Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Security Analyst

Physicians Management Group LLC

Description

PHYSICIANS MANAGEMENT GROUP

JOB DESCRIPTION

IT Security Analyst REPORTS TO: Director of Information Systems

SCHEDULE: HYBRID

GENERAL SUMMARY: Maryland Primary Care Physicians, LLC (MPCP) is an independent, physician-owned network comprised of approximately 100 board certified providers across 10 locations, servicing 130,000 patients. MPCP's operations and financial management are performed by Physicians Management Group, LLC (PMG). The IT Security Analyst is responsible for safeguarding the organization's information systems, data, and infrastructure through proactive risk management, continuous monitoring, and compliance tracking. This role supports the Compliance Manager's formal risk analysis and risk register, contributes to the cybersecurity insurance renewal process, manages the core security toolset, and assists with incident response and breach risk determination. The Analyst also supports HIPAA-aligned access governance and vendor risk oversight for systems and third parties handling electronic protected health information (ePHI), partnering closely with the Director of Information Systems on policy development and overall security posture. The ideal candidate combines strong technical expertise with sound judgment, clear communication, and a proactive approach to identifying and mitigating security risks in a healthcare environment where ransomware, phishing, third-party/vendor compromise, and connected medical device (IoMT) threats are persistent and escalating. Responsibilities span the administrative, physical, and technical safeguards required by the HIPAA Security Rule. This list of duties is representative and not exhaustive; additional responsibilities may be assigned as business needs evolve. SUPERVISION EXERCISED: None. Typical Physical Demands: Requires sitting, some standing, stooping, and stretching. Occasionally may lift up to 30 pounds. Requires sufficient hand-eye coordination and manual dexterity to operate a keyboard, photocopier, telephone, calculator, and other office equipment. Requires normal range of hearing and eyesight to record, prepare, and communicate appropriate reports. Typical Working Conditions: Work is typically performed in a corporate office / clinic setting and could involve contact with staff and/or patients. Hybrid schedule: three days per week on-site and two days remote. Occasional travel to affiliated MPCP locations as needed. On-call availability may be required to support security incident response. Primary Duties/Responsibilities Include but not Limited to: Cyber Insurance & Risk Management Annually analyze changes to cyber insurance requirements and partner with the Director of IS to implement necessary policy, technical, or procedural changes Complete annual attestation forms and applications required for cyber insurance renewal Security Operations & Compliance Monitoring Implement, monitor, and maintain security protocols and controls across the environment Conduct regular user account audits, security group audits, and MFA compliance reviews Coordinate periodic penetration testing and vulnerability assessments with an approved third-party vendor; track and remediate identified deficiencies Manage the security vendor quoting and evaluation process Support the formal HIPAA-aligned risk analysis, including contributing to the risk register and tracking of remediation owners and timelines Verify and maintain encryption standards for ePHI at rest and in transit across endpoints, servers, and email Perform regular review of information system activity – including audit logs, access reports, and security incident tracking reports – to detect unauthorized or anomalous access to ePHI (HIPAA 164.308(a)(1)(ii)(D)) Implement, maintain, and periodically test audit controls that record and examine activity in information systems that contain or use ePHI (HIPAA 164.312(b)) Systems & Tools Management Manage and monitor remote monitoring and management (RMM) tools Manage and monitor SIEM, antivirus, and EDR platforms, including alert triage, mitigation, and incident reporting Support technical incident response activities, including investigation, containment, and coordination with the Compliance Manager on HIPAA breach risk determination and notification requirements Administer and monitor the Proofpoint email security platform Oversee Windows endpoint patch management and compliance reporting Manage firewall rule adjustments as needed to support security requirements Maintain a current inventory of networked, biomedical, and Internet-of-Medical-Things (IoMT) devices that create, store, or transmit ePHI; monitor them for known and exploited vulnerabilities and support network segmentation to isolate high-risk devices Configure and verify technical access controls on systems containing ePHI, including unique user identification, automatic logoff, and emergency access procedures (HIPAA 164.312(a)) Verify that ePHI is backed up, that backups are encrypted and maintained in an offline or immutable form, and that restoration is regularly tested to ensure recovery from ransomware or destructive attacks Policy & Compliance Support Assist the Director of IS and Compliance Manager in developing and maintaining policies and procedures supporting the organization's cybersecurity posture Support development of policies and procedures aligned with HIPAA regulatory requirements and risk management standards Support security controls and audit processes for the Electronic Health Record (EHR) system and all systems containing ePHI Support periodic access reviews for systems containing ePHI to ensure alignment with least-privilege and minimum-necessary access principles Support vendor security risk assessments and due diligence for third parties with access to ePHI, in coordination with the Compliance Manager Confirm that Business Associate Agreements (BAAs) are executed and current for all third parties that create, receive, maintain, or transmit ePHI, in coordination with the Compliance Manager Support physical safeguards and device and media controls, including secure disposal, re-use, sanitization, and tracking of hardware and media containing ePHI (HIPAA 164.310) Support timely provisioning and deprovisioning of access upon hire, role change, and termination, and assist with enforcement of the workforce security and sanction policies for security violations (HIPAA 164.308(a)) Support periodic technical and non-technical evaluations of the security program against the HIPAA Security Rule and maintain required security documentation and evidence for at least six years (HIPAA 164.308(a)(8), 164.316) Business Continuity & Organizational Support Participate in Business Continuity and Disaster Recovery planning, testing, and tabletop exercises Monitor healthcare-specific threat intelligence (e.g., Health-ISAC, HHS HC3, and CISA advisories) and translate relevant alerts into defensive actions Manage and monitor employee security awareness training programs and track completion/compliance Research and attend relevant security conferences, training, and continuing education opportunities Performance Requirements: Maintains cyber insurance attestations, applications, and required policy/control updates on schedule to keep the organization's coverage current and audit-ready Completes user account, security group, and MFA compliance audits on a regular, defined cadence, with findings documented and remediated within established timeframes Ensures penetration testing and vulnerability assessments are scheduled, completed, and tracked to closure, with identified deficiencies remediated according to risk-based timelines Contributes accurate, timely updates to the HIPAA risk register, including clear ownership and remediation timelines for each identified risk Reviews audit logs, access reports, and security incident tracking reports on a consistent basis, escalating unauthorized or anomalous ePHI access promptly Keeps SIEM, antivirus, EDR, and email security (Proofpoint) platforms properly configured and monitored, with alerts triaged and addressed within defined response windows Maintains Windows endpoint patch compliance at or above organizational targets Supports incident response activities with clear, timely documentation and coordination with the Compliance Manager on breach risk determination Maintains a current, accurate inventory of networked, biomedical, and IoMT devices, with known vulnerabilities tracked and addressed Verifies ePHI backup, encryption, and restoration testing occur on schedule, with results documented Supports policy, access review, and vendor risk assessment activities in a manner that meets HIPAA regulatory deadlines and audit expectations Maintains required security documentation and evidence in accordance with the six-year HIPAA retention requirement Participates actively in Business Continuity/Disaster Recovery planning, testing, and tabletop exercises, and maintains accurate supporting documentation and after-action reports Ensures employee security awareness training completion is tracked and reported accurately Demonstrates sound judgment and clear, professional communication when working across IT, compliance, and vendor stakeholders, and escalates issues appropriately and in a timely manner Stays current on cybersecurity threats and technologies through ongoing professional development Knowledge, Skills & Abilities: Demonstrated verbal and written communication skills Demonstrated analytical and problem-solving abilities Ability to work collaboratively across IT and compliance functions while managing competing priorities Microsoft 365 security stack proficiency required, including Entra ID (Azure AD), Exchange Online, Microsoft Defender, Conditional Access, and Purview / Data Loss Prevention (DLP) Required scripting/automation experience, particularly PowerShell Working knowledge of vulnerability management, network segmentation, and backup/recovery practices Education: Bachelor's degree in Computer Science, Information Technology, or related field required Experience: Minimum 3 years of IT experience with a security focus Hands-on experience with SIEM and EDR platforms Experience supporting a healthcare EHR environment strongly preferred Working knowledge of HIPAA rules and regulations Familiarity with the HIPAA Security Rule safeguards (administrative, physical, and technical) and the Breach Notification Rule Exposure to medical device/IoMT security and network segmentation preferred Certifications/License: CompTIA Security+ certification (or greater) required Preferred: an intermediate or healthcare-focused security certification such as CompTIA CySA+, GIAC GSEC, or CISSP Alternative to Minimum Qualifications: None #J-18808-Ljbffr Physicians Management Group LLC

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the IT Security Analyst in Maryland vacancy
  • $94.49k - $131.16k

     ...see what we can achieve. Together.SummaryThe Senior Information Security Analyst is responsible for identifying, investigating, and addressing...  ...for the enterprise. The position will collaborate with the IT department to maintain security controls, which includes tuning... 
    Suggested
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Baltimore, MD
    2 days ago
  • $90k - $100k

     ...Job Title IT Security Analyst Location Baltimore, MD FLSA Status Exempt Department Information Technology (IT) Reports to Director, Information Technology Operations Compensation $90,000 – $100,000 + bonus Position Summary The Baltimore Orioles organization is a storied... 
    Suggested
    Remote work
    Flexible hours

    Baltimore Orioles

    Baltimore, MD
    1 day ago
  •  ...Description PHYSICIANS MANAGEMENT GROUP JOB DESCRIPTION IT Security Analyst REPORTS TO: Director of Information Systems SCHEDULE: HYBRID GENERAL SUMMARY: Maryland Primary Care Physicians, LLC (MPCP) is an independent, physician-owned network comprised of approximately... 
    Suggested
    Work at office
    Remote work
    3 days per week

    Physicians Management Group LLC

    Columbia, MD
    2 days ago
  • $102.5k - $188.9k

     ...grow with confidence, and proactively manage to secure success.Cyber threats continue to evolve, and organizations...  ..., and respond to exploitation activity before it disrupts business operations. As a Cyber Exploitation Analyst, you will support cyber defense efforts by... 
    Suggested
    Work at office

    Deloitte

    Baltimore, MD
    5 days ago
  • $115k - $170k

    SummaryThe MIL Corporation is seeking an Offensive Security Engineer, Intermediate (Security Engineering, Senior Analyst) to support the daily operations of the Naval Aviation Red Team. The successful candidate will serve at the Naval Air Station Patuxent River, MD. This... 
    Suggested
    Full time
    Contract work
    Work experience placement
    Local area

    MIL Corporation

    Lexington Park, MD
    4 days ago
  •  ...Job Title: RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF IT Security Analyst serves as a mid-level cybersecurity... 
    Permanent employment
    Local area
    Remote work

    System One

    Bethesda, MD
    15 days ago
  •  ...Job Description Job Description We are seeking a Computer Security Analyst to become an integral part of our team! You will analyze data...  ...company revenue and efficiency. Responsibilities: Analyze IT environments for compliance with NIST security controls.... 

    Trubest Enterprise Solutions LLC

    Annapolis, MD
    28 days ago
  • $89.9k - $134.9k

     ...impossible. Our employees are not only part of history, they're making history.Northrop Grumman is seeking a Principal Industrial Security Analyst 3/CPSO. This CPSO position, for the support of a program(s) as it relates to all applicable classified federal, contractual,... 
    Full time
    Work experience placement
    Relocation
    Shift work

    Northrop Grumman

    Baltimore, MD
    4 days ago
  • $89.9k - $134.9k

     ...Expand your horizons, advance your career, and contribute to a secure future for generations. Northrop Grumman’s Space Sector invites...  ...pioneering spirit to our collaborative teams. As an Industrial Security Analyst - Level 3 or 4 located in Linthicum, MD, you’ll be a linchpin... 
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Relocation
    Shift work

    Northrop Grumman

    Linthicum, MD
    4 days ago
  • $72.4k - $108.6k

     ...Industrial Security Analyst II / CPSO Relocation assistance: No relocation assistance available. Clearance required: Yes (Top Secret). Travel: Yes, 10% of the time. Overview The role supports program(s) by applying classified federal, contractual, customer, and company... 
    Work experience placement
    Relocation
    Shift work

    Northrop Grumman

    Baltimore, MD
    4 days ago
  • $65k - $75k

     ...Junior Program Protection Security Analyst Aether Aerospace is currently seeking a Program Protection Security Analyst, Junior level, to support our government customer on NAS Patuxent River. Overview: TSA is currently seeking a Program Protection Security Analyst, Junior... 
    For contractors
    Work at office
    Local area

    Technology Security Associates

    Annapolis, MD
    3 days ago
  •  ...on this job and more exclusive features. FirstDiv is seeking a Security Analyst III to support security operations and classified information...  ...Employment type Full-time Job function Job function Other Industries IT Services and IT Consulting Referrals increase your chances of... 
    Full time
    For contractors
    Work at office
    Local area

    First Division Consulting Inc

    Edgewood, MD
    1 day ago
  •  ...The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure... 
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Maryland
    5 days ago
  •  ...As a Personnel Security Analyst, you will provide personnel security support and resolution of issues of low and medium complexity in a collaborative team office environment. In this role, you will assist the Government in operating a responsive and professional call... 
    Work at office

    Xcelerate Solutions

    Aberdeen, MD
    2 days ago
  •  ...advisory firm. We work with executives and nonprofit leaders to align IT solutions with business goals and strategy. Since Hartman does...  .... Summary Hartman Executive Advisors is seeking an information security professional in the Baltimore/Washington-Metropolitan region... 
    Full time
    Temporary work

    Hartman Executive Advisors

    Baltimore, MD
    3 days ago
  •  ...Anthropic is seeking a Safeguards Enforcement Analyst on the account abuse team to build and run enforcement workflows that keep our products safe. You will focus on detecting harm and shaping policy layers for access controls and identity verification, operating at the... 

    Anthropic

    Fort Washington, MD
    12 hours ago
  •  ...X-energy in Rockville, Maryland is seeking a qualified Plant Security Analyst to support the development and implementation of the Physical Protection Program for the Xe-100 plant. This includes security planning for construction and the oversight of access programs.... 
    Full time

    X Energy, LLC

    Rockville, MD
    12 hours ago
  • $40 per hour

    A cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. This role allows you to work remotely on your own schedule, contributing directly to the improvement of AI systems. Candidates... 
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Annapolis, MD
    3 days ago
  • $135k - $153k

     ...Security Lead Analyst Job Description *This position is contingent upon award. At iCallidus, we are innovators harnessing the power of creative thinkers to develop, execute, and manage groundbreaking IT solutions. Our multidisciplinary team excels in cybersecurity, digital... 
    Permanent employment
    Full time
    Temporary work

    iCallidus Inc

    Columbia, MD
    2 days ago
  • $40 per hour

     ...cybersecurity firm seeks experienced cybersecurity professionals for a remote position. The role involves evaluating AI-generated security content, solving technical cybersecurity problems, and improving AI models. Candidates should have 2+ years of experience in various... 
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Annapolis, MD
    3 days ago
  • $60k

     ...inquiries from the customer base in a timely manner.You will provide exceptional custo... Show more Full-time We are seeking a Senior Security Analyst to join a team of mission-focused professionals.This role is pivotal in safeguarding and strengthening the security posture of... 
    Hourly pay
    Full time
    Contract work
    Temporary work
    Part time
    For contractors
    H1b
    Work at office
    Work from home
    Flexible hours
    Shift work
    Night shift

    Apex Systems

    Riverdale, MD
    12 hours ago
  •  ...Standard job duties include: Receive and process contractor, licensee, and employee clearance or access requests. Pre-screen all security forms to ensure accuracy. Conducting on-line credit checks, Federal Bureau of Investigation Fingerprint (FBIF) checks, Personnel Investigations... 
    For contractors
    Work at office

    AQIWO

    Rockville, MD
    2 days ago
  •  ...Our client, a leading organization in digital security and identity management, is seeking a Senior Infrastructure Operations Analyst - Identity Access Management to join their team. As a Senior Infrastructure Operations Analyst, you will be instrumental in safeguarding... 
    Weekly pay
    Temporary work
    Flexible hours

    ManpowerGroup Global, Inc.

    Owings Mills, MD
    12 hours ago
  •  ...to talk with you regarding the next step in your career. Come join our team! Zantech is looking for a talented Information Security Analyst - SME to provide specialized cybersecurity expertise supporting risk management operations, conduct security assessments, implement... 
    Remote job
    Full time
    Contract work

    Zantech-it

    Camp Springs, MD
    12 hours ago
  •  ...The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response...  ...background investigation requirements appropriate to a federal IT environment. Ability to work effectively as part of a 24... 
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Maryland
    1 day ago
  •  ...spectrum of services that go beyond traditional IT support. Our portfolio now includes...  ...marketing, data analytics, compliance, security solutions, and cloud expertise. As a dynamic...  ...with functional managers, engineers, and analysts. Klik Solutions complies with all federal... 
    Local area

    Klik Holdings

    Baltimore, MD
    1 hour ago
  • $72k - $90k

     ...clients' most complex challenges. Position Overview: The Security Analyst supports customer engagements by helping to deliver business...  ...functional teams (security engineers, architects, compliance, IT, and business stakeholders) to deliver security projects on time... 
    Full time
    Remote work
    Shift work

    World Wide Technology

    Adelphi, MD
    1 day ago
  • $140k - $195k

     ...Job Summary This role supports Plant Security management in developing, implementing, and overseeing the Physical Protection Program for the Xe-100 plant. Responsibilities include security planning for construction, managing Access Authorization and Fitness for Duty programs... 
    For contractors
    Local area
    Monday to Friday

    X Energy, LLC

    Rockville, MD
    4 days ago
  • $117.2k - $176.7k

     ...emerging technologies to enhance delivery of your work product. Additionally, accountable for advising business partners on adopting new security requirements. This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual... 

    Salesforce.Com Inc

    Baltimore, MD
    5 days ago
  •  ...Senior Information Security Analyst As a Senior Information Security Analyst, you will be a key member of our security team, responsible...  ...enablement. Requirements: ~5-7 years of work experience in IT in one or more areas of infrastructure, application... 
    Contract work
    Work experience placement
    Work at office
    2 days per week

    Accede Solutions Inc.

    Columbia, MD
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Security Analyst. Be the first to apply!