3 years of experience in information security, privacy, risk, audit, or related fields.
3 years of experience in a healthcare or regulated environment preferred.
Security+ or equivalent certification strongly preferred.
Familiarity with healthcare security/privacy requirements (e.g., HIPAA/HITECH).
Understanding of security frameworks like NIST CSF.
Responsibilities
Monitor and manage the Information Security team mailbox and ticket queue.
Conduct routine security investigations, including documentation and reporting.
Assist with risk management activities such as assessments and gap analyses.
Support planning and execution of Information Security projects and audits.
Coordinate third-party/vendor risk management activities and evidence collection.
Develop and maintain Information Security policies and procedures.
Contribute to security awareness training and initiatives.
Benefits
Supportive work environment focused on information security.
Opportunities for professional development and training.
Engagement in meaningful work within a healthcare setting.
Collaboration with diverse teams and stakeholders.
Full Job Description
The Information Security Analyst is a key team member in Dana-Farber Cancer Institute's Information Security program. Reporting to the AVP, Information Security Officer, the Analyst supports day-to-day program operations, including routine security investigations, risk management support, training and awareness, and policy maintenance. The Analyst works closely with Information Services teams and other stakeholders to support information security objectives.
Primary Duties and Responsibilities
Monitor and triage the Information Security team mailbox and ticket queue; respond to workforce inquiries, route/escalate as needed, and document, update, and close tickets in accordance with team procedures and SLAs.
Conduct routine information security investigations at the direction of the AVP, Information Security Officer, including documentation, fact-finding, analysis, and summary reporting.
Assist with risk management activities such as surveys, assessments, inventories, and gap analyses against established security and privacy standards.
Support planning, execution, documentation, and follow-up for Information Security projects, audits, and workplans; compile status updates and final summaries for stakeholders.
Assist with third-party/vendor risk management activities, including coordinating evidence collection, completing assessments, and tracking periodic review activities.
Support development, review, and maintenance of Information Security policies and procedures; respond to routine requests for policy interpretation and guidance.
Contribute to security awareness and education efforts, including developing and delivering department-specific training and partnering with Communications to promote awareness initiatives.
Knowledge, Skills and Abilities
Ability to maintain confidentiality and handle sensitive patient, employee, and organizational information with discretion.
Familiarity with healthcare security/privacy requirements (e.g., HIPAA/HITECH and applicable state privacy requirements) and general compliance concepts.
Familiarity with security frameworks and control concepts (e.g., NIST CSF and basic NIST control principles) and how they apply to policies and assessments.
Strong analytical and problem-solving skills; ability to gather facts, identify patterns/trends, and escalate issues appropriately.
Strong documentation skills, including producing clear investigation notes, assessment results, training materials, and stakeholder-ready summaries.
Effective communication skills, including the ability to explain policies and security concepts to non-technical audiences and collaborate across teams.
Strong organizational and time-management skills; ability to manage multiple requests, meet deadlines, and track work to completion.
Minimum Job Qualifications
High school diploma/GED required.
3 years of information security, privacy, risk, audit, or related experience required.
3 years supporting security programs in a healthcare or other regulated environment preferred.
Security+ or equivalent Information Security certification strongly preferred.
License/Certification/Registration Required: None
Supervisory Responsibilities: No
Patient Contact: No
Special Working Conditions:
On call requirements
The hiring range is based on market pay structures, with individual salaries determined by factors such as business needs, market conditions, internal equity, and based on the candidate's relevant experience, skills and qualifications.
For union positions, the pay range is determined by the Collective Bargaining Agreement (CBA).
$76,300.00 - $92,100.00
About Dana-Farber Cancer Institute
Dana-Farber Cancer Institute is a non-profit organization that provides cancer treatment and research services. The institute was founded in 1947 and is affiliated with Harvard Medical School. Dana-Farber Cancer Institute is committed to providing the highest quality care to cancer patients, and is dedicated to finding new treatments and cures for the disease. The institute offers a range of services, including chemotherapy, radiation therapy, and surgery. Dana-Farber Cancer Institute is also involved in a number of research initiatives, and has made significant contributions to the field of cancer research.