Back to search
ARSA - Advanced Reconstructive Surgery Alliance Linkedin · Posted yesterday

IT Security Analyst

Red Bank, New Jersey, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Position Summary

ARSA is seeking an IT Security Analyst to serve as the operational engine behind the organization’s cybersecurity program. This role is responsible for executing the annual IT Security Work Plan across a multi-pillar physician management organization supporting approximately 1,000 Microsoft 365 users and a distributed MSP Alliance model. The IT Security Analyst reports to the Director of Information Technology and works closely with the Corporate Compliance team, external MSP and SOC partners, and pillar-level IT stakeholders.


Responsibilities

Risk Assessment & Compliance

  • Conduct and document the annual HIPAA Security Risk Assessment in accordance with 45 CFR §164.308(a)(1).
  • Maintain and update the IT security policy library, ensuring alignment with HIPAA, HITECH, NIST CSF, and organizational requirements.
  • Coordinate and support internal and third-party security audits; track findings through remediation.
  • Support the IT Security Sub-Committee of the Corporate Compliance Committee with documentation, reporting, and follow-up.
  • Assist with vendor risk assessments, BAA review coordination, and third-party security questionnaires.

Microsoft 365 Security & Hardening

  • Administer and harden M365 tenant security settings including Conditional Access policies, Entra ID configurations, Defender for Office 365, Purview, and Intune.
  • Monitor Microsoft Secure Score and implement recommended controls appropriate to ARSA’s risk profile.
  • Support M365 tenant migration and consolidation efforts across the multi-pillar MSP Alliance structure.
  • Manage role-based access control (RBAC), privileged identity management (PIM), and MFA enforcement across tenants.
  • Assist in configuring and reviewing Microsoft Defender alerts, DLP policies, and audit log monitoring.

Security Operations & Incident Response

  • Serve as the internal point of coordination for Tier 1 SOC escalations.
  • Participate in security incident investigations, containment activities, and post-incident documentation.
  • Assist with tabletop exercises and Incident Response Plan (IRP) maintenance.
  • Monitor threat intelligence relevant to healthcare and physician practice environments.
  • Support rogue AI/unauthorized tool detection initiatives in coordination with MSP partners.

Vulnerability Management & Penetration Testing

  • Coordinate and review results from vulnerability scanning (Nessus) and penetration testing (Vohani) engagements.
  • Track remediation of identified vulnerabilities; escalate unresolved critical findings to the IT Director.
  • Work with MSP Alliance partners to ensure consistent vulnerability management practices across pillar environments.

Security Awareness & Phishing

  • Administer the KnowBe4 security awareness platform, including phishing simulations, training campaigns, and reporting.
  • Analyze phishing simulation results; identify trends and recommend targeted training interventions.
  • Support development and delivery of security awareness content for onboarding and annual training requirements.

Azure & Cloud Security

  • Assist in security hardening of Azure services including Key Vault, Private Endpoints, NSG rules, Log Analytics, and AI Foundry configurations.
  • Apply least-privilege access controls and network segmentation standards to new Azure service deployments.
  • Support Entra ID-based authentication requirements and flag SQL authentication or non-compliant credential patterns in vendor integrations.

AI Governance & Security

  • Support the AI tool use case approval process by conducting security and privacy assessments for proposed AI tools, including review of vendor security documentation, BAA status, and data handling practices.
  • Lead and maintain rogue and shadow AI detection efforts, including DNS-layer blocking, port-level controls, and threat hunting coordination with SOC and MSP partners to identify unauthorized AI tool usage across the environment.
  • Evaluate the security posture of agentic and autonomous AI systems, including review of action scope, audit logging, least-privilege access, and PHI exposure risk prior to deployment approval.
  • Monitor approved AI platforms (e.g., Microsoft Copilot, Claude Enterprise) for policy compliance, data handling anomalies, and alignment with CO-IS-AI requirements; escalate findings to the IT Director and Compliance as appropriate.
  • Maintain awareness of emerging AI security threats, attack vectors (e.g., prompt injection, model abuse, data exfiltration via AI interfaces), and evolving regulatory guidance applicable to healthcare AI deployments.

MSP Alliance Coordination

  • Serve as a coordination point between ARSA IT and the nine pillar-level MSPs for security-related projects and initiatives.
  • Track MSP compliance with ARSA security standards; escalate gaps to the IT Director.
  • Participate in MSP Alliance security reviews and assist with MSP onboarding security assessments.

Additional Tasks

  • Contribute to IT security roadmap planning and annual work plan development.
  • Other duties as assigned by the Director of Information Technology.


Qualifications

Required

  • Education: Bachelor’s degree in Information Technology, Cybersecurity, or a related field; or equivalent combination of education and experience.
  • Experience: 3–5 years in IT security, cybersecurity operations, or a related discipline.
  • Working knowledge of HIPAA Security Rule requirements and healthcare security obligations.
  • Demonstrated proficiency in Microsoft 365 administration, including Entra ID, Defender, Purview, and Conditional Access.
  • Familiarity with network security concepts including firewalls, VLANs, segmentation, DNS filtering, and port management.
  • Experience with MFA deployment, privileged access management, and credential hygiene practices.
  • Hands-on experience with vulnerability management tools and remediation tracking.
  • Strong written communication skills; ability to document findings, procedures, and risk assessments clearly.
  • Ability to work independently on multiple concurrent workplan items with minimal supervision.


Certifications

At least one of the following certifications is strongly preferred at hire; ARSA will support attainment of additional certifications through training resources and exam reimbursement. Candidates with strong demonstrated experience and no certifications will be considered.

  • CompTIA Security+
  • Microsoft SC-900 or MS-500 (Microsoft Security, Compliance, and Identity)
  • AZ-500 (Microsoft Azure Security Technologies)
  • HCISPP (HealthCare Information Security and Privacy Practitioner)

Aspirational certifications within 12–18 months of hire: CompTIA CySA+, CISSP Associate.


Compensation and Benefits:

$85,000 – $105,000 annually

the starting rate within this range for this role varies depending on a number of factors, including a candidate’s qualifications, skills, competencies, experience, and location.

  • Medical, Dental, and Vision Insurance (for eligible employees)
  • Health Savings Account (HSA)
  • Life and Long-Term Disability Insurance
  • 401(k) with Profit Sharing
  • Paid Time Off (PTO)
  • Mileage Reimbursement (for applicable travel positions)
  • Employer Contribution Toward Health Insurance Premiums
  • Employee Discounts on Products and Services



Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search