supports policy, access review, and vendor risk assessment activities in a manner that meets HIPAA regulatory deadlines and audit expectations Maintains required security documentation and evidence in accordance with the six-year HIPAA retention requirement Participates actively in Business Continuity/Disaster Recovery planning, testing, and tabletop exercises, and maintains accurate supporting documentation and after-action reports Ensures employee security awareness training completion is tracked and reported accurately Demonstrates sound judgment and clear, professional communication when working across IT, compliance, and vendor stakeholders, and escalates issues appropriately and in a timely manner Stays current on cybersecurity threats and technologies through ongoing professional development Knowledge, Skills & Abilities: Demonstrated verbal and written communication skills Demonstrated analytical and problem-solving abilities Ability to work collaboratively across IT and compliance functions while managing competing priorities Microsoft 365 security stack proficiency required, including Entra ID (Azure AD), Exchange Online, Microsoft Defender, Conditional Access, and Purview / Data Loss Prevention (DLP) Required scripting/automation experience, particularly PowerShell Working knowledge of vulnerability management, network segmentation, and backup/recovery practices Education: Bachelor's degree in Computer Science, Information Technology, or related field required Experience: Minimum 3 years of IT experience with a security focus Hands-on experience with SIEM and EDR platforms Experience supporting a healthcare EHR environment strongly preferred Working knowledge of HIPAA rules and regulations Familiarity with the HIPAA Security Rule safeguards (administrative, physical, and technical) and the Breach Notification Rule Exposure to medical device/IoMT security and network segmentation preferred Certifications/License: CompTIA Security+ certification (or greater) required Preferred: an intermediate or healthcare-focused security certification such as CompTIA CySA+, GIAC GSEC, or CISSP Alternative to Minimum Qualifications: None #J-18808-Ljbffr
- We are seeking an experienced Info Security Analyst IV to support FIPS 140 validation projects within a hands-on lab environment. This role focuses on security analysis, cryptographic validation testing, product evaluations, automation, and technical reporting in support...SuggestedLocal area
- ...Senior Information Security Analyst As a Senior Information Security Analyst, you will be a key member of our security team, responsible... ...enablement. Requirements: ~5-7 years of work experience in IT in one or more areas of infrastructure, application development...SuggestedContract workWork experience placementWork at office2 days per week
- ...Job Description Job Description iQuasar is seeking to fill an Information Security Analyst IV position. At iQuasar, we strive to provide the next generation of cutting-edge technologies. Our growth means exciting career opportunities for talented professionals in...SuggestedContract work
- ...provide simple access to care from anywhere, helping health plans deliver better outcomes for their members. We're Hiring an Actuarial Analyst to Join Our Team! We are seeking a highly analytical and detail-oriented Actuarial Analyst to join our Analytics team. This role...Suggested
$19.25 per hour
...Target here. ALL ABOUT ASSETS PROTECTION Assets Protection (AP) teams function to keep our guests, team and brand secure and lead through crisis events. They protect profitable sales by mitigating shortage risks, preventing, and resolving theft and...SuggestedHourly payLocal areaFlexible hoursShift workNight shiftDay shift- ...Senior Financial Analyst/Project Planning & Controls (PP&C) Senior Financial Analyst/Project Planning & Controls (PP&C) to join the project team, supporting Program Management and cross‑functional partners. The role oversees full P&L and cash flow responsibility for assigned...Contract workTemporary workFor subcontractorWork at officeLocal areaRelocation packageFlexible hours
- ...John Evans Recruiting has an exciting Senior Financial Analyst to support directly the CFO in developing an fp&a team. This will be for a rapidly growing privat eequity backed SAAS business so its important someone comes with budgeting/forecasting, CFO support abilities...
$68k - $78k
...transparency, and decision support. We are seeking a Senior Financial Analyst to join our Corporate Finance team. This newly created role will... ...closely with division leaders, cost center managers, IT, Procurement, Legal, and Finance leadership to support decision‑...Flexible hours- ...Security Specialist Connexus Hub is a professional services firm that works with Government Agencies and Fortune 500 customers. Our team brings the innovation and agility of a small company along with the breadth and impact of a large firm. Our expansive range of capabilities...Part timeMonday to Friday
$75k - $85k
Orano TN (an Orano subsidiary) is a leader in U.S. nuclear logistics, offering innovative solutions for used nuclear fuel, radioactive waste management, and transportation. Our success is driven by a focus on safety, human performance, transparent pricing, and integrity...Temporary workWork experience placementFor subcontractor$2,900 - $5,800 per month
Every year huge investments are made on construction projects that support the Navy’s high-tech fleet of ships, aircraft, equipment and personnel. At the center of these projects is a talented group of Civil Engineers who help to ensure that each initiative is conceived...Civilian ContractorFull timeContract workPart timeWork at office- ...Title: Corporate FP&A Analyst We are KBR When you become part of our KBR team, your opportunities are endless. Through internal... ..., and system-to-system integrations Partner with Finance and IT teams to design and implement smarter, scalable solutions that improve...Temporary workWork at officeLocal areaRemote workRelocation packageFlexible hours
- A leading investigations company is hiring a Full Time Background Field Investigator. This remote role requires an active Top-Secret Clearance and entails conducting federal background investigations. You will travel to various locations while preparing detailed reports...Full timeRemote work
- ...focuses on preventing financial loss due to theft and fraud while supporting safety compliance in stores. The specialist will monitor security, document incidents, and maintain close relations with law enforcement. Ideal candidates should be committed to integrity and...
- ...officers, identify and report hazards and suspicious activities. Patrol the campus being highly visible and alert for safety and security hazards, suspicious activities and intruders. Respond to alarms. Respond to all calls for campus police services. Render services...Full timeWork experience placementWork at officeLocal areaRemote workVisa sponsorshipWork visaShift workWeekend workAfternoon shift
$25.82 - $47.5 per hour
...out of your primary residence. With your active Top-Secret Clearance required , you will play a vital role in supporting National Security and ensuring excellence with our clients and customers. The compensation range is $25.82-$47.50 per hour with additional H&W/hour...Hourly payFull timeContract workFor contractorsRemote workHome officeFlexible hours- ...Senior Financial Analyst Industry leading manufacturer is looking for a Financial Analyst that will produce the monthly operating expense reporting package and present to leadership and department managers. You'll be responsible for creating dashboards, budget versus...
- ...Financial Analyst Maryland - Columbia, MD 21046 Overview Level: Experienced Position... ...specialized services in the Cyber Security, Information Technology, Intel Analysis,... ...strong background in systems engineering and IT solutions with experienced operational analysts...Full timeContract workOverseas
- ...JOB SUMMARY: Arundel Mills Supervision of all employees assigned to the Security department, with full responsibility for performance management of said staff. Manage and oversee all assigned areas in order to maintain a safe environment for all employees, vendors...For contractorsLocal areaImmediate startShift work
$15 - $20.4 per hour
...with peers and supervisors to accomplish tasks ~ Able to work a flexible schedule to support business needs ~0-2 years retail or security experience Benefits include: Associate discount; EAP; smoking cessation; bereavement; 401(k) Associate contributions; child...Hourly payTemporary workLocal areaHome officeFlexible hours$25 - $32 per hour
...Position Overview: We are seeking a detail-oriented and highly organized Human Resources / Personnel Security Assistant to support our HR and Security departments with administrative, personnel, and compliance-related duties. The ideal candidate will have experience...Contract workFor contractors$99k - $110k
Who We Are As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constellation is focused on our purpose: lighting the way to a brilliant tomorrow for all. We have been the leader in clean energy production...Shift work$65.06k - $117.29k
About the Job Financial coordinator between MedStar's self-insured claims management program and MedStar's captive insurance company and in that role provides to MedStar's Finance Department detailed financial information regarding expenses associated with the claims management...Work at office$40 - $45 per hour
...Cleared Armed Security Officer Position Type: Full-Time, Non-exempt Work Location: Columbia, MD Clearance: Minimum Secret Shift: 12-hour Panama Schedule Patriot Group International LLC. (PGI), voted #1 Best Place to Work by Virginia Business Magazine and...Hourly payFull timeFor contractorsLocal areaLong distanceShift work$38 - $45 per hour
...Electronic Security Banking Specialist 2 Location: Mount Laurel, NJ 08054, USA Location details: Showing 1 location Description Convergint is looking for a full-time Banking Service Technician to service and support existing customers by responding to service calls, carrying...Full timeLocal areaRemote work$38.5 per hour
...Job Posting: 07/31/2026 Job Posting End: 08/28/2026 Job ID: R0289528 EARN A BONUS UP TO $2,500! At Wegmans, our store security teams are committed to keeping our customers and employees safe. Our security specialists play a critical role helping to communicate...Full timeWork at officeDay shiftAfternoon shift$72.28k - $108.16k
TD Bank is seeking a Senior Finance Analyst for the Mount Laurel, New Jersey location, offering a hybrid work model. The role involves conducting financial analysis, providing financial support, and advising management on various finance processes. The ideal candidate will...$61k - $65k
...Overview Actalent has an immediate opening for a Financial Analyst at our Corporate office in Hanover, MD. Compensation Target Salary | $61,000 - $65,000 Bonus potential | Quarterly up to $1,000 Schedule Full Time | Permanent Monday - Friday | 8:00 AM - 5:00 PM Hybrid...Permanent employmentFull timeTemporary workWork at officeImmediate startRemote workMonday to Friday$72.95k - $103.96k
...sales as one of the largest privately owned dealership groups in the United States. Principal Purpose of Position Be the lead analyst on non-standard client analyses and long term projects Create new tools and improve upon existing processes Utilize data...Full timeTemporary workPart timeWork experience placementWork at officeLocal areaFlexible hours- ...Actalent is seeking a Financial Analyst for our corporate office in Hanover, MD. The role focuses on preparation, validation, and analysis of all department financials, supporting budgeting and income statement analysis for Directors and Controllers. The position requires...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Analyst. Be the first to apply!





