Location: Richmond, VA Position Type: Hybrid Hybrid Schedule: Hybrid schedule determined later Contract Length: Long-term with annual extensions
Position Overview: This role serves as an EHR Security Analyst and Application Support Specialist, responsible for defining and maintaining access controls, security policies, and user permissions within an enterprise EHR system. The position also provides Tier 1 support to end users while ensuring compliance with healthcare regulations and organizational security standards.
Duties:
Define, map, and maintain EHR position structures, including roles, preferences, and security groups
Monitor and enforce access controls to ensure users have appropriate permissions based on job functions
Support and help automate user provisioning and deprovisioning processes
Conduct internal security audits to identify and mitigate risks and vulnerabilities
Develop and maintain security policies, procedures, and application guidelines
Assist in creating and maintaining security documentation and downtime procedures
Investigate and respond to EHR-related security incidents, ensuring timely resolution and reporting
Collaborate with cross-functional teams to integrate security into system updates, enhancements, and third-party applications
Monitor user activity and behavior to identify trends, anomalies, or potential threats
Support internal and external audit processes related to EHR security
Participate in system upgrades, security patching, and ongoing maintenance activities
Contribute to domain strategy and continuous improvement of the EHR security environment
Stay current on emerging threats, regulatory changes, and industry best practices
Provide Tier 1 support to end users for EHR security and access-related issues
Required Qualifications:
5+ years of strong understanding of Oracle Health EHR and security
5+ years of analytical, problem-solving, and troubleshooting experience related to Cerner/OHPAC security and access issues
5+ years of excellent communication and collaboration skills working with IT teams, compliance officers, and end users
5+ years of application support experience
3+ years of ability to manage multiple competing priorities and multitask in a fast-paced environment
3+ years of demonstrated commitment to delivering exceptional customer service to users with varying technical knowledge
Preferred Qualifications:
3+ years of understanding of HIPAA, HITECH, meaningful use, and other healthcare security regulations
3+ years of experience with Active Directory (AD), single sign-on (SSO), multi-factor authentication (MFA), and identity management solutions
3+ years of knowledge of Discern and CCL
5+ years of familiarity with healthcare IT infrastructure, including networking, firewalls, and database security