Job DescriptionUW Medicine IT Services has an outstanding opportunity for a
Lead Cyber Security Analyst.
WORK SCHEDULE- 100% FTE
- Monday - Friday; Core hours for UW Medicine IT Services are 8:00 - 5:00 (PST)
- Day Shift
DEPARTMENT DESCRIPTIONUW Medicine IT Services (ITS) is a shared services organization that supports all of UW Medicine. UW Medicine is comprised of Harborview Medical Center (HMC), UW Medical Center-Montlake Campus (UWMC-Montlake), UW Medical Center-Northwest Campus (UWMC-NW), UW Medicine Primary Care (UWMPC), UW Physicians (UWP), UW School of Medicine (SOM), and Airlift Northwest (ALNW). ITS is responsible for the ongoing support and maintenance of the infrastructure and applications which support all these institutions, along with the implementation of new services and applications that are used to support and further the UW Medicine mission.
POSITION HIGHLIGHTS- 100% remote opportunity
- 15 days of vacation your first year - Also, 12 days of sick time, 1 personal holiday, and 11 paid holidays each year
- 100% matching, 100% immediately vesting 403(b)
PRIMARY JOB RESPONSIBILITIES- Supporting the direction and priorities of the Manager by coordinating and overseeing the operational activities and ensuring standard services are meeting appropriate targets, including the following:
- Vulnerability and risk assessment activities with significant impact on business operations for all UW Medicine entities and vendors
- Design, development, and implementation of security tools, platforms, and methodologies drawing from industry requirements and frameworks such as HIPAA, HITRUST, and NIST to identify and mitigate risks to patient care and critical operations
- Implementation and leveraging of prescribed tools to discover system and/or software vulnerabilities and inform and/or validate risk assessments throughout the enterprise
- Integrate threat information into enterprise vulnerability assessments, risk assessments, and mitigation activities
- Operating and updating UW Medicine's risk register and risk management program
- Development and delivery of user training, security awareness programs, and UW Medicine-wide security documentation such as policies, standards, and operating procedures
- Prioritizing and distributing the workload throughout a team of Cyber Security Analysts, managing the day-to-day workflow, and reporting to the Manager the status of work assignments
- Providing a point of escalation for operational and other service issues
- Identifying and proposing service management improvements
- Providing advice, coaching, and mentorship to team on work techniques, best practices, and operational expertise
- Serving as the Manager's delegate to represent the team to customers, project managers, technical leadership, and organizational management
Areas of responsibility include, but are not limited to:- Leading information security service delivery with a continuous improvement mindset and reporting metrics to directly impact business and leadership decisions
- Overseeing team support for applications, infrastructure, and technology projects to ensure the use of secure designs and that technical solution architectures align with organizational risk management goals
- Consulting with technical and non-technical stakeholders, including internal and external entities, on security best practices to reduce the risk of compromise across people, processes, and technology
- Monitoring and developing monitoring to proactively identify and respond to threats, vulnerabilities, or risks within UW Medicine
- Leading efforts to track and mitigate known and emergent threats to UW Medicine to support institutional threat awareness, risk assessments, threat detection and analysis, incident response, and cyber security operations
- Collaborating with Cyber Security Engineers in information security incident triage, containment, and investigative activities, as needed, as part of the incident management process
- Mentoring other Analysts and team members
REQUIREMENTS- Bachelor's degree in Computer Science, Information Technology, Business Administration, or related field or equivalent combination of experience/education
6+ years of experience must include:- 6+ years' information security experience to include experience in several of the following areas: Risk Management, Audit, Compliance, Security Engineering, Project Management, Architecture, and Governance
- 1+ year(s) of formal mentorship for technology professionals
- Demonstrated experience leading team activities and initiatives in designing, implementing, or maintaining security tools (including threat assessment tools, risk management tools, or vulnerability management scanning systems)
- Demonstrated experience leading and mentoring others in security assessments, security control analysis, risk assessments, vulnerability assessments, or penetration tests of highly complex systems that support critical business operations (ex. Patient Care, Finance, HR)
- Advanced understanding of, and the experience mentoring others in, security-related technologies, systems, and tools
- Demonstrated experience using, and the ability to lead a team in, threat modeling and vulnerability review to impact the design of highly interconnected enterprise systems
- Advanced understanding of information security threats and vulnerabilities and how they translate to risks
- Advanced knowledge of common information security regulations and/or standards such as NIST 800-53/CSF, ISO 27001/2, HIPAA, PCI DSS, and SOC and how to apply them
- Demonstrated experience leading service delivery, team activities, and initiatives
Compensation, Benefits and Position DetailsPay Range Minimum:$135,000.00 annual
Pay Range Maximum:$160,008.00 annual
Other Compensation:Benefits:For information about benefits for this position, visit https://www.washington.edu/jobs/benefits-for-uw-staff/
Shift:First Shift (United States of America)
Temporary or Regular?This is a regular position
FTE (Full-Time Equivalent):100.00%
Union/Bargaining Unit:Not Applicable