Careerscape is recruiting on behalf of our client, a growing healthcare data provider based in Columbus, OH, for an Information Cyber Security Analyst to join their remote team. This is an opportunity to protect sensitive health information at scale, owning vulnerability assessments and compliance audits for an organization whose data integrity directly impacts patient care and provider trust across the healthcare industry.
Day to day, you will spend your time running scans, triaging findings, and translating technical risk into plain language for auditors, engineers, and leadership alike. The role suits someone who is equal parts detail-oriented and pragmatic, comfortable moving between HIPAA compliance documentation in the morning and a live vulnerability remediation conversation with engineering in the afternoon. If you enjoy building repeatable security processes in a mission-driven healthcare environment, this client wants to hear from you.
Responsibilities
Conduct regular vulnerability assessments and penetration test coordination across cloud and on-premise systems
Monitor security alerts and investigate potential incidents in coordination with the IT team
Lead HIPAA and SOC 2 compliance audits and maintain supporting documentation
Develop and update information security policies, standards, and procedures
Track remediation of identified vulnerabilities through resolution with engineering owners
Perform risk assessments on new vendors, systems, and third-party integrations
Maintain security awareness training materials and deliver periodic staff training
Support disaster recovery and business continuity planning efforts
Prepare audit-ready reports and metrics for leadership and external auditors
Stay current on emerging threats and healthcare data security regulations
Requirements
Bachelor's degree in Information Security, Computer Science, or related field, or equivalent experience
Five or more years of experience in information security, IT audit, or a related discipline
Hands-on experience with vulnerability scanning tools such as Nessus, Qualys, or Rapid7
Working knowledge of HIPAA, HITRUST, or SOC 2 compliance frameworks
Familiarity with NIST or ISO 27001 security standards
Strong understanding of network security, firewalls, and endpoint protection
Experience communicating technical risk findings to non-technical stakeholders
Security certification such as CISSP, CISA, Security+, or CEH preferred
Ability to work independently in a fully remote, distributed team environment
Benefits
Medical, dental, and vision insurance
401k with employer match
Generous paid time off and paid holidays
Fully remote position with flexible working hours
Home office equipment and internet stipend
Professional development and certification reimbursement