Security Analyst

HealtheConnectionsSyracuse, NY
$70,000 - $85,000Hybrid

About The Position

HealtheConnections, a leader in health information exchange (HIE) services for NYS-based organizations, is seeking a Security Analyst to enhance its enterprise security and compliance program. This role is suited for individuals experienced in information security, governance, risk, compliance, or IT operations who are motivated to build processes, improve security practices, and collaborate across teams to protect sensitive healthcare information. The Security Analyst will play a crucial role in safeguarding health information exchanged daily by providers and organizations across New York State. Responsibilities include coordinating vendor security reviews, supporting regulatory compliance, maintaining risk documentation, tracking remediation efforts, and ensuring audit readiness. The position involves working with internal teams, business partners, and vendors to strengthen security processes within a collaborative, high-performing organization that directly impacts community healthcare. The ideal candidate is organized, proactive, enjoys problem-solving, and excels at creating well-documented, repeatable processes.

Requirements

  • 2–5 years of experience in Information Security, IT Risk, Compliance, Audit, or related field.
  • Working knowledge of HIPAA and healthcare security requirements.
  • Familiarity with security frameworks such as NIST Cybersecurity Framework, HITRUST, OHIP or similar governance frameworks.
  • Experience supporting vendor risk assessments, audit activities, security documentation, or remediation tracking.
  • Strong organizational skills with the ability to manage multiple priorities and follow through on open items.
  • Experience using Microsoft 365, SharePoint, Excel, Jira, Salesforce, Process Street or similar workflow tools preferred.
  • Healthcare or other regulated industry experience is a plus.
  • Security certifications (Security+, CySA+, CISA, CRISC, or similar) or progress toward certification are preferred.
  • Ability to stay organized and manage multiple priorities.
  • Ability to build repeatable processes and maintain detailed documentation.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Ability to think critically and solve problems with a risk-based mindset.
  • Ability to follow through on projects and proactively drive work to completion.
  • Ability to collaborate across departments while maintaining attention to detail.

Nice To Haves

  • Healthcare or other regulated industry experience is a plus.
  • Security certifications (Security+, CySA+, CISA, CRISC, or similar) or progress toward certification are preferred.

Responsibilities

  • Coordinate third-party vendor security reviews and risk assessments.
  • Collaborate with third-party vendors, security partners, and service providers to support security operations, resolve security issues, assess risks, and ensure adherence to organizational security requirements and best practices.
  • Maintain security risk registers, audit documentation, Plans of Action and Milestones (POA&Ms), and remediation tracking to support timely resolution of identified security risks and compliance requirements.
  • Support HIPAA, HITRUST, NIST, OHIP and other security compliance initiatives.
  • Track security vulnerabilities and coordinate remediation with technical teams.
  • Develop and maintain security policies, procedures, and operational documentation.
  • Prepare security metrics, dashboards, and reports.
  • Support security awareness initiatives and organization-wide security communications.

Benefits

  • Medical insurance for employees
  • 401k matching
  • Generous vacation/holiday time
  • Unlimited sick time
  • Flexibility in work hours
  • Hybrid/remote work
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service