Lead IT Security Analyst - HIPAA, HITRUST, FISMA

NYU Langone HealthNew York, NY
$121,792 - $210,092

About The Position

NYU Langone Health is seeking a Lead IT Security Analyst to join their team. This role reports to the IT Controls & Regulatory Compliance Manager and functions as a senior individual contributor and subject matter expert. The position is responsible for leading enterprise risk assessments and evaluating the security of modern technology environments, including cloud-based platforms. The IT Controls Lead will drive the design, execution, and continuous improvement of the organization's risk assessment program to ensure compliance with regulatory and industry requirements such as HIPAA, HITRUST, PCI DSS, and FISMA. This role involves close collaboration with IT, Security, Clinical, Research, and Compliance stakeholders to assess risk across enterprise systems, research technologies, and cloud infrastructure, ensuring security controls are appropriately designed and operating effectively.

Requirements

  • Typically requires 10 or more years of experience
  • BA/BS degree or equivalent
  • Qualified candidates must be able to effectively communicate with all levels of the organization.

Nice To Haves

  • Advanced degree desirable

Responsibilities

  • Lead the execution and maturation of the enterprise risk assessment program aligned to regulatory and industry frameworks.
  • Conduct and oversee complex risk assessments, including HIPAA and HITRUST-aligned evaluations.
  • Define and maintain risk assessment methodologies, scoring models, and standards.
  • Identify, analyze, and document risks, and develop actionable remediation strategies.
  • Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS).
  • Evaluate key control domains, including: Identity and access management, Network architecture and segmentation, Logging, monitoring, and detection capabilities, Data protection and encryption.
  • Assess alignment to frameworks such as: HITRUST, PCI, NIST Cybersecurity Framework, ISO/IEC 27001.
  • Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments.
  • Lead security and risk reviews of research technologies and data use cases, including systems handling sensitive or regulated data.
  • Partner with clinical and research stakeholders to evaluate emerging technologies and ensure appropriate risk controls are in place.
  • Provide guidance on secure design and data protection strategies.
  • Serve as a senior escalation point for complex or high-risk assessments across: Enterprise systems, Third-party/vendor solutions, Cloud and research environments.
  • Provide subject matter expertise and mentorship to team members supporting assessments and compliance activities.
  • Influence decision-making across stakeholders without direct authority.
  • Support internal and external audit activities by providing subject matter expertise, documentation, and control validation.
  • Ensure risk assessments and control evaluations align with regulatory expectations and audit requirements.
  • Partner with the IT Controls Manager on audit responses and remediation planning.
  • Identify opportunities to enhance assessment processes, tooling, and automation.
  • Contribute to development of metrics, dashboards, and reporting to measure risk posture and program effectiveness.
  • Drive continuous improvement in how risk is identified, assessed, and managed across the enterprise.

Benefits

  • Financial security benefits
  • Generous time-off program
  • Employee resources groups for peer support
  • Holistic employee wellness program (physical, mental, nutritional, sleep, social, financial, and preventive care)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service