Information Security Analyst

MercyhealthFreeport, IL
Onsite

About The Position

Serve as a champion for effective information security processes and behaviors across the enterprise. Triage information security alerts generated throughout the information security solution stack (i.e., MDR, CRI, XDR). Monitor systems that support the Mercyhealth information security posture; including, but not limited to, malware detection systems, spyware and adware detection systems, and spam filtering systems to identify trends and behaviors that increase risk. Investigate incidents and create accurate and timely incident reports, escalating to the appropriate persons as necessary. Evaluate bug reports, security exploit reports, and other security notices issued by vendors, manufacturers, government agencies, professional associations, and other organizations as needed, make recommendations to internal management and technical resources to take precaution steps and track remediation. Develop, maintain, and communicate key metrics to measure information security program effectiveness. Represent the information security program through attendance in departmental and team meetings throughout the enterprise to inform, train and promote information security topics. Assist in fulfilling evidence requests in response to regulatory compliance audits (i.e., SOC, HIPAA/HITECH). Evaluate acquired or developed systems and architectures to ensure alignment with Mercyhealth’s information security requirements. Conduct regular audits of information systems to ensure compliance with security policies and identify areas for improvement. Assess the security posture of third-party vendors providing products and services to the organization. Identify and develop content to support the information security awareness and training program. Serve as an active, supporting role to the Security Incident Response Team (SIRT) and participate in security incident response efforts.

Requirements

  • Associate's degree and a minimum of two years of professional work experience in IT operations or IT security role.
  • Knowledge of common security exploits, vulnerabilities, and countermeasures.
  • Demonstrated ability to perform the Essential Duties of the position with or without accommodation.
  • Authorization to work in the United States without sponsorship.
  • Must be able to follow written/oral instructions.
  • Demonstrate effective communication and a highly collaborative work ethic.
  • Analyze, identify, and resolve problems using critical thinking.
  • Demonstrates a sense of urgency and a commitment to high standards of ethics, regulatory compliance, customer service and business integrity.

Nice To Haves

  • Certifications (e.g., CompTIA Security+) preferred.
  • 1+ years of experience working in at least one of the following regulatory settings: ISO 27001, SOX, HIPAA, HITECH, CLIA, CAP desirable.
  • Hands-on experience with SIEM implementation and administration.
  • Information security in a public/private cloud infrastructure (Azure, AWS) environment.
  • Completion or coursework toward information security certifications.

Responsibilities

  • Serve as a champion for effective information security processes and behaviors across the enterprise.
  • Triage information security alerts generated throughout the information security solution stack (i.e., MDR, CRI, XDR).
  • Monitor systems that support the Mercyhealth information security posture; including, but not limited to, malware detection systems, spyware and adware detection systems, and spam filtering systems to identify trends and behaviors that increase risk.
  • Investigate incidents and create accurate and timely incident reports, escalating to the appropriate persons as necessary.
  • Evaluate bug reports, security exploit reports, and other security notices issued by vendors, manufacturers, government agencies, professional associations, and other organizations as needed, make recommendations to internal management and technical resources to take precaution steps and track remediation.
  • Develop, maintain, and communicate key metrics to measure information security program effectiveness.
  • Represent the information security program through attendance in departmental and team meetings throughout the enterprise to inform, train and promote information security topics.
  • Assist in fulfilling evidence requests in response to regulatory compliance audits (i.e., SOC, HIPAA/HITECH).
  • Evaluate acquired or developed systems and architectures to ensure alignment with Mercyhealth’s information security requirements.
  • Conduct regular audits of information systems to ensure compliance with security policies and identify areas for improvement.
  • Assess the security posture of third-party vendors providing products and services to the organization.
  • Identify and develop content to support the information security awareness and training program.
  • Serve as an active, supporting role to the Security Incident Response Team (SIRT) and participate in security incident response efforts.

Benefits

  • Medical, Dental, Vision
  • Life & Disability Insurance
  • FSA/HSA Options
  • Generous, accruing paid time off
  • Paid Parental and caregiver leave
  • Career advancement and educational opportunities
  • Tuition and certification reimbursement
  • Certification Reimbursement
  • Well-being Programs
  • Employee Discounts
  • On-Demand Pay
  • Financial Education
  • Annual recognition/awards events
  • Partner appreciation days
  • Family entertainment/attractions discount
  • Community service/improvement opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service