Point your AI agent at freehire and let it find you a job.

Get the CLI →

danafarber

New

Information Security Analyst

Posted Updated
Discussion
The Information Security Analyst is a key team member in Dana-Farber Cancer Institute’s Information Security program. Reporting to the AVP, Information Security Officer, the Analyst supports day-to-day program operations, including routine security investigations, risk management support, training and awareness, and policy maintenance. The Analyst works closely with Information Services teams and other stakeholders to support information security objectives.

Located in Boston and the surrounding communities, Dana-Farber Cancer Institute is a leader in life changing breakthroughs in cancer research and patient care. We are united in our mission of conquering cancer, HIV/AIDS, and related diseases. We strive to create an inclusive, diverse, and equitable environment where we provide compassionate and comprehensive care to patients of all backgrounds, and design programs to promote public health particularly among high-risk and underserved populations. We conduct groundbreaking research that advances treatment, we educate tomorrow's physician/researchers, and we work with amazing partners, including other Harvard Medical School-affiliated hospitals.

Primary Duties and Responsibilities

  • Monitor and triage the Information Security team mailbox and ticket queue; respond to workforce inquiries, route/escalate as needed, and document, update, and close tickets in accordance with team procedures and SLAs.
  • Conduct routine information security investigations at the direction of the AVP, Information Security Officer, including documentation, fact-finding, analysis, and summary reporting.
  • Assist with risk management activities such as surveys, assessments, inventories, and gap analyses against established security and privacy standards.
  • Support planning, execution, documentation, and follow-up for Information Security projects, audits, and workplans; compile status updates and final summaries for stakeholders.
  • Assist with third-party/vendor risk management activities, including coordinating evidence collection, completing assessments, and tracking periodic review activities.
  • Support development, review, and maintenance of Information Security policies and procedures; respond to routine requests for policy interpretation and guidance.
  • Contribute to security awareness and education efforts, including developing and delivering department-specific training and partnering with Communications to promote awareness initiatives.

Knowledge, Skills and Abilities

  • Ability to maintain confidentiality and handle sensitive patient, employee, and organizational information with discretion.
  • Familiarity with healthcare security/privacy requirements (e.g., HIPAA/HITECH and applicable state privacy requirements) and general compliance concepts.
  • Familiarity with security frameworks and control concepts (e.g., NIST CSF and basic NIST control principles) and how they apply to policies and assessments.
  • Strong analytical and problem-solving skills; ability to gather facts, identify patterns/trends, and escalate issues appropriately.
  • Strong documentation skills, including producing clear investigation notes, assessment results, training materials, and stakeholder-ready summaries.
  • Effective communication skills, including the ability to explain policies and security concepts to non-technical audiences and collaborate across teams.
  • Strong organizational and time-management skills; ability to manage multiple requests, meet deadlines, and track work to completion.

Minimum Job Qualifications

  • High school diploma/GED required.
  • 3 years of information security, privacy, risk, audit, or related experience required.
  • 3 years supporting security programs in a healthcare or other regulated environment preferred.
  • Security+ or equivalent Information Security certification strongly preferred.

License/Certification/Registration Required: None

Supervisory Responsibilities: No

Patient Contact: No

Special Working Conditions:

  • On call requirements

At Dana-Farber Cancer Institute, we work every day to create an innovative, caring, and inclusive environment where every patient, family, and staff member feels they belong. As relentless as we are in our mission to reduce the burden of cancer for all, we are committed to having faculty and staff who offer multifaceted experiences. Cancer knows no boundaries and when it comes to hiring the most dedicated and compassionate professionals, neither do we. If working in this kind of organization inspires you, we encourage you to apply.

Dana-Farber Cancer Institute is an equal opportunity employer and affirms the right of every qualified applicant to receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, national origin, sexual orientation, genetic information, disability, age, ancestry, military service, protected veteran status, or other characteristics protected by law.

EEO Poster

.

Pay Transparency Statement

The hiring range is based on market pay structures, with individual salaries determined by factors such as business needs, market conditions, internal equity, and based on the candidate’s relevant experience, skills and qualifications.

For union positions, the pay range is determined by the Collective Bargaining Agreement (CBA).

$76,300.00 - $92,100.00

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available