Jobs and Careers
DU

Information Security Analyst

Duke University
United Statesfull_timeVerifiedPosted 6 Jan 2025

About the role

At Duke Health, we're driven by a commitment to compassionate care that changes the lives of patients, their loved ones, and the greater community. No matter where your talents lie, join us and discover how we can advance health together.

About Duke Health Technology Solutions

Pursue your passion for caring and innovation with Duke Heath Technology Solutions, which is dedicated to the transformation, development, and management of enterprise information technology solutions across Duke Health. By harnessing the power of innovative technologies like cloud computing and artificial intelligence — and pairing them with a forward-thinking approach — Duke Health Technology Solutions is revolutionizing the future of health care at Duke Health and beyond.

Occupational Summary
The Information Security Analyst provides support for a variety of operational and consultative functions as part of a Duke Information Security Office (ISO). The Information Security Analyst helps design, implement, manage, and monitor technical, administrative, and physical controls to protect the confidentiality, integrity, and availability of the organization's information assets. The Information Security Analyst will carry out these responsibilities in collaboration with IT, clinical, research, and management staff from across Duke.
Duke Health Information Security Office analysts will perform work across multiple domains of information security but will have primary duties assigned specifically from analyst Working Titles. 
Work Performed
This position has the Working Title of Cloud Regulatory Specialist. Duties specific to this position will primarily reside in the Governance and Risk Security Analyst domain with the primary objective of regulatory compliance documentation and assessments of NIST capabilities in a cloud setting. 
Governance and Risk Security Analyst:
•    Vendor risk assessment;
•    Exception management;
•    Security Policy management;
•    Regulatory Compliance aligned with HIPAA, NIST CSF, CIS, and other security frameworks.
IAM Security Analyst:
•    Assists in providing access support for the implementation and administration of IAM supported platforms to include Epic Maestro Care, Active Directory, and disconnected applications;
•    Ensures IAM solutions adhere to regulatory, compliance and internal requirements;
•    Provides Break/Fix and enhancement support following existing change management 
•    Provides guidance on the implementation and usage of IAM capabilities in enterprise systems
Penetration Test Security Analyst: 
•    Conduct comprehensive penetration tests and security assessments of web applications, networks, systems, and infrastructure to identify security vulnerabilities, weaknesses, and exposures;
•    Perform manual and automated penetration testing techniques, including but not limited to network penetration testing, static and dynamic application security testing, and device security testing;
•    Analyze and interpret penetration test results, prioritize identified vulnerabilities based on risk severity, and provide actionable recommendations for remediation;
•    Collaborate with cross-functional teams, including developers, system administrators, and security engineers, to address identified security issues and implement effective security controls and measures;
•    Document and report findings, recommendations, and remediation steps in clear and concise reports tailored to technical and non-technical audiences.
Vulnerability Security Analyst: 
•    Identify and prioritize security vulnerabilities, weaknesses, and exposures based on risk severity, impact, and exploitability;
•    Analyze and interpret vulnerability scan results, including vulnerability assessment reports, scan findings, and threat intelligence feeds, to identify emerging threats and potential security issues;
•    Collaborate with cross-functional teams, including system administrators, network engineers, and software developers, to address identified vulnerabilities and implement appropriate remediation measures and security controls;
•    Monitor and track the progress of vulnerability remediation efforts, escalate critical issues as needed, and ensure timely resolution of identified security risks;
•    Develop and maintain comprehensive documentation, including vulnerability assessment reports and standards, security policies and procedures.
Tools, Architecture and Engineering Security Analyst: 
•    Deploy, configure, and maintain security solutions and tools such as Endpoint Detection & Response, Web Gateway, Vulnerability Management, Data Loss Prevention, etc.;
•    Act as an escalation point for issues, incident

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Duke University

View company profile →