Cyber Security Analyst (Medical Device Security)

Scottish Rite for ChildrenDallas, TX
11dHybrid

About The Position

Seeking a Cyber Security Analyst with a focus on Medical Device Security. This role will serve as the primary liaison between IT, Biomedical Services, Departmental Leadership, and Asset Owners to ensure the cybersecurity of all medical devices. The analyst will coordinate and execute cybersecurity tasks, support compliance initiatives, and manage lifecycle activities for medical devices. The position requires strong cross-departmental communication, project coordination skills, and a solid understanding of both IT/cybersecurity best practices and clinical workflows. Each Cyber Security Analyst is assigned a specific focus area representing their primary domain of expertise and responsibility within the cybersecurity team. For this position, the focus area is Medical Device Security. The analyst will concentrate on safeguarding the hospital’s medical device ecosystem, coordinating cybersecurity tasks, compliance, and lifecycle management for all medical equipment, and serving as the primary liaison between IT, Biomedical Services, and clinical departments. Reviewing inventory of medical devices and identifying cybersecurity risks such as missing patches, outdated software, or configuration weaknesses. Addressing identified risks directly or through vendor/department coordination, ensuring follow-up and risk resolution. Defining and communicating technical requirements for device configuration, VLANs, authentication, and encryption to vendors and departments. Supporting policy and configuration compliance initiatives by aligning device configurations with internal technical control standards. Periodically updating control standards to ensure configurations remain current. Collaborating with GRC and security teams on logging, auditing, access control, risk assessments, and compliance automation. Periodically reviewing medical device inventory to ensure lifecycle management (rounding, end-of-life tracking, replacement planning). Coordinating and delivering cybersecurity awareness and training for medical device stakeholders. Maintaining and reconciling the medical device asset inventory.

Requirements

  • Bachelor’s degree in Cybersecurity/Information Security, Biomedical Engineering (with a focus on Cybersecurity or IT), Computer Science, or related field (or equivalent experience).
  • 5+ years of cybersecurity experience, medical device experience, IT systems experience in healthcare or regulated environments (or equivalent experience).
  • Familiarity with medical device security, FDA cybersecurity guidance, HIPAA, and NIST 800-53/800-171 frameworks.
  • Hands-on experience medical devices and IT systems.

Nice To Haves

  • Certifications such as Security+, CySA+, or CISSP.

Responsibilities

  • Monitoring security alerts, investigate potential threats, and respond to security incidents in collaboration with the SOC and IT operations teams.
  • Conduct regular vulnerability scans, risk assessments, and penetration tests. Analyze results and prioritize remediation efforts.
  • Collect, analyze, and correlate logs from various systems and devices (SIEM tools) to detect anomalous or malicious activity.
  • Assist in developing, maintaining, and enforcing information security policies, procedures, and standards. Support internal and external audits.
  • Support identity and access management (IAM) functions, including privileged access reviews and role-based access control enforcement.
  • Collaborate with infrastructure teams to maintain secure configurations, firewall rules, and endpoint protection policies.
  • Document incidents, root cause analyses, and remediation outcomes. Prepare periodic reports for leadership and compliance.
  • Support organization-wide security awareness initiatives and assist with phishing simulations or targeted education campaigns.
  • Stay informed about emerging cybersecurity threats, technologies, and regulatory requirements. Recommend improvements to enhance organizational resilience.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service