IT Security Analyst
Physicians Management Group LLC
Job Description
Job Description
Description:
PHYSICIANS MANAGEMENT GROUP
JOB DESCRIPTION
IT Security Analyst
REPORTS TO: Director of Information Systems
SCHEDULE: HYBRID
GENERAL SUMMARY: Maryland Primary Care Physicians, LLC (MPCP) is an independent, physician-owned network comprised of approximately 100 board certified providers across 10 locations, servicing 130,000 patients. MPCP's operations and financial management are performed by Physicians Management Group, LLC (PMG). The IT Security Analyst is responsible for safeguarding the organization's information systems, data, and infrastructure through proactive risk management, continuous monitoring, and compliance tracking. This role supports the Compliance Manager's formal risk analysis and risk register, contributes to the cybersecurity insurance renewal process, manages the core security toolset, and assists with incident response and breach risk determination. The Analyst also supports HIPAA-aligned access governance and vendor risk oversight for systems and third parties handling electronic protected health information (ePHI), partnering closely with the Director of Information Systems on policy development and overall security posture. The ideal candidate combines strong technical expertise with sound judgment, clear communication, and a proactive approach to identifying and mitigating security risks in a healthcare environment where ransomware, phishing, third-party/vendor compromise, and connected medical device (IoMT) threats are persistent and escalating. Responsibilities span the administrative, physical, and technical safeguards required by the HIPAA Security Rule. This list of duties is representative and not exhaustive; additional responsibilities may be assigned as business needs evolve.
SUPERVISION EXERCISED: None.
Typical Physical Demands: Requires sitting, some standing, stooping, and stretching. Occasionally may lift up to 30 pounds. Requires sufficient hand-eye coordination and manual dexterity to operate a keyboard, photocopier, telephone, calculator, and other office equipment. Requires normal range of hearing and eyesight to record, prepare, and communicate appropriate reports.
Typical Working Conditions: Work is typically performed in a corporate office / clinic setting and could involve contact with staff and/or patients. Hybrid schedule: three days per week on-site and two days remote. Occasional travel to affiliated MPCP locations as needed. On-call availability may be required to support security incident response.
Primary Duties/Responsibilities Include but not Limited to:
Cyber Insurance & Risk Management
- Annually analyze changes to cyber insurance requirements and partner with the Director of IS to implement necessary policy, technical, or procedural changes
- Complete annual attestation forms and applications required for cyber insurance renewal
Security Operations & Compliance Monitoring
- Implement, monitor, and maintain security protocols and controls across the environment
- Conduct regular user account audits, security group audits, and MFA compliance reviews
- Coordinate periodic penetration testing and vulnerability assessments with an approved third-party vendor; track and remediate identified deficiencies
- Manage the security vendor quoting and evaluation process
- Support the formal HIPAA-aligned risk analysis, including contributing to the risk register and tracking of remediation owners and timelines
- Verify and maintain encryption standards for ePHI at rest and in transit across endpoints, servers, and email
- Perform regular review of information system activity – including audit logs, access reports, and security incident tracking reports – to detect unauthorized or anomalous access to ePHI (HIPAA 164.308(a)(1)(ii)(D))
- Implement, maintain, and periodically test audit controls that record and examine activity in information systems that contain or use ePHI (HIPAA 164.312(b))
Systems & Tools Management
- Manage and monitor remote monitoring and management (RMM) tools
- Manage and monitor SIEM, antivirus, and EDR platforms, including alert triage, mitigation, and incident reporting
- Support technical incident response activities, including investigation, containment, and coordination with the Compliance Manager on HIPAA breach risk determination and notification requirements
- Administer and monitor the Proofpoint email security platform
- Oversee Windows endpoint patch management and compliance reporting
- Manage firewall rule adjustments as needed to support security requirements
- Maintain a current inventory of networked, biomedical, and Internet-of-Medical-Things (IoMT) devices that create, store, or transmit ePHI; monitor them for known and exploited vulnerabilities and support network segmentation to isolate high-risk devices
- Configure and verify technical access controls on systems containing ePHI, including unique user identification, automatic logoff, and emergency access procedures (HIPAA 164.312(a))
- Verify that ePHI is backed up, that backups are encrypted and maintained in an offline or immutable form, and that restoration is regularly tested to ensure recovery from ransomware or destructive attacks
Policy & Compliance Support
- Assist the Director of IS and Compliance Manager in developing and maintaining policies and procedures supporting the organization's cybersecurity posture
- Support development of policies and procedures aligned with HIPAA regulatory requirements and risk management standards
- Support security controls and audit processes for the Electronic Health Record (EHR) system and all systems containing ePHI
- Support periodic access reviews for systems containing ePHI to ensure alignment with least-privilege and minimum-necessary access principles
- Support vendor security risk assessments and due diligence for third parties with access to ePHI, in coordination with the Compliance Manager
- Confirm that Business Associate Agreements (BAAs) are executed and current for all third parties that create, receive, maintain, or transmit ePHI, in coordination with the Compliance Manager
- Support physical safeguards and device and media controls, including secure disposal, re-use, sanitization, and tracking of hardware and media containing ePHI (HIPAA 164.310)
- Support timely provisioning and deprovisioning of access upon hire, role change, and termination, and assist with enforcement of the workforce security and sanction policies for security violations (HIPAA 164.308(a))
- Support periodic technical and non-technical evaluations of the security program against the HIPAA Security Rule and maintain required security documentation and evidence for at least six years (HIPAA 164.308(a)(8), 164.316)
Business Continuity & Organizational Support
- Participate in Business Continuity and Disaster Recovery planning, testing, and tabletop exercises
- Monitor healthcare-specific threat intelligence (e.g., Health-ISAC, HHS HC3, and CISA advisories) and translate relevant alerts into defensive actions
- Manage and monitor employee security awareness training programs and track completion/compliance
- Research and attend relevant security conferences, training, and continuing education opportunities
Performance Requirements:
- Maintains cyber insurance attestations, applications, and required policy/control updates on schedule to keep the organization's coverage current and audit-ready
- Completes user account, security group, and MFA compliance audits on a regular, defined cadence, with findings documented and remediated within established timeframes
- Ensures penetration testing and vulnerability assessments are scheduled, completed, and tracked to closure, with identified deficiencies remediated according to risk-based timelines
- Contributes accurate, timely updates to the HIPAA risk register, including clear ownership and remediation timelines for each identified risk
- Reviews audit logs, access reports, and security incident tracking reports on a consistent basis, escalating unauthorized or anomalous ePHI access promptly
- Keeps SIEM, antivirus, EDR, and email security (Proofpoint) platforms properly configured and monitored, with alerts triaged and addressed within defined response windows
- Maintains Windows endpoint patch compliance at or above organizational targets
- Supports incident response activities with clear, timely documentation and coordination with the Compliance Manager on breach risk determination
- Maintains a current, accurate inventory of networked, biomedical, and IoMT devices, with known vulnerabilities tracked and addressed
- Verifies ePHI backup, encryption, and restoration testing occur on schedule, with results documented
- Supports policy, access review, and vendor risk assessment activities in a manner that meets HIPAA regulatory deadlines and audit expectations
- Maintains required security documentation and evidence in accordance with the six-year HIPAA retention requirement
- Participates actively in Business Continuity/Disaster Recovery planning, testing, and tabletop exercises, and maintains accurate supporting documentation and after-action reports
- Ensures employee security awareness training completion is tracked and reported accurately
- Demonstrates sound judgment and clear, professional communication when working across IT, compliance, and vendor stakeholders, and escalates issues appropriately and in a timely manner
- Stays current on cybersecurity threats and technologies through ongoing professional development
Knowledge, Skills & Abilities:
- Demonstrated verbal and written communication skills
- Demonstrated analytical and problem-solving abilities
- Ability to work collaboratively across IT and compliance functions while managing competing priorities
- Microsoft 365 security stack proficiency required, including Entra ID (Azure AD), Exchange Online, Microsoft Defender, Conditional Access, and Purview / Data Loss Prevention (DLP)
- Required scripting/automation experience, particularly PowerShell
- Working knowledge of vulnerability management, network segmentation, and backup/recovery practices
Education:
- Bachelor's degree in Computer Science, Information Technology, or related field required
Experience:
- Minimum 3 years of IT experience with a security focus
- Hands-on experience with SIEM and EDR platforms
- Experience supporting a healthcare EHR environment strongly preferred
- Working knowledge of HIPAA rules and regulations
- Familiarity with the HIPAA Security Rule safeguards (administrative, physical, and technical) and the Breach Notification Rule
- Exposure to medical device/IoMT security and network segmentation preferred
Certifications/License:
- CompTIA Security+ certification (or greater) required
- Preferred: an intermediate or healthcare-focused security certification such as CompTIA CySA+, GIAC GSEC, or CISSP
Alternative to Minimum Qualifications: None
Requirements:$94.49k - $131.16k
...see what we can achieve. Together.SummaryThe Senior Information Security Analyst is responsible for identifying, investigating, and addressing... ...for the enterprise. The position will collaborate with the IT department to maintain security controls, which includes tuning...SuggestedFull timeWork at officeRemote workRelocationVisa sponsorshipRelocation package- ...Network Security Analyst LOCATION Annapolis Junction, MD 20701 CLEARANCE TS/SCI Full Poly (Please note this position requires... ...Analyst, Network Defense Analyst, Threat Intelligence Analyst, IT Security Specialist, Vulnerability Analyst, Incident Response...SuggestedTemporary workFor contractorsImmediate startFlexible hours
$102.5k - $188.9k
...grow with confidence, and proactively manage to secure success.Cyber threats continue to evolve, and organizations... ..., and respond to exploitation activity before it disrupts business operations. As a Cyber Exploitation Analyst, you will support cyber defense efforts by...SuggestedWork at office- ...Description Job Description Position Infrastructure Security Consultant/Infrastructure Security Analyst Duration: 3 years contract role Location:... ...-related field . Solutions Architecture / IT Design: Demonstrated experience with Solutions Architecture...SuggestedFull timeContract workWork experience placement
$55 - $60 per hour
DescriptionPosition Overview The Information Security Analyst II (GRC) provides support for Governance, Risk, and Compliance activities aligned... ...security, risk, or compliance • Bachelor's degree in systems/ IT Security related field • Certified in CISSP, CISM or CRISC -...SuggestedContract workTemporary work$89.9k - $134.9k
...impossible. Our employees are not only part of history, they're making history.Northrop Grumman is seeking a Principal Industrial Security Analyst 3/CPSO. This CPSO position, for the support of a program(s) as it relates to all applicable classified federal, contractual,...Full timeWork experience placementRelocationShift work$72.4k - $108.6k
...impossible. Our employees are not only part of history, they're making history. Northrop Grumman is seeking an Industrial Security Analyst 2/CPSO . This CPSO position, for the support of a program(s) as it relates to all applicable classified federal, contractual,...Work experience placementRelocationShift work- ...Junior Security Analyst The Junior Security Analyst will oversee, evaluate, and support the documentation, validation, and accreditation processes necessary to assure that IT systems meet the organization's security requirements: • Respond to crisis or urgent situations...Immediate start
- ...Location Riverdale, MD Our client is seeking a Security Analyst with a strong security background to lead security assessments, manage and... ...-on and highly cross-functional, partnering with Engineering, IT, Product, and key business stakeholders to identify risk, drive...Permanent employmentFull timeTemporary work
$19 - $20 per hour
...Job Description Job Description Junior Physical Security Specialist TSA is actively hiring for a Junior Physical Security Specialist at NAS Patuxent River to support security administration requirements at various facilities. Duties will include physical and/or industrial...Hourly pay- ...*********CONTINGENT UPON AWARD********************Duties & Responsibilities:Program and Policy Administration:The Security Forces Readiness Analyst will provide on-site analytical support for Duties on War (DoW) and Department of the Air Force (DAF) programs and systems...For contractorsLocal areaRelocation
$100k - $110k
...Job Description Job Description Journeyman Security Program Analyst Overview: Aether Aerospace is seeking a Journeyman Security Program Analyst (Journeyman) to provide administrative, analytical, knowledge management, and security support to the NAVAIR Inspector General...Night shift$45k - $55k
...Job Description Job Description Junior Program Protection Security Analyst Overview: Aether Aerospace is currently seeking a Program Protection Security Analyst, Junior level, to support our government customer at NAS Patuxent River, MD. The candidate must be proficient...$112.2k - $168.2k
...customer and company requirements. The responsibilities include, but are not limited to the following: train and lead several security analysts, manage destruction, security education and awareness, compliance, create, maintain and leverage working relationships with internal...Work experience placementRelocationShift work$112.2k - $168.2k
...Sr. Principal Industrial Security Analyst 4/Lead CPSO RELOCATION ASSISTANCE: No relocation assistance available CLEARANCE REQUIRED FOR START: Yes CLEARANCE TYPE: Secret TRAVEL: Yes, 10% of the Time Description At Northrop Grumman, our employees have incredible opportunities...Work experience placementRelocationShift work- The Johns Hopkins Applied Physics Laboratory is seeking a Modeling & Simulation Analyst in Laurel, MD. The candidate will utilize AFSIM tools to evaluate operations in national security. Key qualifications include a Bachelor's degree in a technical field and at least three...
$72.4k - $108.6k
Industrial Security Analyst II / CPSO Relocation assistance: No relocation assistance available. Clearance required: Yes (Top Secret). Travel: Yes, 10% of the time. Overview The role supports program(s) by applying classified federal, contractual, customer, and company...Work experience placementRelocationShift work$79.16k - $127.67k
...of Business: Technology Solutions Job Description: The Senior Threat Intelligence Analyst defines, develops and/or implements Technology Controls / Information Security related policies, programs, tools and provides specialized expertise and guidance on assessing...Full timeWork experience placementWork at officeLocal areaWork from homeFlexible hours$79.16k - $127.67k
...Line of Business: Technology Solutions Job Description: The Senior Threat Intelligence Analyst defines, develops and/or implements Technology Controls / Information Security related policies, programs, tools and provides specialized expertise and guidance on...Work at officeLocal areaWork from homeFlexible hours- ...advisory firm. We work with executives and nonprofit leaders to align IT solutions with business goals and strategy. Since Hartman does... .... Summary Hartman Executive Advisors is seeking an information security professional in the Baltimore/Washington-Metropolitan region...Full timeTemporary work
$70 - $80 per hour
...Info Security Analyst IV Location: Mount Laurel, NJ Onsite Flexibility: Hybrid — 2 days in office, 3 days work from home (could potentially... ...— including solutions developers, release train strategists, IT specialists, cybersecurity analysts, and compliance...Permanent employmentContract workTemporary workFor contractorsWork at officeWork from homeWork visaMonday to FridayFlexible hoursShift work- ...Senior Information Security Analyst As a Senior Information Security Analyst, you will be a key member of our security team, responsible... ...enablement. Requirements: ~5-7 years of work experience in IT in one or more areas of infrastructure, application...Contract workWork experience placementWork at office2 days per week
- ...Description: Onsite in Fort Meade, MD Our client seeks a Security Analyst serving as an Information Systems Security Officer to lead... ...and maintain applicable NIST 800-53 controls for responsible IT systems. Update System Security Plans semi-annually and document...Hourly payContract workLocal area
- ...defense. Make an impact by connecting and securing critical operations across the globe,... ...Description As an Information Security Analyst Sr Principal, you will be responsible for... ...experience and proven track record supporting IT customers as part of an enterprise...
- ...Description Job Description CyberLinx Solutions is seeking a SOC Analyst (Tier 1) / Security Monitoring Analyst to support our Security Operations... ...SOC procedures. Coordinate with internal security and IT teams when additional investigation is required....
- ...Job Description Job Description iQuasar is seeking to fill an Information Security Analyst IV position. At iQuasar, we strive to provide the next generation of cutting-edge technologies. Our growth means exciting career opportunities for talented professionals in...Contract work
- We are seeking an experienced Info Security Analyst IV to support FIPS 140 validation projects within a hands-on lab environment. This role focuses on security analysis, cryptographic validation testing, product evaluations, automation, and technical reporting in support...Local area
- ...partnering with our clients to improve the lives and ensure the security of all Americans—from soldiers and veteran to kids and the... ...Purpose of Scope: We are seeking an Information Security Analyst who is responsible for providing security support services while...Work experience placementRemote work
- VITG is looking for an Cloud Information Security Analyst (CISA) responsible for taking the lead on implementing security tools, security tool usage, ensuring tools remain compliant and configured properly, setting program policy all the while ensuring a successful program...Full timeWork experience placementWork at officeRemote workShift work
$105.4k - $207.8k
Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative...Work experience placementLocal areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Analyst. Be the first to apply!


