How to Apply
A cover letter is required for consideration for this position and should be attached as the first page of your resume. The cover letter should address your specific interest in the position and outline skills and experience that directly relate to this position.
Job Summary
The University of Michigan's Information Assurance team at Michigan Medicine (IA:MM) is looking for a candidate to fulfill the role of Vulnerability Analyst Associate. You will support in developing and enhancing our organization's information security risk management and strategies. You will also help with the logistics for information security risk remediation throughout the Academic Medical Center and across the three missions of research, learning, and patient care. As a Vulnerability Analyst will promote strategic and operational direction by ensuring the support of complex assessment systems, reporting and processes.
Opportunity
We are a team that focuses on how we can together help protect Michigan Medicine; it's patients, students, workforce, data, systems, and identities from cybersecurity threats. We champion our staff, their backgrounds, interests, and abilities with opportunities for training career growth in an increasing critical field. In addition to the benefits of working at one of the best learning and research institutions in the world, we also promote the development of our talented staff's cybersecurity career within an equitable balance of work and home priorities. This position is being made available with the ability for you to negotiate alternative work schedules and remote/on-site options to suit your work-life balance.
Non-Michigan residents should inquire about potential employment while working remotely in a state other than Michigan. Apply to be part of a strong team that partners with our institution, community, and each other.
Our Division's Mission
We serve as a trusted partner and provides a best-in-class security program to uphold and protect the mission of Michigan Medicine.
Our Division's Vision
We believe in cultivating a shared responsibility of security to enhance how we provide care, deliver education and create innovation to protect the quality of healthcare.
Our Division's Principles
- Prioritize your self-care, family-care, team-care, then the work.
- Implement balanced assurance solutions.
- Strengthen our department's capabilities.
- Develop an assurance-minded workforce.
- Focus on practical information assurance.
Responsibilities*
- Prepare security assessments for all information systems, and information technology services of Michigan Medicine Trusted IT Service Providers for compliance with U-M and Michigan Medicine procedure, legal and regulatory requirements.
- Help develop mitigation strategies to bring risk levels into an acceptable range and assist and support the Michigan Medicine Trusted IT Service Providers with those remediation activities.
- As a member of the Information Assurance Team recommend improvements in policies, procedures, and technical safeguards to address risks to the security of Michigan Medicine information systems and data.
- Assess the impact of reported vulnerabilities and help implement mitigation strategies based on severity.
- Build good relationships with teams, and partners at all levels (e.g. management, colleagues, and employees) using competencies to build trust, change perceptions, communicate, influence, and adapt.
- Improve security service solutions and offerings by keeping up-to-date on security conferences, seminars, reading, research, and testing.
Required Qualifications*
- Associate degree or an equivalent combination of education and experience.
- 2 years information technology experience.
Desired Qualifications*
- Understanding of fundamental information security concepts including: Authentication, Authorization, Audit, Encryption, and Firewalls.
- Understanding and exposure of fundamental security related practices such as: Risk Management or Vulnerability Management.
- Experience completing tasks within established deadlines.
- Experience with information systems security.
- Experience in a healthcare environment.
- Experience with vulnerability scanning and penetration testing technology.
- Hold or in pursuance of a security certification such as CISSP, CISA, GIAC-GSEC.
Modes of Work
Positions that are eligible for hybrid or mobile/remote work mode are at the discretion of the hiring department. Work agreements are reviewed annually at a minimum and are subject to change at any time, and for any reason, throughout the course of employment. Learn more about the work modes.
Additional Information
Benefits
We offer a benefits package that includes comprehensive training and career development opportunities, generous retirement savings plans, ample paid time off, and a wealth of family care support: https://careers.umich.edu/benefits
Background Screening
Application Deadline
U-M EEO/AA Statement
The University of Michigan is an equal opportunity/affirmative action employer.