We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

ITSC Security Analyst

Capital Rx
$92,000-$115,000
United States, New York, New York
Aug 14, 2026
About Judi Health

Judi Health is a health technology company providing benefit administration solutions to employers, unions, health plans, and government entities. Judi Health replaces fragmented, outdated systems with the industry's first Unified Claims Processing architecture, seamlessly consolidating pharmacy and medical benefit administration on a single, secure platform. By delivering true price transparency, eliminating unnecessary middleman fees, and leveraging advanced AI-powered care delivery, Judi Health helps clients achieve unprecedented operational efficiency and service levels.

At Judi Health, we're deploying the infrastructure our country needs to deliver the healthcare we all deserve. We are the intelligence platform powering benefits plans for millions of Americans and proudly leading the next generation of care. To learn more, visit www.judi.health.

Location:Hybrid 3 days (offices in NYC, Denver, CO and Charlotte, NC area)

Position Summary

The ITSC (IT Security & Compliance) Analyst works collaboratively on the GRC team within the IT department to identify, manage and communicate security risks, implement and monitor security compliance, and respond to audits effectively.

Position Responsibilities:



  • Collaborate with the engineering departments and development teams to implement security controls from approved security frameworks and drive best IT practices.
  • Continuously monitor, evaluate, and report on the effectiveness of security controls to ensure ongoing compliance with governing security frameworks, including HITRUST, SOC 2, FedRAMP, and other applicable industry or regulatory standards.
  • Interface with internal partner teams to help drive best practices and security compliance.
  • Evaluate and perform Risk Assessments of new software solutions with internal partners.
  • Drive deployment of new GRC systems and AI automated solutions as needed.
  • Write procedure documentation for end users as needed to facilitate process improvement.
  • Help develop IT security training content and drive completion of required security training in collaboration with Human Resources.
  • Respond to complex security questionnaires, RFP/RFI requests, and client audits.
  • Serve as primary technical resource during client security audits, communicating complex technical concepts clearly, professionally, and in alignment with established organizational and industry security standards.
  • Facilitate end-to-end evidence gathering for external audits, ensuring all technical and administrative artifacts align strictly with security control requirements and regulatory frameworks.
  • Evaluate, identify, and remediate the risks associated with current vendors, new vendor acquisitions, and consumer data exchanges.
  • Perform risk oversight tasks of vendor security compliance.
  • Help run Internal, external and vendor related audits.
  • Conduct security analysis of deployed software.
  • Monitor for risks to the enterprise and to implemented controls
  • Identify, maintain, and publish the requirements for the IT department to achieve compliance and privacy standards in SOC 2, HITRUST, FedRAMP, and other frameworks.
  • Work with the internal team in communicating related security notifications and IT controls within the organization while collaborating with teams and vendors on changes, remediations, and updates.
  • Experience with Agile and/or Kanban with emphasis on Scrum to drive continuous process improvement.
  • Perform Access Reviews.


Required Qualifications:



  • Experience related to duties and responsibilities.
  • Experience working in Governance, Risk, and Compliance or on a security team.
  • A customer-oriented approach to problem resolution
  • Experience with IT control auditing and compliance.
  • Working knowledge of Software Development Lifecycle concepts and processes
  • Working knowledge of cloud providers with respect to IT Security & Compliance controls and practices.
  • General knowledge of frameworks and controls: NIST 800-53, FedRAMP, HITRUST, SOC 2, PCI, ISO 27001
  • General knowledge of HIPAA and the requirements to protect PHI.
  • Ability to communicate concepts in a concise form to management and cross-functional teams. departments or teams verbally, in writing, and through pictures or diagrams when appropriate.
  • Excellent written, oral, instructional, presentation, and interpersonal skills focused on motivation and positive attitude.
  • Highly self-motivated with the ability to prioritize tasks and work independently.
  • Ability to work quickly and efficiently.
  • Desire to work at a rapidly growing organization in healthcare.
  • Experience working with remote users in a distributed environment.
  • Experience with Office 365 suite, Atlassian suite, Vanta (or other GRC tools).
  • Experience with any major cloud platform (AWS, Google, Azure) is preferred.


(Optional) Preferred Qualifications:



  • CCSK
  • CCAK
  • CISA
  • AWS Cloud Practitioner
  • SANS certificates


New York, NY Salary Range
$92,000 $115,000 USD
Denver, CO Salary Range
$84,400 $105,500 USD
Charlotte, NC Salary Range
$76,800 $96,000 USD

All employees are responsible for adherence to the Judi Health Code of Conduct including the reporting of non-compliance. This position description is designed to be flexible, allowing management the opportunity to assign or reassign duties and responsibilities as needed to best meet organizational goals.

We provide equal employment opportunities to all employees and applicants for employment and prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, medical condition, genetic information, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

By submitting an application, you agree to the retention of your personal data for consideration for a future position at Judi Health. More details about Judi Health's privacy practices can be found at https://www.judi.health/legal/privacy-policy.

Applied = 0

(web-77cf7d65c7-548rw)