Lead IT Security Analyst - HIPAA, HITRUST, FISMA

North Shore Bank

• $121K — $210K *
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in IT security or related field
  • Bachelor's degree or equivalent work experience
  • Subject matter expertise in HIPAA, HITRUST, PCI DSS, FISMA
  • Strong communication abilities with all organizational levels
  • Experience with cloud security and risk assessment methodologies

Responsibilities

  • Lead the maturation of the enterprise risk assessment program
  • Conduct complex risk assessments in alignment with regulatory frameworks
  • Define and maintain risk assessment methodologies and scoring models
  • Identify and document risks, developing actionable remediation strategies
  • Evaluate security in cloud and hybrid environments
  • Partner with engineering teams to ensure effective control implementations
  • Support audit activities with expertise and documentation

Benefits

  • Comprehensive benefits and wellness package
  • Access to financial security benefits
  • Generous time-off program
  • Employee resource groups for peer support
  • Holistic wellness program targeting multiple well-being areas
Full Job Description
Job Description

Position Summary:
We have an exciting opportunity to join our team as a Lead IT Security Analyst.

This position reports to the IT Controls & Regulatory Compliance Manager and serves as a senior individual contributor and subject matter expert responsible for leading enterprise risk assessments and evaluating the security of modern technology environments, including cloud-based platforms.

The IT Controls Lead drives the design, execution, and continuous improvement of the organizations risk assessment program to ensure compliance with regulatory and industry requirements, including HIPAA, HITRUST, PCI DSS, and FISMA.

This role partners closely with IT, Security, Clinical, Research, and Compliance stakeholders to assess risk across enterprise systems, research technologies, and cloud infrastructure, and to ensure that security controls are appropriately designed and operating effectively.

Job Responsibilities:

Enterprise Risk Assessment Leadership

  • Lead the execution and maturation of the enterprise risk assessment program aligned to regulatory and industry frameworks


  • Conduct and oversee complex risk assessments, including HIPAA and HITRUST-aligned evaluations


  • Define and maintain risk assessment methodologies, scoring models, and standards


  • Identify, analyze, and document risks, and develop actionable remediation strategies


Cloud Security & Technology Risk Evaluation

  • Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS)


  • Evaluate key control domains, including:


  • Identity and access management


  • Network architecture and segmentation


  • Logging, monitoring, and detection capabilities


  • Data protection and encryption


  • Assess alignment to frameworks such as:


  • HITRUST


  • PCI


  • NIST Cybersecurity Framework


  • ISO/IEC 27001


  • Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments


Research Technology & Clinical Risk Oversight

  • Lead security and risk reviews of research technologies and data use cases, including systems handling sensitive or regulated data


  • Partner with clinical and research stakeholders to evaluate emerging technologies and ensure appropriate risk controls are in place


  • Provide guidance on secure design and data protection strategies


Cross-Functional Leadership & Escalation

  • Serve as a senior escalation point for complex or high-risk assessments across:


  • Enterprise systems

  • Third-party/vendor solutions


  • Cloud and research environments


  • Provide subject matter expertise and mentorship to team members supporting assessments and compliance activities


  • Influence decision-making across stakeholders without direct authority


Regulatory & Audit Support

  • Support internal and external audit activities by providing subject matter expertise, documentation, and control validation


  • Ensure risk assessments and control evaluations align with regulatory expectations and audit requirements


  • Partner with the IT Controls Manager on audit responses and remediation planning


Program Improvement & Innovation

  • Identify opportunities to enhance assessment processes, tooling, and automation


  • Contribute to development of metrics, dashboards, and reporting to measure risk posture and program effectiveness


  • Drive continuous improvement in how risk is identified, assessed, and managed across the enterprise


Minimum Qualifications:
To qualify you must have a Typically requires 10 or more years of experience and BA/BS degree or equivalent

Preferred Qualifications:
Advanced degree desirable

Qualified candidates must be able to effectively communicate with all levels of the organization.

NYU Langone Health provides its staff with far more than just a place to work. Rather, we are an institution you can be proud of, an institution where you'll feel good about devoting your time and your talents.

At NYU Langone Health, we are committed to supporting our workforce and their loved ones with a comprehensive benefits and wellness package. Our offerings provide a robust support system for any stage of life, whether it's developing your career, starting a family, or saving for retirement. The support employees receive goes beyond a standard benefit offering, where employees have access to financial security benefits, a generous time-off program and employee resources groups for peer support. Additionally, all employees have access to our holistic employee wellness program, which focuses on seven key areas of well-being: physical, mental, nutritional, sleep, social, financial, and preventive care. The benefits and wellness package is designed to allow you to focus on what truly matters. Join us and experience the extensive resources and services designed to enhance your overall quality of life for you and your family.

NYU Langone Health provides a salary range to comply with the New York state Law on Salary Transparency in Job Advertisements. The salary range for the role is $121,792.22 - $210,091.64 Annually. Actual salaries depend on a variety of factors, including experience, specialty, education, and hospital need. The salary range or contractual rate listed does not include bonuses/incentive, differential pay or other forms of compensation or benefits.

To view the Pay Transparency Notice, please click here

Similar Jobs

More Jobs at North Shore Bank

More Healthcare Jobs

Find similar Lead IT Security Analyst - HIPAA, HITRUST, FISMA jobs: