1

It Security Analyst Jobs in Silver Spring, MD (NOW HIRING)

RMF IT Security Analyst

Bethesda, MD · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst

Bethesda, MD · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst

Bethesda, MD · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst

Bethesda, MD · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst

Bethesda, MD · Remote

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

RMF IT Security Analyst

Bethesda, MD · On-site

$120K - $130K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

RMF IT Security Analyst Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The RMF ...

SAP NS2 Internal Project US Citizen only IT Security Analyst T2 12/16/2024 to 12/15/2025 Physical Work Arrangement NS2 Office (Herndon, VA) Description: The Cyber Trust Analyst will work in a ...

Information System Security Analyst

Mclean, VA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The ideal candidate will have strong analytical skills and a passion for staying current with the latest IT security trends and technologies. Key Responsibilities: • Monitoring and Detection:

Information System Security Analyst

Mclean, VA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The ideal candidate will have strong analytical skills and a passion for staying current with the latest IT security trends and technologies. Key Responsibilities: Monitoring and Detection: Monitor ...

IT Security Manager

Baltimore, MD · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Provides operational leadership and mentorship to Security Analysts, ensuring standard operating ... As the IT Security Manager (Global Cyber Command), you will lead information gathering efforts ...

ITSM Security Analyst

Washington, DC

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

ProSidian Seeks a ITSM (Information Technology Service Management) Security Analyst to support an engagement for an American scientific agency within the United States Department of Commerce that ...

IT Security Specialist

Annapolis Junction, MD · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Analyst, Security Engineer, Network Security Specialist, Security Administrator, IT Risk Analyst, Cyber Defense Specialist, Security ...

next page

Showing results 1-20

It Security Analyst information

See Silver Spring, MD salary details

$20

$47

$73

How much do it security analyst jobs pay per hour?

As of Aug 15, 2026, the average hourly pay for it security analyst in Silver Spring, MD is $47.91, according to ZipRecruiter salary data. Most workers in this role earn between $36.54 and $57.40 per hour, depending on experience, location, and employer.

What does an IT security analyst do?

An IT security analyst is responsible for protecting an organization's computer systems and networks from cyber threats. They monitor security systems, investigate security incidents, implement security measures, and ensure compliance with security policies, often using tools like firewalls, intrusion detection systems, and security information and event management (SIEM) software. Strong analytical skills and relevant certifications such as CISSP or CompTIA Security+ are commonly required.

Is IT hard to get a security analyst job?

Securing an IT security analyst position can be competitive, often requiring relevant experience, knowledge of cybersecurity tools, and certifications such as CompTIA Security+ or CISSP. Strong technical skills, problem-solving ability, and staying current with security trends improve job prospects, but the difficulty varies based on the job market and individual qualifications.

What are the key skills and qualifications needed to thrive as an IT Security Analyst?

To thrive as an IT Security Analyst, you need a strong understanding of cybersecurity concepts, risk assessment, and network security, often backed by a degree in computer science or information technology. Familiarity with security tools such as firewalls, intrusion detection systems, SIEM platforms, and certifications like CISSP or CompTIA Security+ are typically required. Analytical thinking, attention to detail, and effective communication are essential soft skills in this role. These skills are crucial for identifying threats, implementing protective measures, and ensuring the ongoing security of organizational systems and data.

What is the difference between It Security Analyst vs Network Security Analyst?

AspectIt Security AnalystNetwork Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CCNA Security
Work EnvironmentIT departments, cybersecurity firms, corporate security teamsNetwork operations centers, cybersecurity teams, IT departments
Employer & Industry UsageBroadly in various industries focusing on overall securityPrimarily in organizations with complex network infrastructures
Common Search & ComparisonYesYes

The main difference between an It Security Analyst and a Network Security Analyst lies in their focus areas. It Security Analysts oversee overall cybersecurity strategies, policies, and incident response, while Network Security Analysts specialize in protecting network infrastructure, monitoring network traffic, and securing network devices. Both roles require similar certifications and often work together to ensure comprehensive security coverage within organizations.

What are some common challenges IT Security Analysts face when responding to security incidents?

IT Security Analysts often encounter challenges such as quickly identifying and containing threats, balancing thorough investigation with the need for rapid response, and communicating technical findings to non-technical stakeholders. They must also keep up with the constantly evolving landscape of cyber threats and ensure compliance with organizational policies and regulations. Effective collaboration with IT, legal, and management teams is crucial to ensure a coordinated and efficient incident response.
More about It Security Analyst jobs

What are popular job titles related to It Security Analyst jobs in Silver Spring, MD?

For It Security Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching It Security Analyst jobs in Silver Spring, MD look for?

The top searched job categories for It Security Analyst jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for It Security Analyst jobs?

Cities near Silver Spring, MD with the most It Security Analyst job openings:

Infographic showing various It Security Analyst job openings in Silver Spring, MD as of August 2026, with employment types broken down into 79% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $99,662 per year, or $47.9 per hour.

$95K - $125K/yr

Full-time

Posted 23 days ago


Job description

Description:

PHYSICIANS MANAGEMENT GROUP

JOB DESCRIPTION

IT Security Analyst

REPORTS TO: Director of Information Systems


SCHEDULE: HYBRID


GENERAL SUMMARY: Maryland Primary Care Physicians, LLC (MPCP) is an independent, physician-owned network comprised of approximately 100 board certified providers across 10 locations, servicing 130,000 patients. MPCP's operations and financial management are performed by Physicians Management Group, LLC (PMG). The IT Security Analyst is responsible for safeguarding the organization's information systems, data, and infrastructure through proactive risk management, continuous monitoring, and compliance tracking. This role supports the Compliance Manager's formal risk analysis and risk register, contributes to the cybersecurity insurance renewal process, manages the core security toolset, and assists with incident response and breach risk determination. The Analyst also supports HIPAA-aligned access governance and vendor risk oversight for systems and third parties handling electronic protected health information (ePHI), partnering closely with the Director of Information Systems on policy development and overall security posture. The ideal candidate combines strong technical expertise with sound judgment, clear communication, and a proactive approach to identifying and mitigating security risks in a healthcare environment where ransomware, phishing, third-party/vendor compromise, and connected medical device (IoMT) threats are persistent and escalating. Responsibilities span the administrative, physical, and technical safeguards required by the HIPAA Security Rule. This list of duties is representative and not exhaustive; additional responsibilities may be assigned as business needs evolve.


SUPERVISION EXERCISED: None.


Typical Physical Demands: Requires sitting, some standing, stooping, and stretching. Occasionally may lift up to 30 pounds. Requires sufficient hand-eye coordination and manual dexterity to operate a keyboard, photocopier, telephone, calculator, and other office equipment. Requires normal range of hearing and eyesight to record, prepare, and communicate appropriate reports.


Typical Working Conditions: Work is typically performed in a corporate office / clinic setting and could involve contact with staff and/or patients. Hybrid schedule: three days per week on-site and two days remote. Occasional travel to affiliated MPCP locations as needed. On-call availability may be required to support security incident response.


Primary Duties/Responsibilities Include but not Limited to:

Cyber Insurance & Risk Management

  1. Annually analyze changes to cyber insurance requirements and partner with the Director of IS to implement necessary policy, technical, or procedural changes
  2. Complete annual attestation forms and applications required for cyber insurance renewal

Security Operations & Compliance Monitoring

  1. Implement, monitor, and maintain security protocols and controls across the environment
  2. Conduct regular user account audits, security group audits, and MFA compliance reviews
  3. Coordinate periodic penetration testing and vulnerability assessments with an approved third-party vendor; track and remediate identified deficiencies
  4. Manage the security vendor quoting and evaluation process
  5. Support the formal HIPAA-aligned risk analysis, including contributing to the risk register and tracking of remediation owners and timelines
  6. Verify and maintain encryption standards for ePHI at rest and in transit across endpoints, servers, and email
  7. Perform regular review of information system activity – including audit logs, access reports, and security incident tracking reports – to detect unauthorized or anomalous access to ePHI (HIPAA 164.308(a)(1)(ii)(D))
  8. Implement, maintain, and periodically test audit controls that record and examine activity in information systems that contain or use ePHI (HIPAA 164.312(b))

Systems & Tools Management

  1. Manage and monitor remote monitoring and management (RMM) tools
  2. Manage and monitor SIEM, antivirus, and EDR platforms, including alert triage, mitigation, and incident reporting
  3. Support technical incident response activities, including investigation, containment, and coordination with the Compliance Manager on HIPAA breach risk determination and notification requirements
  4. Administer and monitor the Proofpoint email security platform
  5. Oversee Windows endpoint patch management and compliance reporting
  6. Manage firewall rule adjustments as needed to support security requirements
  7. Maintain a current inventory of networked, biomedical, and Internet-of-Medical-Things (IoMT) devices that create, store, or transmit ePHI; monitor them for known and exploited vulnerabilities and support network segmentation to isolate high-risk devices
  8. Configure and verify technical access controls on systems containing ePHI, including unique user identification, automatic logoff, and emergency access procedures (HIPAA 164.312(a))
  9. Verify that ePHI is backed up, that backups are encrypted and maintained in an offline or immutable form, and that restoration is regularly tested to ensure recovery from ransomware or destructive attacks

Policy & Compliance Support

  1. Assist the Director of IS and Compliance Manager in developing and maintaining policies and procedures supporting the organization's cybersecurity posture
  2. Support development of policies and procedures aligned with HIPAA regulatory requirements and risk management standards
  3. Support security controls and audit processes for the Electronic Health Record (EHR) system and all systems containing ePHI
  4. Support periodic access reviews for systems containing ePHI to ensure alignment with least-privilege and minimum-necessary access principles
  5. Support vendor security risk assessments and due diligence for third parties with access to ePHI, in coordination with the Compliance Manager
  6. Confirm that Business Associate Agreements (BAAs) are executed and current for all third parties that create, receive, maintain, or transmit ePHI, in coordination with the Compliance Manager
  7. Support physical safeguards and device and media controls, including secure disposal, re-use, sanitization, and tracking of hardware and media containing ePHI (HIPAA 164.310)
  8. Support timely provisioning and deprovisioning of access upon hire, role change, and termination, and assist with enforcement of the workforce security and sanction policies for security violations (HIPAA 164.308(a))
  9. Support periodic technical and non-technical evaluations of the security program against the HIPAA Security Rule and maintain required security documentation and evidence for at least six years (HIPAA 164.308(a)(8), 164.316)

Business Continuity & Organizational Support

  1. Participate in Business Continuity and Disaster Recovery planning, testing, and tabletop exercises
  2. Monitor healthcare-specific threat intelligence (e.g., Health-ISAC, HHS HC3, and CISA advisories) and translate relevant alerts into defensive actions
  3. Manage and monitor employee security awareness training programs and track completion/compliance
  4. Research and attend relevant security conferences, training, and continuing education opportunities

Performance Requirements:

  • Maintains cyber insurance attestations, applications, and required policy/control updates on schedule to keep the organization's coverage current and audit-ready
  • Completes user account, security group, and MFA compliance audits on a regular, defined cadence, with findings documented and remediated within established timeframes
  • Ensures penetration testing and vulnerability assessments are scheduled, completed, and tracked to closure, with identified deficiencies remediated according to risk-based timelines
  • Contributes accurate, timely updates to the HIPAA risk register, including clear ownership and remediation timelines for each identified risk
  • Reviews audit logs, access reports, and security incident tracking reports on a consistent basis, escalating unauthorized or anomalous ePHI access promptly
  • Keeps SIEM, antivirus, EDR, and email security (Proofpoint) platforms properly configured and monitored, with alerts triaged and addressed within defined response windows
  • Maintains Windows endpoint patch compliance at or above organizational targets
  • Supports incident response activities with clear, timely documentation and coordination with the Compliance Manager on breach risk determination
  • Maintains a current, accurate inventory of networked, biomedical, and IoMT devices, with known vulnerabilities tracked and addressed
  • Verifies ePHI backup, encryption, and restoration testing occur on schedule, with results documented
  • Supports policy, access review, and vendor risk assessment activities in a manner that meets HIPAA regulatory deadlines and audit expectations
  • Maintains required security documentation and evidence in accordance with the six-year HIPAA retention requirement
  • Participates actively in Business Continuity/Disaster Recovery planning, testing, and tabletop exercises, and maintains accurate supporting documentation and after-action reports
  • Ensures employee security awareness training completion is tracked and reported accurately
  • Demonstrates sound judgment and clear, professional communication when working across IT, compliance, and vendor stakeholders, and escalates issues appropriately and in a timely manner
  • Stays current on cybersecurity threats and technologies through ongoing professional development

Knowledge, Skills & Abilities:

  • Demonstrated verbal and written communication skills
  • Demonstrated analytical and problem-solving abilities
  • Ability to work collaboratively across IT and compliance functions while managing competing priorities
  • Microsoft 365 security stack proficiency required, including Entra ID (Azure AD), Exchange Online, Microsoft Defender, Conditional Access, and Purview / Data Loss Prevention (DLP)
  • Required scripting/automation experience, particularly PowerShell
  • Working knowledge of vulnerability management, network segmentation, and backup/recovery practices

Education:

  • Bachelor's degree in Computer Science, Information Technology, or related field required

Experience:

  • Minimum 3 years of IT experience with a security focus
  • Hands-on experience with SIEM and EDR platforms
  • Experience supporting a healthcare EHR environment strongly preferred
  • Working knowledge of HIPAA rules and regulations
  • Familiarity with the HIPAA Security Rule safeguards (administrative, physical, and technical) and the Breach Notification Rule
  • Exposure to medical device/IoMT security and network segmentation preferred

Certifications/License:

  • CompTIA Security+ certification (or greater) required
  • Preferred: an intermediate or healthcare-focused security certification such as CompTIA CySA+, GIAC GSEC, or CISSP

Alternative to Minimum Qualifications: None


Requirements: