System Application Analyst - Security (Systems/Applications Analyst) in Portland, Oregon at Oregon Health & Science University
Explore Related Opportunities
Job Description
US--Remote
Requisition ID: 2026-41413
Position Category: Information Systems
Job Type: AFSCME union represented
Position Type: Regular Full-Time
Posting Department: Information Technology Group (ITG)
Posting Salary Range: $97,378 - $147,456 per year, with offer based on experience, education and internal equity
Posting FTE: 1.00
Posting Schedule: Typically Monday - Friday
Posting Hours: Business Hours, Typically 8:00am - 5:00pm
HR Mission: Central Services
Drug Testable: No
Department Overview
The mission of the Information Technology Group (ITG) is to develop, implement and maintain technology-based services and solutions enable OHSU to effectively manage information to accomplish its missions.
This position as an Application Analyst, will (1) perform Security Center duties to secure all third-party applications and devices, (2) perform security vulnerability review and analysis activities to support remediation efforts, (3) assume project management responsibilities for small to medium projects or sub-projects as assigned, and (4) respond to issues related to Security Center and other duties as assigned.
Function/Duties of PositionIdentify, Investigate and Apply Security Patches to Third-Party applications
- Using security tools, identify and prioritize system vulnerabilities.
- Investigate the need for functionality on servers and eliminate any unnecessary features.
- Work with SMEs and technical teams to maintain the security and compliance of third-party applications and medical devices.
- Review vulnerability scan results and security findings to identify security risks requiring remediation.
- Assist in evaluating the potential impact of identified vulnerabilities and document findings.
- Identify and document mitigating measures if an application or device is unable to apply a patch.
- Develop test plans/documentation, conduct testing and validation as appropriate.
- Use patch management and monitoring tools to automate and streamline patching activities.
- Support remediation efforts by working with application owners and technical teams to resolve identified security vulnerabilities.
Project Management
Assume project management responsibilities for small to medium security projects or sub-projects as assigned.
Follow all Project Management standard processes.
Communicate status, progress, issues and roadblocks to project sponsor and manager as appropriate.
- Ensure that all components of a project plan are completed including design, build, testing, validation, training and communication.
Problem Resolution and Security Analysis
- Respond to issues related to application security.
- Review security alerts, vulnerability reports, and security findings.
- Investigate security-related issues and assist in determining root causes.
- Collaborate with application teams, infrastructure teams, and vendors to resolve identified security concerns.
- Communicate problem progress and resolution and document activities in Service Manager as appropriate.
- Escalate significant risks, unresolved vulnerabilities, or recurring issues to senior analysts and management.
Other
- Perform other appropriate job-related duties as assigned by supervisor.
Required Qualifications
Master’s degree in computer science, a related field, or a clinical field and two years' work related experience in the information technology field or a combination of clinical or operational healthcare environments; OR
Bachelor’s degree in computer science, a related field, or a clinical field and four years' work related experience in the information technology field or a combination of clinical or operational healthcare environments; OR
Associate’s degree in computer science, a related field, or a clinical field and five years' work related experience in the information technology field or a combination of clinical or operational healthcare environments; OR
Six years work related experience in the information technology field or a combination of clinical or operational healthcare environments; OR
Equivalent combination of education and experience where one year of experience will be substituted for an Associate’s degree and two years of experience will be substituted for a Bachelor’s degree.
Experience
- 2+ years experience in Healthcare Information Systems, Application Support, Application Security, Security Analysis, Server Administration, or related Information Technology disciplines.
- Experience reviewing vulnerability assessment results and supporting security remediation efforts preferred.
Skills and Abilities
Ability to work in a highly autonomous role by demonstrating self-motivation and creativity in design approach.
Ability to function effectively in a very dynamic team environment.
Ability to proactively pursue problem resolution independently.
Ability to manage multiple complex tasks efficiently while successfully meeting assigned deadlines.
Additional Details
Benefits
- Healthcare for full-time employees covered 100% and 88% for dependents.
- $50K of term life insurance provided at no cost to the employee.
- Two separate above market pension plans to choose from.
- Vacation - up to 200 hours per year dependent on length of service.
- Sick Leave - up to 96 hours per year.
- 9 paid holidays per year.
- Substantial Tri-Met and C-Tran discounts.
- Employee Assistance Program.
- Childcare service discounts.
- Tuition reimbursement.
- Employee discounts to local and national businesses.