Senior Information Security Analyst in Information Services

📁
Information Technology
💼
UTHealth Houston General Administration
📅
2500008U Requisition #

Position Summary:

Responsible for designing, implementing, and monitoring the IT security program with a focus on identifying server/web vulnerabilities, security awareness, Identity and Access Management (IAM), and implementation of information security solutions in support of the Information Security program and other supervisory responsibilities as assigned.

Your work location will be on the eighth floor of the University Center Tower. Some work can be done remotely, but this is a hybrid position – there will also be a need for the employee to meet with researchers throughout the university, which will involve going to their specific labs/work locations, which may be outside of the UCT building.

What we do here changes the world. UTHealth Houston is Texas’ resource for healthcare education, innovation, scientific discovery, and excellence in patient care. That’s where you come in.

Once you join us, you won't want to leave. It’s because we reward our team for the excellent service they provide. Our total rewards package includes the benefits you’d expect from a top healthcare organization (benefits, insurance, etc.), plus:  

  • 100% paid medical premiums for our full-time employees  
  • Generous time off (holidays, preventative leave days, both vacation and sick time – all of which equates to around 37-38 days per year) 
  • The longer you stay, the more vacation you’ll accrue! 
  • Longevity Pay (Monthly payments after two years of service) 
  • Build your future with our awesome retirement/pension plan! 

We take care of our employees! As a world-renowned institution, our employees’ well-being is important to us. We offer work/life services such as... 

  • Free financial and legal counseling 
  • Free mental health counseling services 
  • Gym membership discounts and access to wellness programs 
  • Other employee discounts include entertainment, car rentals, cell phones, etc. 
  • Resources for child and elder care 
  • Plus many more! 

Position Key Accountabilities:

Essential Functions

  • Provides technical leadership and support in selecting, configuring, and maintaining security and IAM software, utilities, and hardware.
  • Manages projects and supervises Information Security Staff and/or resources relating to departmental projects and key initiatives as the Chief Information Security Officer requires.
  • Maintains current understanding of IT audit techniques, information security, and IAM best practices, policies, and procedures, including Federal, State, and other applicable regulatory requirements and guidelines (HIPAA, FERPA, NIST, PCI DSS, TAC 202).
  • Evaluates cost-effective alternatives to current information security program components.
  • Participates in annual review of all information security policies, standards, procedures, and guidelines; recommends amendments; assures alignment with current regulatory requirements.
  • Monitors and enforces compliance with information security policies, standards, procedures, and guidelines.
  • Responsible for developing, implementing, and maintaining an ongoing IT security awareness and employee training program for the entire UTHSC-H.
  • Conducts risk and security assessments, facilitates disaster recovery planning, and supports business continuity efforts for business-critical systems. Evaluates results with system owners and custodians.
  • Provides information security consulting on a variety of technologies and processes.
  • Performs periodic penetration tests and vulnerability scans. Review results for evidence of vulnerability or compromise; assist in or facilitate the implementation of resolution. Track the solution of findings and prepare reports.
  • Manages enterprise configuration/vulnerability management program, web application firewalls, and security scans to identify and correct security gaps. Prepares remediation reports and provides technical mentorship and guidance for various levels of operations staff.
  • Participates in, develops, and facilitates activities in support of Computer Security Incident Response Team (CSIRT) efforts. Coordinates initial assessments, including severity, potential impact, and resolution efforts with fellow CSIRT members.
  • Provides guidance on integrating IAM tools and automation into new and existing applications.
  • Works with clinical, academic, and administrative application groups to design, develop, and deploy IAM integration and automation solutions with minimum supervision.
  • Provides support for enterprise account life-cycle management, including account provisioning, account de-provisioning, authentication, and authorization.
  • Provides support, configuration, and maintenance for the IAM infrastructure, including, but not limited to, IDM, AM, SSO, Federated Authentication, LDAP, IAM application development, and support tools.
  • Provide support for the Public Key Infrastructure system and process.
  • System administration for a variety of Linux and Windows-based servers to support security and IAM tools.
  • Monitors system log information for evidence of compromise; responds to and reports security incidents.
  • Provides forensic analysis and support for compliance and other security-related investigations; provides summary analysis as necessary.
  • Initiates and participates in periodic security audits and test controls, prepares reports, and makes recommendations as necessary.
  • Performs other duties as assigned.

Certification/Skills:

  • Complex problem-solving skills; ability to think independently as well as work in a dynamic team group.
  • Ability to work within tight deadlines; strong organizational skills.
  • Excellent verbal and written communication skills.
  • Ability to configure and administer Windows and VMware servers and desktops.
  • Working knowledge of UNIX-based systems.
  • Web application security; programming, Linux system administration, database administration.
  • Network architecture design; incorporating security into SDLC.
  • Training in information technology is required.
  • CISSP Certified Information Systems Security Professional preferred
  • Certified Information Systems Auditor (CISA) preferred
  • CISM - Certified Information Security Manager preferred

Minimum Education:

Bachelor's Degree required May substitute required education with equivalent years of experience beyond the minimum experience requirement.

Minimum Experience:

2 years of experience in information technology support or information technology auditing required 1 year to two years of direct involvement with security platforms deployed as part of an enterprise-level information security program required

Physical Requirements:

Exerts up to 50 pounds of force occasionally and/or up to 20 pounds frequently, and/or up to 10 pounds constantly to move objects.

Security Sensitive:

Security Sensitive: This job class may contain positions that are security sensitive and thereby subject to the provisions of Texas Education Code § 51.215

Residency Requirement:

Employees must permanently reside and work in the State of Texas.

If you are looking for a great healthcare career in Houston, visit http://go.uth.edu/careers!

University of Texas Health Science Center at Houston (UTHealth)

Established in 1972 by The University of Texas System Board of Regents, The University of Texas Health Science Center at Houston (UTHealth) is Houston’s Health University and Texas’ resource for health care education, innovation, scientific discovery and excellence in patient care. The most comprehensive academic health center in the UT System and the U.S. Gulf Coast region, UTHealth Houston is home to schools of biomedical informatics, biomedical sciences, dentistry, nursing and public health and the John P. and Kathrine G. McGovern Medical School. UTHealth Houston includes The University of Texas Harris County Psychiatric Center, as well as the growing clinical practices UT Physicians, UT Dentists and UT Health Services. The university’s primary teaching hospitals are Memorial Hermann-Texas Medical Center, Children’s Memorial Hermann Hospital and Harris Health Lyndon B. Johnson Hospital.

UTHealth Benefits

UTHealth Houston offers a comprehensive and competitive benefits package. For more information on our benefits programs please refer to the UTHealth Houston Office of Benefits Website.


https://www.uth.edu/benefits/

Equal Employment Opportunity Statement

UTHealth Houston is committed to providing equal opportunity in all employment-related activities without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, genetic information, gender identity or expression, veteran status or any other basis prohibited by law or university policy. Reasonable accommodation, based on disability or religious observances, will be considered in accordance with applicable law and UTHealth Houston policy. The University maintains affirmative action programs with respect to women, minorities, individuals with disabilities, and eligible veterans in accordance with applicable law.


UTHealth Houston has adopted a policy consistent with CMS regulations to protect our patients and university community from exposure to COVID-19. This policy affects all employees, residents, fellows, students, contractors, new hires, visiting scholars program participants, adjunct faculty, and volunteers who work, train, or collaborate at the John S. Dunn Behavioral Science Center.
 
In addition, all UTHealth Houston ​​​​​​​employees who are assigned to work at a location that is subject to the affiliated partner’s hospital, clinical offices, or agency are required to abide by UTHealth’s Houston rules and regulations, as well as the affiliate’s rules and regulations, including COVID-19 vaccination and safety requirements. 


Work location is based on the needs of the department and may be adjusted.

Forbes Best-in-State Employers

Previous Job Searches

My Profile

Create and manage profiles for future opportunities.

Go to Profile

My Submissions

Track your opportunities.

My Submissions

Similar Listings

McGovern Medical School at UTHealth Houston

Texas Medical Center-Houston, Texas

📁 Information Technology

Requisition #: 25000060

McGovern Medical School at UTHealth Houston

Texas Medical Center-Houston, Texas

📁 Information Technology

Requisition #: 25000073

UTHealth Houston School of Biomedical Informatics

Texas Medical Center-Houston, Texas

📁 Information Technology

Requisition #: 240002RT