Matrix Medical Network is the nation’s leading independent provider of comprehensive in-home health assessments, serving Medicare Advantage, Managed Medicaid and Commercial patients across all 50 states. With a network of 3,000 + clinicians, we deliver personalized Whole Person Care that includes diagnostic testing, risk identification, medication management and preventive health education, empowering people to better manage acute and chronic conditions. Guided by our mantra - We see you. We hear you. We’ve got you. - and our core values of Integrity, Accountability, Trust, Respect and Passion, we are committed to creating a culture where both patients and teammates feel valued, supported and heard.
Security Audit Analyst
Location
United States
Posted
124 days ago
Salary
0
Seniority
Mid Level
Job Description
Security Audit Analyst
Matrix Medical Network
Overview Security Audit Analyst (Remote) About Us: Matrix Medical Network is a leading clinical services organization that supports the needs of diverse and vulnerable populations, working with millions of individuals across the country to assess and help them manage their health risks through our large network of clinicians. We support Medicare Advantage, Managed Medicaid and Commercial plans; serving populations of all ages, from seniors to other high-risk individuals. Matrix colleagues understand the important role every department plays in helping the members and customers we serve have the best experience possible across all touchpoints. Join our team and help create innovative strategies and solutions to make quality healthcare more accessible! Matrix Medical Network is proud to be a Diversity, Equity, Inclusion and Accountability Employer Why Work at Matrix? - The opportunity to work with one of the fastest growing companies in healthcare whose vision is to provide unparalleled quality and value to providers and members. - A chance to work with great people on exciting projects. - Our opportunities allow you to leverage your expertise and compassion, making a direct impact to the health and well-being of members. - Competitive Compensation: Be rewarded for your effort and passion while making a difference in the community. Responsibilities About the role: Type: Full Time Salaried Compensation: Target $135,000; 10% bonus Location: Fully Remote, must be in the United States Hours: Full Time Days Benefits Offered to include: Medical, Dental, Vision, paid time off, paid holidays, 401K with company matching, voluntary life insurance, short term disability, long term disability, employee assistance program, health savings account, flexible spending accounts, additional voluntary benefits available. What to Expect: The Security Audit Analyst supports Matrix Medical Network’s IT Security and Risk program by performing audits, enforcing policy compliance, and conducting vulnerability assessments. This role plays a key part in entitlement reviews and helps identify opportunities to automate user provisioning, deprovisioning, and access review processes. The analyst will collaborate closely with peers across Information Security, IT Infrastructure, and Business Operations to promote and uphold Matrix’s information security policies, ensuring the effectiveness of security controls. The ideal candidate demonstrates a strong understanding of IT systems, cybersecurity principles, and healthcare compliance, with a keen eye for process improvement and risk mitigation. Responsibilities: - Respond to internal and external inquiries regarding Matrix’s security program, including Client Security Questionnaires, HITRUST CSF Audits, and other regulatory requests. - Conduct and document entitlement reviews, inactivity audits, and other recurring validation activities. - Administer and maintain Identity and Access Management (IAM) tools. - Maintain and enhance audit and control processes to ensure compliance and operational efficiency. - Verify the integrity and effectiveness of Security Operations procedures and IT security controls. - Identify deviations from policies and procedures; communicate critical security control gaps to management. - Analyze vulnerability scan reports and validate the severity of identified issues. - Support continuous improvement of Security Operations processes through innovation, collaboration, and automation. - Perform additional duties as assigned. Qualifications Experience: - Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field. - 2–4 years of experience in information security or IT infrastructure within a HIPAA-regulated organization. - 2–4 years of experience in a cloud environment (preferably Azure) with a strong understanding of related compliance requirements. - 2+ years of experience in information security auditing preferred. Skills: - Working knowledge of HIPAA Security and Privacy Rules and industry security frameworks (e.g., HITRUST, NIST). - Industry certifications such as CISSP, Security+, or ISACA credentials preferred. - Proficiency in Microsoft Excel for reporting and analysis. - Strong written and verbal communication skills with the ability to convey technical concepts in business-friendly terms. - Proven ability to work independently in a remote environment and collaborate effectively with cross-functional teams. - Strong analytical, organizational, and prioritization skills. - Ability to maintain confidentiality and adhere to data privacy requirements. - Familiarity with vulnerability scanning tools and Active Directory preferred. - Experience working in highly regulated environments (healthcare or financial services) is a plus. Our Culture: - We have a clear vision of where we are going, and we are guided by core values that embody our organization and our culture. - We emphasizes innovation and growth, and you will be given the opportunities and tools to develop personally and professionally. - We encourage and celebrate collaboration. - We have a deep commitment to positively impact the communities in which we work and to make a difference in the lives of who we serve. Matrix Medical Network is an Equal Employment Opportunity Employer. It is the policy of Matrix to provide equal employment opportunities without regard to race, color, religion, sex, gender identity or expression, pregnancy, age, national origin, age, disability, marital status, veteran status, sexual orientation, genetic information or any other protected characteristic under applicable law. It is also the policy of Matrix that qualified individuals with disabilities receive equal opportunity in regard to job application procedures, hiring, and all aspects of the employment process. Matrix is committed to the full inclusion of all qualified individuals. Consistent with the Americans with Disabilities Act (ADA) and applicable state and local laws, it is the policy of Matrix to provide reasonable accommodation when requested by a qualified applicant or employee with a disability, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed to participate in the job application or interview process, pre-employment testing, to otherwise participate in the selection process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact MatrixHR@matrixhealth.net.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Security Analyst
NumotionNumotion is a leading mobility and rehab equipment supplier headquartered in Brentwood, Tennessee. Committed to serving its customer's lifelong needs, Numotion
At Numotion, we’re on a mission to improve the lives of people with disabilities. As North America’s largest provider of mobility products and services, we deliver personalized solutions from manual and power wheelchairs to medical supplies and other assistive technologies that support health, independence, and everyday participation. We’re committed to a workforce of diverse backgrounds and experiences and to an inclusive environment shaped by open dialogue, attentive listening, and tangible, ongoing action. The Security Analyst supports the organization’s cybersecurity program by monitoring systems, investigating security events, and assisting with the execution of core security initiatives. This role focuses on operational security tasks and works under the guidance of senior team members to ensure threats are identified and addressed in a timely manner. The Security Analyst plays a key role in maintaining day-to-day security operations while developing technical skills and experience across multiple security domains. The pay range for this position is $65,000-75,000 Salary. It is not typical for an individual to be hired at or near the top of the pay range and compensation decisions are dependent on the facts and circumstances of each case. The specific compensation offered to a candidate may be influenced by a variety of factors including skills, qualifications, experience and location. KEY RESPONSIBILITIES: § Monitor security alerts, logs, and dashboards to identify potential security incidents and escalate as appropriate § Perform initial analysis and investigation of security events following established procedures § Support ongoing security initiatives such as vulnerability management, endpoint protection, and threat detection activities § Maintain and operate security tools including SIEM, DNS, AV, and cloud security technologies § Assist with documentation of incidents, investigations, and remediation actions § Utilize Numotion Leadership Principles to perform job with integrity, compliance, and values consistent with Numotion’s mission. § Adhere to employee or customer confidentiality and comply with Numotion’s policies and federal regulations. § Always provide excellent customer service for all internal and external customers of the operations. Provide solutions for customer concerns and continually focus on customer service as our top priority. § The above duties and responsibilities are not an all-inclusive list but rather a general representation of the duties and responsibilities associated with this position. The duties and responsibilities will be subject to change based on organizational needs and/or as deemed necessary by management. REQUIRED QUALIFICATIONS, SKILLS, AND EXPERIENCE: § 1-4 years of relevant experience § Ability to analyze and troubleshoot security-related issues with guidance from senior staff § Strong communication skills and willingness to collaborate with technical and non-technical teams § Experience with endpoint security or monitoring tools (CrowdStrike experience preferred) § Basic scripting or automation experience (PowerShell preferred) § Exposure to cloud environments and security concepts PREFERRED QUALIFICATIONS, SKILLS, AND EXPERIENCE: § Knowledge of mobility and accessibility equipment and products. § Experience with inventory software, order processing systems, and internet tools. § Strong interpersonal, presentation, and problem-solving skills. § Familiarity with third-party payer systems including VA, Insurance Waiver Programs, and Commercial payers. § Proven ability to lead through change and drive performance in a fast-paced environment. PHYSICAL WORK REQUIREMENTS: The physical demands and work environment characteristics described here are representative of those that must be met by an employee to successfully perform the essential functions of the job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. § Frequent use of hands, wrists, fingers associated with computer equipment. § Prolonged periods of time working at a desk and/or on a computer. § Occasionally move and reach with arms and hands. § Ability to lift/move up to 20 pounds. At Numotion, we offer competitive compensation packages, including medical, dental and vision insurance, short-term and long-term disability, a 401k, and life insurance. Numotion is an equal opportunity employer. We strive for a workplace that reflects the communities we serve and do not tolerate discrimination against our employees, customers, and partners regardless of ethnicity, disability, gender identity, sexual orientation, religion, age, citizenship, marital or veteran status. Numotion is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.
Role Description - Gerenciar e acompanhar todo o fluxo de processos de importação, assegurando conformidade, prazos e qualidade operacional; - Digitar, revisar e registrar processos no sistema, mantendo cadastros e documentos sempre atualizados; - Emitir numerários, documentos de importação e conferência de informações junto a transportadoras, armadores, recintos alfandegados e fornecedores; - Planejar e coordenar o agendamento de carregamentos, acompanhando prazos e execução junto aos stakeholders internos e externos; - Contribuir para a análise e otimização de processos, propondo melhorias e soluções que aumentem a eficiência operacional; - Preparar relatórios gerenciais e indicadores de performance da área de importação; - Garantir o controle documental completo, arquivamento adequado e suporte a auditorias internas ou externas; - Apoiar a equipe em atividades administrativas e estratégicas da área, promovendo integração com outros setores; - Executar outras atividades correlatas ao setor, alinhadas aos objetivos estratégicos da empresa. Qualifications - Formação superior em andamento ou completa em Comércio Exterior, Relações Internacionais ou áreas correlatas. - Experiência mínima de 2 anos em rotinas de importação ou comércio exterior. - Conhecimento intermediário/avançado em Excel. - Capacidade analítica para revisão de processos, indicadores e melhorias operacionais. - Boa comunicação, organização, proatividade e dinamismo. Benefits - Remuneração: R$ 5.000,00 a R$ 5.500,00 (Sênior) - R$ 635,00 alimentação/refeição - R$ 400,00 ajuda de custo creche (caso tenha filhos até 7 anos) - Plano de saúde - Seguro de vida - Vale transporte público - TotalPass: benefício com desconto em academias Company Description
Senior GRC Analyst
Summit 7 SystemsSummit 7 is here to rise above the ordinary. The work we do here goes far beyond day-to-day projects - it further protects the US defense industrial base from cyber threats, fosters thought leadership, and creates growth opportunities. Our support staff, sales team and technicians are all coming together to make a difference. We also recognize that you're a person with life beyond work, that's why we invest in these meaningful health and welfare benefits.
Position Title: GRC Analyst Clearance: Desired, not required Location: Huntsville, AL/Remote Salary*: $110,000+ *Dependent upon qualifications Summit 7 is here to rise above the ordinary. The work we do here goes far beyond day-to-day projects - it further protects the US defense industrial base from cyber threats, fosters thought leadership and creates growth opportunities. Our support staff, sales team and technicians are all coming together to make a difference. We also recognize that you're a person with life beyond work, that's why we invest in meaningful health and welfare benefits such as: - Excellent health/dental benefits from BCBS - See into the future with our luxurious VSP vision benefits - Prepare for the long-haul courtesy of our 401k with company matching - Unlimited mobile phone plan - 10 days' vacation, 7 days sick time - Bonuses and salary increase potential via our certifications plan We do cool work here, defying expectations by simply being who we are - each of us makes an impact. Summary We are seeking a detail-oriented GRC Analyst to join our compliance and risk management team supporting critical defense industrial base (DIB) requirements. This role is essential to our expanding compliance program portfolio, including CMMC Level 2/3, NIST 800-171 R2/R3, ISO 27001:2022, GDPR, and SOC 2 Type II certifications. As a GRC Analyst, you will be responsible for the operational execution of our compliance programs, ensuring continuous monitoring, evidence management, and risk remediation tracking across multiple frameworks. You will work closely with the VP Cybersecurity Compliance and cross-functional teams to maintain audit readiness and support the implementation of new compliance programs. This position is ideal for a compliance professional who thrives in operational roles, values process discipline, and wants to contribute to protecting national security through robust cybersecurity governance. Responsibilities Continuous Compliance Operations (55%) - Evidence Management: Collect, organize, and maintain compliance evidence on weekly, monthly, quarterly, and semi-annual schedules across all active frameworks - ServiceNow GRC Administration: Update and maintain GRC modules including control implementations, risk registers, POA&Ms, and compliance artifacts - Risk & POA&M Management: Distribute notifications to risk and POA&M owners, track remediation activities, escalate overdue items, and maintain accurate status reporting - Supplier Risk Management: Coordinate supplier risk assessments including onboarding, offboarding, and annual reviews; maintain vendor risk documentation - Cross-Framework Reconciliation: Map and reconcile evidence requirements across multiple standards as new versions are released Program Implementation Support (30%) - New Program Standup: Assist with implementation of new compliance frameworks including document gathering, gap analysis support, and stakeholder coordination - Control Implementation Tracking: Monitor and document control implementation progress, identify blockers, and support remediation efforts - Assessment Preparation: Prepare evidence packages and coordinate with assessors for C3PAO, ISO certification, and other third-party audits - Documentation Development: Support development and maintenance of System Security Plans (SSPs), policies, procedures, and compliance documentation Collaboration & Continuous Improvement (15%) - Cross-Functional Coordination: Work with IT, Engineering, HR, Legal, and other departments to gather evidence and implement controls - Process Improvement: Identify opportunities to streamline evidence collection and automate compliance workflows - Training Support: Participate in compliance training initiatives and security awareness programs - Audit Support: Serve as primary liaison for evidence requests during audits and assessments Requirements Education & Experience - Bachelor's degree in Information Security, Computer Science, Risk Management, or related field; or equivalent practical experience - 2-4 years of experience in GRC, compliance, information security, or IT audit roles - Demonstrated practitioner experience with at least one major compliance framework (NIST 800-171, ISO 27001, SOC 2, CMMC, or similar) Technical Skills - Working knowledge of NIST 800-171 R2/R3, CMMC Levels 1-3, and/or ISO 27001:2022 requirements - Experience with GRC platforms (ServiceNow GRC, Future Feed, or similar) - Proficiency with Microsoft Office 365 and collaboration tools - Understanding of information security concepts, controls, and risk management principles Core Competencies - Exceptional Attention to Detail: Ability to manage complex evidence matrices and ensure accuracy across multiple frameworks - Process Discipline: Strong adherence to established procedures and documentation standards - Organizational Skills: Ability to manage multiple deadlines, priorities, and stakeholder requests simultaneously - Communication: Clear written and verbal communication skills for stakeholder coordination and documentation - Analytical Thinking: Capability to understand control requirements and translate them into operational evidence collection activities Preferred Qualifications - Certifications: One or more of the following: - Certified CMMC Professional (CCP) or Certified CMMC Assessor (CCA) - Certified Information Systems Security Professional (CISSP) - Certified Information Security Manager (CISM) - ISO 27001 Lead Implementer or Lead Auditor - CRISC (Certified in Risk and Information Systems Control) - Experience working in defense industrial base (DIB) organizations or cleared environments - Hands-on implementation or assessment familiarity with NIST 800-171 r2/r3, NIST 800-53, NIST 800-172, or FedRAMP requirements - Background in IT operations, systems administration, or cybersecurity engineering Summit 7 Systems is an equal opportunity/ affirmative action employer and an alcohol and drug free workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. Summit 7 Systems requires background investigations. Any offer of employment is contingent upon the results of a reference/background check. We are a drug and alcohol-free workplace and require pre-employment drug screening.
Red Team Associate Operator / Penetration Tester
Federal Reserve SystemThe Federal Reserve Bank of San Francisco, also known as the San Francisco Fed (SF Fed), is the 12th district in the Federal Reserve System, which includes Alaska, Arizona, Califor
Company Federal Reserve Bank of Richmond When you join the Federal Reserve—the nation's central bank—you’ll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we’re building a dynamic team for our future. Bring your passion and expertise, and we’ll provide the opportunities that will challenge you and propel your growth—along with a wide range of benefits and perks that support your health, wealth, and life. In addition to competitive compensation, we offer a comprehensive benefits package that includes tuition assistance, generous paid time off, top-notch health care benefits, child and family care leave, professional development opportunities, a 401(k) match, pension, and more. All brought together in a work environment where you can truly find balance About the Opportunity Our National Incident Response Team (NIRT), a national service provider for the Federal Reserve System (FRS), delivers effective and efficient national intrusion detection, incident response, security intelligence, threat assessment, and vulnerability assessment services for the FRS. NIRT’s mission is to play a leading role in the FRS’ efforts to protect its information systems against unauthorized use. NIRT’s Adversary Emulation team has an immediate opening for an Associate Operator to join their team as a key participant on a variety of engagements and projects that will target and evaluate the cyber security posture of people, processes, and technology within the FRS. As an Associate Operator, you will report to the Sr. Manager and work on a team of security professionals focused on enabling business line initiatives by performing security assessments against people, processes, and technologies by using automated tools and expertise of hands-on tools that simulate attacker tactics, techniques and procedures (TTPs). You will also perform assessments for new and existing services, infrastructure, and applications to identify weaknesses before an attacker does. You will use a variety of tools and techniques including penetration testing, red teaming, purple teaming, and social engineering and have the opportunity to combine your technical expertise with your imagination to discover innovative methods for ensuring that the FRS remains one step ahead of its adversaries around the world. What You Will Do - Strengthen FRS security posture through offensive security assessments where you will perform complex security assessments including the identification and exploitation of vulnerabilities across the system - Leverage offensive security foundational knowledge to support in the execution of cybersecurity solutions to benefit security engagements and mitigate cyber threats - Improve operational efficiency by building and evaluating workflow processes, procedures, checklists, automation, and tooling - Enable success of security initiatives by performing tasks to development surrounding security or technology capabilities and creating operations-based documentation - Address cybersecurity needs by advising clients on best practices and how to implement changes to securely address complex business needs - Execute on cross-team initiatives to implement cybersecurity improvements for recognized gaps - Grow security capabilities to defend the FRS by working with internal and external stakeholders to execute on strategies and plans to enforce security requirements - Identify and prioritize key risk areas balancing business risk and cyber threats via research of industry trends and business partner missions - Assist and execute technical security assessments to identify risk, likelihood and impact an attacker may have on the System due to weak or missing controls - Perform cybersecurity and Associate Operator duties as assigned Preferred experience we’re looking for: - 1-3 years of relevant information security related work experience in areas such as: computer network defense, computer network exploitation and post-exploitation - Bachelor’s degree or equivalent work experience - Understanding of adversary emulation operations including web application testing, network penetration testing, reconnaissance, social engineering, exploitation and post-exploitation, covert techniques, lateral movement, and data exfiltration - Knowledgeable in offensive cybersecurity roles, such as malware development, red teaming, penetration testing (e.g., web, infrastructure, cloud), purple team exercises in cloud and on-prem environments - Team player with interpersonal, collaborative and consultative skills - Adept attention to detail, oral and written communications skills tailored to audiences ranging from technical subject matter expert partners to senior executive stakeholders - Understanding client relationships, including determining needs, learning expectations, and demonstrating commitment to delivering quality results - Familiar with scripting/programming of Python, PowerShell, or C# with the ability to create and customize tools - The following certifications are highly preferred: GWAPT, GPEN, OSCP, CRTO Discover the Reason Why So Many People Love It Here! When you join Federal Reserve’s National IT organization, not only will you find a challenging and purposeful career, you’ll also have access to a wide range of benefits and perks that support your health and wealth, including: - Great medical benefits - Pension and 401(k) with employer match - Paid time off - Tuition reimbursement - Paid volunteer leave - Onsite amenities that make working here fun! Other Requirements and Considerations: - Candidates should review the Bank’s Code of Conduct to ensure compliance with conflict of interest rules and personal investment restrictions. - If you need assistance or an accommodation due to a disability, please notify rich.recruitment@rich.frb.org. - Sponsorship is not available for this role. The selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information. The ability to obtain and maintain a National Security Clearance (Secret or Top Secret) is required for this role. US Citizenship is required to be eligible for a National Security Clearance. - The national hiring range for the Red Team Associate Operator/Penetration Tester is $92,600- $127,400 annually. For candidates in certain markets (Boston, MA; Chicago, IL; Los Angeles, CA; New York City Metro Area, Philadelphia, PA; San Francisco, CA; Seattle, WA), the listed hiring and salary ranges may be adjusted based on your geographic location. - Salary offered will be based on the job responsibilities and the individual’s knowledge, skills, and experience as defined in the job qualifications/experience. - Applications are reviewed on a rolling basis. Interested candidates are strongly encouraged to apply by April 9, 2026. - Always verify and apply to jobs on Federal Reserve System Careers or through verified Federal Reserve Bank social media channels. Full Time / Part Time Full time Regular / Temporary Regular Job Exempt (Yes / No) Yes Job Category Information Technology Family Group Work Shift First (United States of America) The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences. Always verify and apply to jobs on Federal Reserve System Careers (https://rb.wd5.myworkdayjobs.com/FRS) or through verified Federal Reserve Bank social media channels. Privacy Notice



