
Security Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Assist in IT governance, oversight, risk evaluation, and security awareness within the clinical research framework.
• Execute internal audits and gather evidence to ensure compliance with HIPAA, HITECH, GDPR, and SOC 2.
• Carry out Vendor Risk Management assessments, onboarding, and continuous evaluations for trial sponsors, CROs, and technology partners.
• Conduct Business Impact Analysis and Sensitive Data Reviews for clinical trial data, PHI, and PII.
• Implement User Rights Management and Privileged Access Management reviews for essential applications, including Entra ID, CrowdStrike, and clinical platforms.
• Aid in the assessment, design, and execution of technical controls in line with CIS Controls v8 and NIST CSF v2.
• Identify and propose enhancements for technical controls and processes.
• Collaborate with control owners and system administrators to ensure the effectiveness, consistency, and operability of controls.
• Examine IT systems and tools for suitable controls and processes.
• Analyze test results, assist in addressing IT control deficiencies, and escalate issues to security leadership.
• Verify and revise IT documentation to maintain processes, policies, and controls that are accurate and ready for audits.
• Support incident response initiatives and security operations functions as required.
• Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline.
• Over 3 years of experience in audit, compliance, or technical roles, ideally within healthcare, life sciences, or clinical research sectors.
• Strong understanding of IT security control trends and best practices in auditing and compliance, including HIPAA, SOC 2, and NIST CSF.
• Familiarity with EDR/MDR platforms, SIEM, identity management (Entra ID), and vulnerability management tools.
• Proficient written and verbal communication skills to clearly convey complex IT controls and compliance matters.
• Positive demeanor and a solid dedication to producing high-quality work in a mission-oriented setting.
• Relevant training and/or industry certifications in auditing, compliance, or IT security, such as CISA, CISSP, Security+, or CISM.
• Ability to work Monday through Friday, from 8 am to 5 pm.
• Capacity to meet challenging deadlines and continuously enhance knowledge.
• 401(k) retirement savings plan with employer contribution.
• Eligibility for an annual performance bonus, based on individual and company performance.
• Generous paid time off and paid holidays.
• Comprehensive medical, dental, and vision coverage along with optional insurance choices.
• Company-paid life and disability insurance.
• Employee Assistance Program (EAP) offering confidential, no-cost support for you and your family from day one.
• Flexible FSA and HSA plans.
• A supportive environment that prioritizes balance, well-being, and flexibility.
• Opportunities for continuous learning and professional advancement.
• A collaborative, inclusive, and innovative workplace.
General Dynamics Information Technology
USG
ClickCannabis
Get handpicked remote jobs straight to your inbox weekly.