Sharp HealthCare logo
Sharp HealthCare
Posted 40 days agoVerified live 1d ago

IAM Epic Security Analyst II

Brief overview

Remote
UndergradOr in progress
$50–$72/hrStated range
3+ yrsMinimum
Application Access ControlInformation Systems Security AdministrationEpic SupportActive Directory ManagementIdentity and Access ManagementIdentity FederationRole-Based Access Control (RBAC)Access Management ProcessesHealthcare Information Security and PrivacyIT Security Compliance and AuditingEpic Security CertificationEpic Data Courier BadgeCompTIA Security+

About the company

Sharp HealthCare logo
Sharp HealthCaresharp.com

Sharp HealthCare is a not-for-profit integrated regional health care delivery system based in San Diego, Calif.

Job description

Summary

Sharp HealthCare is hiring an IAM Epic Security Analyst II to support its Identity and Access Management and Epic Security operations. The role maintains access management systems, responds to incidents and access requests, supports audits and compliance, and coordinates Epic security activities across IT teams and business departments.

Responsibilities

  • Ensure readiness for internal and external audits, including action plan to promptly resolve issues identified and ensure Standard Operating Procedures are created and followed
  • Report out on agreed upon Key Performance Indicators (KPIs) related to IAM, Epic Security, SER, incident/service request management and compliance
  • Manage on-call rotations
  • Train new IT staff in system functions and operations in order to maximize user effectiveness and utilization of systems
  • Develop and maintain Standard Operating Procedures (SOPs) for IAM, Epic Security, and SER
  • Develop system documentation for on-call and other operational requirements
  • Monitor and analyze IAM and Epic system performance, make recommendations for improvements
  • Monitor the daily operations of IAM systems (IGA, Active Directory and other IAM systems), ensuring efficient and secure access management
  • Demonstrate in depth, detailed technical knowledge of security requirements and solutions
  • Develop and/or follow practices/guidelines in relation to compliance with IAM Policies, Epic Security, standards, regulatory requirements and ensure the proper processes are followed when exceptions arise
  • Demonstrate content expertise regarding application and business operations by mentoring staff
  • Ensure compliance and adherence with corporate security controls and standards as they relate to Identity and Access Management (IAM)
  • Conduct assessments, on demand and routine audits to identify and mitigate compliance risks
  • Prepare documentation for audits and act as the point of contact for audit related responsibilities
  • Perform certification of RBAC
  • Perform data contamination management, including coordinating clean-up efforts and reporting requirements and ensuring auditing requirements are completed
  • Mitigate risk by addressing security vulnerabilities and audit gaps
  • Participate in efforts regarding audit findings, adherence to compliance and organizational change
  • Partner with Compliance Department to assure all internal and external customers system access and Sharp HealthCare user agreement forms are appropriate and adhered to
  • Develop and maintain documentation related to IAM, Epic Security and Provider SER compliance activities
  • Provide operational support including, but not limited to: account provisioning, de-provisioning, periodic access reviews, emergency access, and privileged access management
  • Provide support for IAM-related issues, troubleshooting and resolving complex problems
  • Support the implementation of IAM tools and technologies to enhance security and user experience
  • Partner closely with the Identity and Access Management (IAM) Development team to align role-based access models (RBAC) with Epic security templates and coordinate downstream provisioning through tools like SailPoint
  • Serve as the bridge between Epic application teams and provisioning stakeholders, ensuring that design decisions reflect operational needs and compliance expectations
  • Build and maintain Epic security templates, shared security classes, and application-level role structures in collaboration with analysts and business partners
  • Build and maintain Epic SER records and Blueprints
  • Maintain guidelines for appropriate access in Epic, including compliance with regulatory limitations
  • Document and adhere to standards for naming conventions, template usage, ownership definitions, and cross-application alignment
  • Maintain version control and history for Epic security structures and changes across environments
  • Contribute to risk mitigation strategies related to role structure, over-permissions, or shared access issues
  • Maintain functionality and resolve issues with the provider HL7 interface or API
  • Participate in on call support for the IAM and Epic Security group
  • Ensure operational procedures are created and followed
  • Ensure that all accounts are configured to support the access control policy of Sharp HealthCare
  • Correctly configure accounts based on the completion of a standardized access request form
  • Adjust work schedule as needed for department coverage
  • Facilitate and participate in a multidisciplinary Epic Security Workgroup with representation from ISD Application teams, Compliance, IAM, Training, Clinical Informatics and Operations
  • Participate in initiatives to standardize data and workflows to better utilize IAM automation tools
  • Identify high risk situations, inform Management with recommendation on next steps. Coordinate the activities to reduce the risk
  • Lead Epic Security projects and initiatives to improve the access management process
  • Maintain active relationships with all customers by continuously assessing needs, preferences and level of satisfaction with tasks
  • Work effectively with physicians, management, staff, auditors, investigators, consultants and vendors
  • Provide continuing support of remote connections, including VPN and Citrix
  • Accept escalation messages and calls from customers
  • Develop knowledge base articles for the Technical Assistance Center
  • Provide in-service or knowledge transfer sessions to Technical Assistance Center staff and other departments, as needed
  • Train and mentor new members in the department to appropriate customer service skills
  • Monitor Change Management tickets for timeliness, quality, and documented processes are followed
  • Monitor Service Desk tickets for timeliness
  • Provider Incident/Service Request support and quality customer service
  • Respond to IAM/Epic incidents in a timely manner
  • Maintains required certifications
  • Obtains other certifications and attends seminars or training as required by the department
  • Maintains knowledge of systems and applications

Skills

  • 3 Years experience in application access control including experience in information systems security administration in a multi entity health care system, experience with supporting, improving, reporting, documenting audits and compliance with internal and external audits
  • 3 Years experience with IT Epic support
  • Bachelor's degree in Computer Science, Healthcare, or related field; or 4 years of relevant experience in Information Technology may substitute for degree. - REQUIRED
  • Epic Security Certification - REQUIRED
  • Epic Data Courier Badge - REQUIRED
  • Epic Provider Administration Badge is required within 90 days of hire
  • Epic Security Post Live Badge is required within 90 days of hire
  • Knowledge of clinical and business operations in a healthcare environment
  • Ability to interpret functional requirements into applications design
  • Ability to communicate technical issues to technical staff and nontechnical users/clients
  • Must have strong leadership and communication skills
  • Knowledge of hospital and clinic culture, business practices, regulatory requirements (e.g., TJC), and health care requirements as it relates to information security and privacy (e.g., HIPAA)
  • Knowledge and understanding of RBAC
  • Knowledge of Identity and Access Management structures/processes such as provisioning, entitlement certification, access removal and privileged access
  • Knowledge of IT security, compliance and Identity Management
  • Ability to work on-call
  • Ability to cross cover shifts as needed
  • Experience with Active Directory Management
  • Extensive operational knowledge and experience with IAM concepts, principles and best practices such as identity federation, role-based access control and access management processes
  • Six Sigma Yellow Belt Certification - Various-No accreditation board -PREFERRED
  • CompTIA Security+ - CompTIA -PREFERRED
  • Epic Bridges Certification - PREFERRED
  • Epic Cogito Certification - PREFERRED

Qualifications

Must Haves

  • 3 Years experience in application access control including experience in information systems security administration in a multi entity health care system, experience with supporting, improving, reporting, documenting audits and compliance with internal and external audits
  • 3 Years experience with IT Epic support
  • Bachelor's degree in Computer Science, Healthcare, or related field; or 4 years of relevant experience in Information Technology may substitute for degree. - REQUIRED
  • Epic Security Certification - REQUIRED
  • Epic Data Courier Badge - REQUIRED
  • Epic Provider Administration Badge is required within 90 days of hire
  • Epic Security Post Live Badge is required within 90 days of hire
  • Knowledge of clinical and business operations in a healthcare environment
  • Ability to interpret functional requirements into applications design
  • Ability to communicate technical issues to technical staff and nontechnical users/clients
  • Must have strong leadership and communication skills
  • Knowledge of hospital and clinic culture, business practices, regulatory requirements (e.g., TJC), and health care requirements as it relates to information security and privacy (e.g., HIPAA)
  • Knowledge and understanding of RBAC
  • Knowledge of Identity and Access Management structures/processes such as provisioning, entitlement certification, access removal and privileged access
  • Knowledge of IT security, compliance and Identity Management
  • Ability to work on-call
  • Ability to cross cover shifts as needed

Nice to Haves

  • Experience with Active Directory Management
  • Extensive operational knowledge and experience with IAM concepts, principles and best practices such as identity federation, role-based access control and access management processes
  • Six Sigma Yellow Belt Certification - Various-No accreditation board -PREFERRED
  • CompTIA Security+ - CompTIA -PREFERRED
  • Epic Bridges Certification - PREFERRED
  • Epic Cogito Certification - PREFERRED

More jobs like this