Mercy Health

Information Security Analyst

Mercy Health$79K — $122K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Associates degree with 2+ years in IT operations or security roles.
  • Preferred certifications in information or cyber security (e.g., CompTIA Security+).
  • Knowledge of ISO 27001, SOX, HIPAA, HITECH regulatory environments beneficial.
  • Understanding common security vulnerabilities and countermeasures.
  • Ability to perform essential duties with or without accommodation.
  • Must have authorization to work in the U.S. without sponsorship.

Responsibilities

  • Champion effective information security processes across the enterprise.
  • Triage security alerts from various tools (MDR, CRI, XDR).
  • Monitor security systems to identify risk trends and behaviors.
  • Investigate incidents and prepare timely incident reports.
  • Evaluate security notices and make recommendations for remediation.
  • Communicate key metrics measuring security program effectiveness.
  • Actively participate in departmental meetings to promote information security topics.
  • Assist with regulatory compliance audit requests (e.g., SOC, HIPAA).
  • Assess third-party vendor security postures.

Benefits

  • Medical, Dental, Vision insurance options.
  • Life and Disability Insurance coverage.
  • Flexible Spending Account (FSA) and Health Savings Account (HSA) options.
  • Generous paid time off that accrues over time.
  • Paid parental and caregiver leave policies.
  • Opportunities for career advancement and educational growth.
  • Tuition and certification reimbursement programs.
  • Comprehensive well-being programs for employees.
  • Employee discounts on various services.
  • On-demand pay option for increased financial flexibility.
  • Financial education resources available.
  • Annual recognition events to celebrate employee contributions.
  • Community service opportunities to foster social impact.
Full Job Description
ESSENTIAL DUTIES AND RESPONSIBILITIES

  • Serve as a champion for effective information security processes and behaviors across the enterprise.


  • Triage information security alerts generated throughout the information security solution stack (i.e., MDR, CRI, XDR).


  • Monitor systems that support the Mercyhealth information security posture; including, but not limited to, malware detection systems, spyware and adware detection systems, and spam filtering systems to identify trends and behaviors that increase risk.


  • Investigate incidents and create accurate and timely incident reports, escalating to the appropriate persons as necessary.


  • Evaluate bug reports, security exploit reports, and other security notices issued by vendors, manufacturers, government agencies, professional associations, and other organizations as needed, make recommendations to internal management and technical resources to take precaution steps and track remediation.


  • Develop, maintain, and communicate key metrics to measure information security program effectiveness.


  • Represent the information security program through attendance in departmental and team meetings throughout the enterprise to inform, train and promote information security topics.


  • Assist in fulfilling evidence requests in response to regulatory compliance audits (i.e., SOC, HIPAA/HITECH).


  • Evaluate acquired or developed systems and architectures to ensure alignment with Mercyhealth's information security requirements.


  • Conduct regular audits of information systems to ensure compliance with security policies and identify areas for improvement.


  • Assess the security posture of third-party vendors providing products and services to the organization.


  • Identify and develop content to support the information security awareness and training program.


  • Serve as an active, supporting role to the Security Incident Response Team (SIRT) and participate in security incident response efforts.


CULTURE OF EXCELLENCE BEHAVIOR EXPECTATIONS

To perform the job successfully, an individual should demonstrate the following behavior expectations:

Quality - Follows policies and procedures; adapts to and manages changes in the environment; Demonstrates accuracy and thoroughness giving attention to details; Looks for ways to improve and promote quality; Applies feedback to improve performance; Manages time and prioritizes effectively to achieve organizational goals.

Service - Responds promptly to requests for service and assistance; Follows the Mercyhealth Critical Moments of service; Meets commitments; Abides by MH confidentiality and security agreement; Shows respect and sensitivity for cultural differences; and effectively communicates information to partners; Thinks system wide regarding processes and functions.

Partnering - Shows commitment to the Mission of Mercyhealth and Culture of Excellence through all words and actions; Exhibits objectivity and openness to other's views; Demonstrates a high level of participation and engagement in day-to-day work; Gives and welcomes feedback; Generates suggestions for improving work: Embraces teamwork, supports and encourages positive change while giving value to individuals.

Cost - Conserves organization resources; Understands fiscal responsibility; Works within approved budget; Develops and implements cost saving measures; contributes to profits and revenue.

EDUCATION & EXPERIENCE

  • Associates degree and a minimum of two years of professional work experience in IT operations or IT security role.


  • Certifications (e.g., CompTIA Security+) preferred.


  • 1+ years of experience working in at least one of the following regulatory settings: ISO 27001, SOX, HIPAA, HITECH, CLIA, CAP desirable.


  • Knowledge of common security exploits, vulnerabilities, and countermeasures.


  • Demonstrated ability to perform the Essential Duties of the position with or without accommodation.


  • Authorization to work in the United States without sponsorship.


CERTIFICATION/LICENSURE

Information security or cyber security certification(s) is preferred.

ADDITIONAL REQUIREMENTS

Passing the Driver's License Check and/or Credit Check (for those positions requiring).

Must be able to follow written/oral instructions.

OTHER SKILLS AND ABILITIES

  • Demonstrate effective communication and a highly collaborative work ethic.


  • Analyze, identify, and resolve problems using critical thinking.


  • Demonstrates a sense of urgency and a commitment to high standards of ethics, regulatory compliance, customer service and business integrity.


  • Hands-on experience with SIEM implementation and administration.


  • Information security in a public/private cloud infrastructure (Azure, AWS) environment.


  • Completion or coursework toward information security certifications.


INFORMATION ACCESS

Partner may access patient care information, financial data, human resource data and strategic and planning data needed to perform their job duties as directed by the director.

WORK CONTACT GROUP

Partners, physicians, vendors

SPECIAL PHYSICAL DEMANDS

The Special Physical Demands are considered Essential Job Functions of the position with or without reasonable accommodations. While performing the duties of this job, the partner is regularly required to sit and use hands to finger, handle or feel. The partner is occasionally required to stand, walk, or reach with hands and arms; climb or balance and stoop, kneel, crouch, or crawl. The partner must occasionally lift and or move up to 25 pounds. Specific vision abilities required by this job include close vision and color vision.

LEVEL OF SUPERVISION

Requires minimal level of supervision.

SUPERVISES

None.

PAY RANGE:

$79,133.91 - $122,657.57

Mercyhealth offers competitive pay and a comprehensive benefits package including:

  • Medical, Dental, Vision
  • Life & Disability Insurance
  • FSA/HSA Options
  • Generous, accruing paid time off
  • Paid Parental and caregiver leave
  • Career advancement and educational opportunities
  • Tuition and certification reimbursement
  • Certification Reimbursement
  • Well-being Programs
  • Employee Discounts
  • On-Demand Pay
  • Financial Education
  • Annual recognition/awards events
  • Partner appreciation days
  • Family entertainment/attractions discount
  • Community service/improvement opportunities


Click here for more details regarding Mercyhealth Careers Benefit Information.

About Mercy Health

Mercy Health is a Catholic healthcare ministry serving Ohio and Kentucky. They offer a wide range of healthcare services, including primary care, specialty care, and hospital care. Mercy Health operates over 250 healthcare facilities, including hospitals, clinics, and outpatient centers. Their mission is to provide compassionate, quality healthcare to all who need it, regardless of their ability to pay.
Learn more about Mercy Health
Size
45,000 employees
Industry
Founded
1985

Similar Jobs

More Jobs at Mercy Health

More Information Technology Jobs

Find similar Information Security Analyst jobs: