Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead IT Security Analyst - HIPAA, HITRUST, FISMA

$121.79k - $210.09k

NYULMC

Job Description

NYU Langone Health is a fully integrated health system that consistently achieves the best patient outcomes through a rigorous focus on quality that has resulted in some of the lowest mortality rates in the nation. Vizient Inc. has ranked NYU Langone the No. 1 comprehensive academic medical center in the country for three years in a row, and U.S. News & World Report recently placed nine of its clinical specialties among the top five in the nation. NYU Langone offers a comprehensive range of medical services with one high standard of care across 6 inpatient locations, its Perlmutter Cancer Center, and over 320 outpatient locations in the New York area and Florida. With $14.2 billion in revenue this year, the system also includes two tuition-free medical schools, in Manhattan and on Long Island, and a vast research enterprise with over $1 billion in active awards from the National Institutes of Health.


For more information, go to NYU Langone Health, and interact with us on LinkedIn, Glassdoor, Indeed, Facebook, Twitter, YouTube and Instagram.

Position Summary:
We have an exciting opportunity to join our team as a Lead IT Security Analyst.


This position reports to the IT Controls & Regulatory Compliance Manager and serves as a senior individual contributor and subject matter expert responsible for leading enterprise risk assessments and evaluating the security of modern technology environments, including cloud-based platforms.


The IT Controls Lead drives the design, execution, and continuous improvement of the organizations risk assessment program to ensure compliance with regulatory and industry requirements, including HIPAA, HITRUST, PCI DSS, and FISMA.


This role partners closely with IT, Security, Clinical, Research, and Compliance stakeholders to assess risk across enterprise systems, research technologies, and cloud infrastructure, and to ensure that security controls are appropriately designed and operating effectively.

Job Responsibilities:

Enterprise Risk Assessment Leadership

  • Lead the execution and maturation of the enterprise risk assessment program aligned to regulatory and industry frameworks
  • Conduct and oversee complex risk assessments , including HIPAA and HITRUST-aligned evaluations
  • Define and maintain risk assessment methodologies, scoring models, and standards
  • Identify, analyze, and document risks, and develop actionable remediation strategies

Cloud Security & Technology Risk Evaluation
  • Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS)
  • Evaluate key control domains, including:
  • Identity and access management
  • Network architecture and segmentation
  • Logging, monitoring, and detection capabilities
  • Data protection and encryption
  • Assess alignment to frameworks such as:
  • HITRUST
  • PCI
  • NIST Cybersecurity Framework
  • ISO/IEC 27001
  • Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments

Research Technology & Clinical Risk Oversight
  • Lead security and risk reviews of research technologies and data use cases , including systems handling sensitive or regulated data
  • Partner with clinical and research stakeholders to evaluate emerging technologies and ensure appropriate risk controls are in place
  • Provide guidance on secure design and data protection strategies
Cross-Functional Leadership & Escalation
  • Serve as a senior escalation point for complex or high-risk assessments across:
  • Enterprise systems
  • Third-party/vendor solutions
  • Cloud and research environments
  • Provide subject matter expertise and mentorship to team members supporting assessments and compliance activities
  • Influence decision-making across stakeholders without direct authority

Regulatory & Audit Support
  • Support internal and external audit activities by providing subject matter expertise, documentation, and control validation
  • Ensure risk assessments and control evaluations align with regulatory expectations and audit requirements
  • Partner with the IT Controls Manager on audit responses and remediation planning
Program Improvement & Innovation
  • Identify opportunities to enhance assessment processes, tooling, and automation
  • Contribute to development of metrics, dashboards, and reporting to measure risk posture and program effectiveness
  • Drive continuous improvement in how risk is identified, assessed, and managed across the enterprise

Minimum Qualifications:
To qualify you must have a Typically requires 10 or more years of experience and BA/BS degree or equivalent

Preferred Qualifications:
Advanced degree desirable

Qualified candidates must be able to effectively communicate with all levels of the organization.

NYU Langone Health provides its staff with far more than just a place to work. Rather, we are an institution you can be proud of, an institution where you'll feel good about devoting your time and your talents.

At NYU Langone Health, we are committed to supporting our workforce and their loved ones with a comprehensive benefits and wellness package. Our offerings provide a robust support system for any stage of life, whether it's developing your career, starting a family, or saving for retirement. The support employees receive goes beyond a standard benefit offering, where employees have access to financial security benefits, a generous time-off program and employee resources groups for peer support. Additionally, all employees have access to our holistic employee wellness program, which focuses on seven key areas of well-being: physical, mental, nutritional, sleep, social, financial, and preventive care. The benefits and wellness package is designed to allow you to focus on what truly matters. Join us and experience the extensive resources and services designed to enhance your overall quality of life for you and your family.


NYU Langone Health is an equal opportunity employer and committed to inclusion in all aspects of recruiting and employment. All qualified individuals are encouraged to apply and will receive consideration. We require applications to be completed online.

View Know Your Rights: Workplace discrimination is illegal.

NYU Langone Health provides a salary range to comply with the New York state Law on Salary Transparency in Job Advertisements. The salary range for the role is $121,792.22 - $210,091.64 Annually. Actual salaries depend on a variety of factors, including experience, specialty, education, and hospital need. The salary range or contractual rate listed does not include bonuses/incentive, differential pay or other forms of compensation or benefits.

To view the Pay Transparency Notice, please click here
Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Lead IT Security Analyst - HIPAA, HITRUST, FISMA in New York, NY vacancy
  • Vytalize is seeking an Epic Security Analyst to manage Epic user access and support HIPAA-related audits. Responsibilities include provisioning user accounts and troubleshooting access issues. The candidate should have a Bachelor’s degree in a relevant field and experience... 
    Suggested

    Vytalize

    Brooklyn, NY
    2 days ago
  • Vytalize Health is seeking an Epic Security Analyst to ensure secure access to Epic applications across the organization. You will manage user roles, support HIPAA audits, and tackle access issues impacting clinical workflows. The ideal candidate holds a Bachelor's in... 
    Suggested

    Vytalize Health

    Brooklyn, NY
    4 days ago
  •  ...Delmock Technologies, Inc. (DTI), is a leading HUBZone business in Baltimore, known for delivering sophisticated IT (Information Technology) and Health...  ...Responsibilities Implement and assess security controls in accordance with FISMA, FedRAMP, IRS IRM 10.8, and National... 
    Suggested
    For contractors
    Local area
    Remote work

    Page Mechanical Group, Inc.

    New York, NY
    2 days ago
  • We are looking for an IT Security Analyst to help protect enterprise systems, data, and cloud environments from emerging threats. This role focuses...  ...frameworks and regulatory standards (e.g., NIST, ISO, HIPAA, GDPR). Working knowledge of identity and access management,... 
    Suggested

    The Phoenix Group

    New York, NY
    1 day ago
  •  ...Role: IT Security Analyst Location: NYC, NY ( Hybrid Role ) Job Description The Security analyst is an integral part of the Client team. The Security Analyst is responsible for the day -to -day administration and maintenance of IT security systems... 
    Suggested
    Flexible hours

    ACI Infotech

    New York, NY
    2 days ago
  •  ...other scanning tools. Web application scanning and web application firewalls. Containers. CIS benchmarks, STIGs, or other security hardening standards. Additional Desirable Skills Or Experience SAML, Kerberos, OAuth, OIDC, LDAP. Powershell and... 

    The Dignify Solutions, LLC

    New York, NY
    2 days ago
  •  ...the world that we serve. The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted...  ...with any PAM solution or IGA. ~ Demonstrated interest in IT security, particularly in access management and privileged account... 
    Internship
    Remote work
    Flexible hours

    Dtcc

    Jersey City, NJ
    14 days ago
  •  ...Lead Security Analyst The Lead Security Analyst will report directly to the Chief Risk Officer. The individual will be responsible for monitoring...  ...with minimal supervision, interact effectively with IT, Security, and Business leaders. Key Responsibilities:... 
    Full time

    Allen Rose Group

    New York, NY
    9 days ago
  • Overview Position Title: Epic Security Analyst - Remote Department: IT Information Security Location: This position may be performed remotely from the United...  ...management processes to meet functional requirements. Lead efforts to optimize performance and usability of the EHR... 
    Remote job
    Full time
    Relocation

    OU Medicine

    Brooklyn, NY
    4 days ago
  • Tallahassee, Orlando, Jacksonville, Miami and Tampa Job Summary Join our team as an IT Security Manager, where you will develop and manage security across multiple IT functional areas, such as data, systems, network, and Web operations. In this role, you will assist in... 
    Work experience placement
    Flexible hours

    Cook Systems

    New York, NY
    3 days ago
  • $100k - $130k

    A leading cybersecurity firm is seeking a proactive Security Analyst to join their team in the United States. This role involves monitoring security alerts, responding to incidents, and developing threat detection capabilities. The ideal candidate will have 4-6 years of... 
    Remote job

    BLACKCLOAK

    New York, NY
    3 days ago
  • $226k - $275k

     ...Nayya, located in New York, is seeking a Director of Security & IT to lead their security strategy and compliance programs. The role involves...  ...years in security and compliance, with notable experience in HIPAA guidelines. Nayya offers a salary range of $226,000 to $275,... 

    Nayya

    New York, NY
    4 days ago
  • Senior Consultant - Epic Security Analyst - Remote Join to apply for the Senior Consultant - Epic...  ...documentation, and optimization suggestions. Lead meetings regarding project status and on...  ...Information Technology Industries IT Services and IT Consulting Referrals increase... 
    Remote job
    Full time
    Contract work
    Local area

    Nordic Global

    New York, NY
    3 days ago
  • IT Security Analyst Associate Position Summary: Monitor UGA network for unauthorized traffic and/or vulnerabilities using a variety of network‑based and server‑based tools. Work with UGA clients to remedy network vulnerabilities and to secure network segments. Write and... 
    Full time
    Monday to Friday

    University of Georgia

    Brooklyn, NY
    5 days ago
  •  ...Senior IT Information Security Operations Specialist Welcome to PGMTEK, Inc where we help candidates find the opportunities that best match...  ...Senior IT Information Security Operations Specialist for a leading international banking institute in New York City. This role... 
    Full time

    PGMTEK Inc.

    New York, NY
    2 days ago
  • OU Medicine is seeking an Epic Security Analyst to join their IT Information Security department. This position can be performed remotely from selected states in the United States, including Oklahoma. Key responsibilities include resolving technical issues, providing end... 
    Remote job

    OU Medicine

    Brooklyn, NY
    4 days ago
  • $128k - $160k

    The Information Security Analyst III is a key member of the Security Operation Center (SOC) team...  ...detection or visualizations. Represent IT Security on incident bridges or other security...  ...of the Security Operations Center Lead. Develop and document processes and procedures... 
    Temporary work
    Work experience placement
    Work at office

    Dechert LLP

    New York, NY
    5 days ago
  • Velera Solutions, LLC is seeking a Senior IT Security Compliance Analyst to lead technology compliance efforts. Responsibilities include consulting on control design, maintaining IT controls, and supporting audits. Candidates should have a Bachelor's degree in a relevant... 
    Remote job

    Velera Solutions, LLC

    New York, NY
    2 days ago
  • $102.6k - $179.25k

     ...About the Role: As a Senior IT Security Analyst, you will engage in advanced cybersecurity tasks with a high level of autonomy. Your contributions...  ...advanced threat detection and monitoring activities. • Lead detailed security audits and forensic investigations. •... 
    Work at office

    Wolters Kluwer N.V.

    New York, NY
    5 days ago
  •  ...Job Description Job Description Sr Cloud Security Analyst The Sr Cloud Security Analyst plays a key role in advancing the organization...  ...equivalent professional experience. ~4–6 years of combined IT and security experience, including exposure to systems analysis... 

    RennerBrown Staffing

    Secaucus, NJ
    12 days ago
  •  ...Description This is a contract to hire opportunity The Cloud Security Analyst will support the organization’s cloud security program by...  ...equivalent work experience. Typically has 4 to 6 years of combined IT and security work experience with a broad range of exposure to... 
    Contract work
    Work experience placement

    RennerBrown Staffing

    Secaucus, NJ
    12 days ago
  • Euclid in New York is seeking a Business Analyst to track project deliverables for multiple security initiatives. The successful candidate will work closely with IT Security and partners to manage objectives, milestones, and ensure timely completion of deliverables. Qualifications... 
    Remote job

    Euclid

    New York, NY
    2 days ago
  • A cybersecurity firm is seeking a Cybersecurity/Information Security Analyst to protect organization data from threats and comply with security policies. Responsibilities include monitoring threats, conducting vulnerability assessments, and developing security policies... 
    Remote job

    Bee On The Job

    New York, NY
    3 days ago
  • $91k - $114k

     ...Overall PurposeThe Security Governance, Risk & Compliance Analyst conducts comprehensive...  ...(SOC-2, GLBA, FISMA, PCI-DSS, others).Facilitate...  ..., risk management, IT audit, information...  ...such as: HITRUST, ISO 27001, NIST, PCI...  ...Advisory experience with leading consulting firms... 
    Hourly pay
    Work experience placement
    Work at office
    Immediate start
    Visa sponsorship
    Work visa
    Flexible hours

    Early Warning Services LLC

    New York, NY
    3 days ago
  • $195k - $240k

     ...(TVM Cloud) Senior Cloud Security and Vulnerability Analyst Location New York Business Area Legal, Compliance, and Risk Ref #...  ...Come find yours. What's The Role? We are seeking an IT Security Analyst to help ensure that our Public Cloud IT... 
    Temporary work
    For contractors
    Work experience placement
    Work at office

    Bloomberg

    New York, NY
    3 days ago
  • Job Title Senior Information Security Analyst / Cybersecurity Liaison Job Summary The Senior Information Security Analyst / Cybersecurity Liaison...  ...clients, ensuring the security, efficiency, and compliance of IT systems. This role is responsible for maintaining computer... 
    Full time
    Work at office
    Local area
    Monday to Friday

    Delaware Nation Industries

    Brooklyn, NY
    4 days ago
  • Cyber Security Engineer IV (Senior Security Analyst) Location: Basking ridge, NJ Duration: 10Months+ Extension Hourly Rate: Depending on Experience (DOE) Work Authorization: Bachelor’s degree in computer science or related fields. Eight or more years of relevant work... 
    Hourly pay
    Permanent employment
    Contract work
    Work experience placement
    Local area

    Digital Technologies, LLC

    New York, NY
    2 days ago
  •  ...intelligent insights. The Role The Security Analyst, Information Security is responsible for...  ...27701, ISO 42001, PCI DSS, GDPR, and HIPAA. ~ Understanding of technical...  ...decades-long history of building traditional IT foundations and deep expertise in AI and... 
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area
    Remote work

    Presidio Networked Solutions, LLC

    New York, NY
    7 days ago
  •  ...Your Opportunity We are seeking an Epic Security Analyst who will maintain secure, compliant, and...  ...lifecycle processes while partnering with IT, HR, and Compliance teams. What You Will...  ...with policies Support audits related to HIPAA and internal controls Partner with HR,... 
    Work experience placement

    Vytalize Health

    Brooklyn, NY
    4 days ago
  •  ...Dox Electronics Inc. is looking to add a Security Analyst who is an expert in the use of a variety...  ...recommendations for remediation within IT environments. Penetration testing (Ethical...  ...security engagements including PCI and HIPAA . You will provide expert IT Security... 

    6AM City, LLC

    New York, NY
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead IT Security Analyst - HIPAA, HITRUST, FISMA. Be the first to apply!