Epic Security Analyst
Position Summary
The Epic Security Analyst will design, configuration, develop, and administration of secure user access within the Epic electronic health record environment, with a strong focus on integration between SailPoint and Epic. This role works closely with Identity and Access Management, Information Security, Epic application teams, clinical and operational stakeholders, compliance, and audit partners to ensure Epic access is accurate, compliant, automated where appropriate, and aligned with business and patient-care needs.
Key Responsibilities
ยทย ย ย ย ย ย Perform Epic security design, build, testing, and implementation, for user access, roles, templates, menus, security classes, and related access components.
ยทย ย ย ย ย ย Configure, troubleshoot, and support integration between SailPoint and Epic to enable reliable identity lifecycle management, access provisioning, modification, and deprovisioning.
ยทย ย ย ย ย ย Analyze Epic access requests, provisioning errors, security build questions, and workflow-related access concerns, escalating complex issues when appropriate.
ยทย ย ย ย ย ย Perform Epic access provisioning, deprovisioning, and modification processes for joiner, mover, and leaver activity, ensuring timely completion and accurate documentation.
ยทย ย ย ย ย ย Partner with Identity and Access Management teams to support role-based access control, attribute-based access models, privileged access controls, approval workflows, and access automation initiatives.
ยทย ย ย ย ย ย Maintain Epic security standards, access matrices, role catalogs, entitlement documentation, and procedures that support least-privilege access and auditability.
ยทย ย ย ย ย ย Collaborate with Epic application teams, clinical operations, revenue cycle, compliance, privacy, and IT stakeholders to translate operational workflows into secure and supportable access models.
ยทย ย ย ย ย ย Perform access reviews, user access attestations, audit requests, privacy investigations, and remediation of security or compliance findings.
ยทย ย ย ย ย ย Monitor, analyze, and resolve Epic security incidents, access concerns, and inappropriate access issues in coordination with Information Security and Compliance teams.
ยทย ย ย ย ย ย Test and validate Epic security and SailPoint-related access changes for upgrades, new modules, implementation projects, optimization work, and organizational changes.
ยทย ย ย ย ย ย Identify opportunities to improve access request processes, reduce one-off exceptions, streamline support, and strengthen the overall Epic security posture.
Qualifications
ยทย ย ย ย ย ย Minimum of 5 years of relevant experience in healthcare IT, Epic application support, information security, identity and access management, access governance, or a closely related environment; degree not required.
ยทย ย ย ย ย ย Hands-on experience with integration between SailPoint and Epic, including identity lifecycle management, access provisioning, deprovisioning, role mapping, entitlement management, or workflow troubleshooting.
ยทย ย ย ย ย ย Current Epic Security certification, accreditation, or active Epic certification status is preferred or may be required based on organizational standards; equivalent demonstrated Epic security expertise may be considered.
ยทย ย ย ย ย ย Experience with Epic security build, access provisioning, user templates, security classes, menus, roles, or related Epic access components.
ยทย ย ย ย ย ย Experience maintaining Epic security documentation, role catalogs, access matrices, and controls that support least-privilege access and audit readiness.
ยทย ย ย ย ย ย Strong understanding of healthcare access controls, identity governance, least-privilege principles, audit requirements, and regulatory expectations related to patient information privacy and security.
ยทย ย ย ย ย ย Experience with Epic upgrades, implementations, optimization initiatives, access reviews, and production support activities.
ยทย ย ย ย ย ย Ability to analyze access issues, document decisions clearly, and communicate technical concepts to clinical, operational, compliance, and IT stakeholders.
ยทย ย ย ย ย ย Experience with SailPoint IdentityIQ or SailPoint Identity Security Cloud, including access request workflows, identity governance, connectors, certifications, or lifecycle events.
ยทย ย ย ย ย ย Experience supporting large health systems, hospitals, academic medical centers, or complex multi-entity healthcare organizations.
ยทย ย ย ย ย ย Ability and willingness to travel as required for client, implementation, training, go-live, upgrade, or stakeholder activities.
This is a remote opportunity, with travel 1x per quarter
The Epic Security Analyst will be a long term contract opportunity through likely end of 2027