Job Closed
This listing is no longer active.
Connecting millions to quality, affordable health insurance
Information Security Compliance Analyst
Location
United States
Posted
130 days ago
Salary
$78K - $97.5K / year
Seniority
Senior
Job Description
Information Security Compliance Analyst
eHealth, Inc.
• Assisting with internal and external audit engagements (SOC2 Type II, HITRUST, PCIDSS, SOX, GuardianSphere etc.) • Gather control evidence to ensure the information provided fulfills the requirements • Organize audit evidence and manage the control and process libraries • Assist the business to assess, document and remediate risks identified during the assessment • Contributing to eHealth’s compliance maturity: • Work with the business to implement sound security controls aligned with the security policies and standards and identify control gaps • Develop metrics to report to management • Assisting with Security awareness training and phishing campaign exercises • Working with business partners to respond to carrier security questionnaires • Evaluating new vendors for security concerns • Assess the status of projects to identify and implement appropriate corrective measures to resolve security concerns as they arise • Assists in the development and ongoing refinement of enterprise AI policies, standards, and guardrails, embedding responsible and compliant AI use into core governance processes, risk assessments, and control frameworks
Job Requirements
- You have a Bachelor's degree in Information Security, Information Systems or related field. We will consider candidates with equivalent work experience in lieu of a Bachelor’s degree.
- You have 3+ years of experience working in an Information Security audit setting such as SOC2 and HITRUST, and knowledge of security controls including NIST, HIPAA, & Privacy
- You have the ability to foster a collaborative working relationship in a fast-paced, team-oriented environment
- You bring strong written and verbal communication skills with a proven ability to hold constructive discussions with the business to ensure information security risks are adequately addressed
- You have attention to detail and strong research skills
- You have the ability to analyze problems from different angles and foster multiple perspectives
- You have experience with risk management tool administration and configuration is a plus
- You have the ability to digest and translate technical language and relay to stakeholders outside of the Security field in understandable terms
- You have the ability to exercise judgement within defined procedures and determine appropriate action with autonomy and support as needed.
Benefits
- Generous benefits include medical, dental and vision beginning on your first day of employment
- 401K with matching
- Tuition reimbursement
- Employee stock purchase program
- 12 company paid holidays and flexible time off (PTO for non-exempt)
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Cybersecurity Analyst
PurpleBox, Inc.Secure Cloud Solutions Consulting and Managed Services PurpleBox Security Services include assessment, design, implementation and management of information security, compliance, and technical security solutions. - Compliance Assessment and Reporting - Risk Assessment - Vulnerability Assessment and Penetration Testing (VA/PT) - Security Policy and Controls - Vulnerability Scanning Services (PCI ASV, OS, Network, Database, Web Application) - SCADA and Industrial Control Systems Security - Security Configuration Baselines - Security Monitoring and Threat Intelligence Services - Application Security Testing Services - Managed Web Application Firewall PurpleBox is an Amazon Web Services (AWS) Partner and helps clients with their Cloud Transformation and Cloud Migration needs: - Cloud Trasformation Strategy - Current State Assessment - Migration Project Management - Cloud Architecture - Cloud Security Architecture - Security and Compliance in the Cloud - Cloud Cost Optimization PurpleBox Cloud Services are focused on providing its customers with the most complete and cost effective cloud solutions. From scoping and designing new environments, to decoupling and migrating complex existing platforms, our experienced team of certified professionals has a proven track record of delivery excellence.
Company Description PurpleBox is the leading technology consulting company that focuses on solving business problems utilizing new technologies. We provide Cybersecurity, Cloud Computing, and DevOps consulting services that help businesses manage their business risk more effectively. Job Description Multiple Cybersecurity Analyst and Engineer Positions are available. Entry Level to Mid & Senior Level Internship, Part-Time, Full-Time We are seeking to hire multiple Cybersecurity Analysts and Engineers to work with our customers in various security testing, architecture, implementation, support, and compliance projects. As part PurpleBox Security Services team, you will be working on challenging projects. Responsibilities: As a Subject Matter Expert in specific cybersecurity technologies and domains, you will provide engineering, architecture design, assessment, and technical support for projects As part of managed security services, you will run daily processes and tools for managing cybersecurity : Vulnerability Management, End Point Protection, Security Logging, Monitoring, and Incident Response, Security Compliance, Privacy, Security Awareness Training, and more... As part of security testing services, performing penetration testing, ethical hacking, and security assessments against Networks, Web Applications, API, Mobile Applications, IoT Devices, and Public Cloud Infrastructure Collaborate in the creation of technical collateral (blog posts, whitepapers, etc...) and provide training in your area of expertise. Give back to the community by volunteering at technical events, speaking at technical conferences, organizing local meetups, and participating in case studies. Write, review, and edit reports, use cases, and system documentation. Qualifications
Information Security Analyst – HIPAA, NIST, CMS, IRS
Zirlen Technologies Inc.,A leading IT Services Company - Delivering what business demands
• Provide expertise in security frameworks and compliance measures • Work with security teams in relevant domains • Communicate effectively with stakeholders • Organize and manage project tasks • Support audit and compliance measures
• Administer and manage Identity and Access Management (IAM) using Microsoft Entra ID. • Manage user lifecycle processes (onboarding, role changes, offboarding), access provisioning and role assignments. • Configure and maintain MFA, Conditional Access, RBAC and Zero Trust controls. • Conduct regular access reviews and support audit and compliance requirements. • Provide L2/L3 support for incidents related to identity, access and cloud. • Operate and manage security tickets, incidents and service requests using Jira. • Monitor, analyze and respond to security alerts related to identity and access. • Administer and support endpoint security solutions. • Collaborate with internal teams on incident response, remediation and security improvements. • Design and implement automation for IAM and security processes to reduce manual tasks. • Contribute to documentation of procedures, guides and operational processes. • Support and improve the cloud security posture in Azure.
• Work in a team, share knowledge, collaborate and grow through the team’s challenges; • Serve as a technical reference on topics related to your responsibilities; • Participate in projects, committees and squads; • Drive the vision, activities, processes and procedures, and analyze scenarios to evolve the DevSecOps area; • Contribute to the creation of DevSecOps processes and procedures; • Act as a reference and provide support to the team on DevSecOps and AppSec topics; • Analyze and define security requirements across the SSDLC and DevSecOps development cycle; • Validate requirements in Development, Staging (Homologation) and Production environments; • Participate in and provide technical consultancy for secure application development (AppSec); • Contribute to the creation and delivery of training for developers; • Actively participate in structuring the AppSec chapter within the company’s agile model, using solutions such as Snyk and Azure DevOps; • Participate actively in cyber exercises, cyber war games, CTFs and other team or partner activities; • Stay continuously aware of new vulnerabilities, scenarios and cyber threat trends.



