Boston Medical Center (BMC) Logo

Boston Medical Center (BMC)

Applications Security Analyst (Epic) III / Senior

Posted 25 Days Ago
Remote
Hiring Remotely in USA
90K-130K Annually
Senior level
Remote
Hiring Remotely in USA
90K-130K Annually
Senior level
The Applications Security Analyst will manage Epic application access, handle hundreds of service tickets weekly, and ensure access governance in a healthcare setting.
The summary above was generated by AI
POSITION SUMMARY:

The Senior Application Security Analyst professional will lead the day-to-day execution and continuous improvement of Epic application access in a high-volume hospital environment. This role blends operational excellence (hundreds of access tickets weekly) with senior-level ownership of access models, governance, and audit readiness.

This role will also be a key application-side partner in our IAM/IGA automation program—helping define the Epic roles/entitlements, approvals, and access review structures that enable scalable onboarding and offboarding automation. Over the next 12–24 months, this team’s scope is expected to broaden from Epic-focused access to enterprise application access governance across the organization.

Position: Applications Security Analyst (Epic) III / Senior        

Department: Information Security

Schedule: Full Time

ESSENTIAL RESPONSIBILITIES / DUTIES:High-Volume ServiceNow Access Operations
  • Own and execute work in a high-volume ServiceNow queue, consistently handling hundreds of tickets per week for joiner/mover/leaver access changes, troubleshooting, and triage.

  • Prioritize and route requests using impact, urgency, patient-care considerations, risk, and defined SLAs; escalate complex/high-risk issues appropriately.

  • Troubleshoot access end-to-end (request intent, user attributes, role mapping, provisioning outcomes, in-application authorization) and document decisions/outcomes clearly for auditability.

Epic Application Access & Security Leadership
  • Serve as the senior escalation point for Epic access design/build and complex access issues; ensure access is scalable, supportable, and aligned to policy.

  • Develop and maintain standardized access patterns Attribute Based Access Control (ABAC)/templates, privileged/elevated access controls) aligned to least privilege.

  • Partner with Epic application teams and operational leaders to translate workflows into durable access models and reduce one-off exceptions.

Access Governance, Audit Readiness, and Risk Controls
  • Maintain an Epic access catalog (roles/entitlements, risk tiers, prerequisites, approval paths) and keep it current as workflows evolve.

  • Support access reviews/attestations for high-risk roles and privileged access; drive remediation of findings and control gaps.

  • Support investigations related to inappropriate access/privacy concerns and contribute to corrective action plans.

IAM/IGA Automation Enablement (Application-Side SME)
  • Partner with IAM/IGA stakeholders during SailPoint implementation to ensure Epic is “automation-ready” (clean entitlements, requestable roles, approvals, constraints, and edge-case handling).

  • Help align access with authoritative source systems (HR, operations, credentialing, etc.) by defining needed attributes and lifecycle scenarios (joiner/mover/leaver, LOA, contractors, students).

  • Support testing/UAT and rollout readiness by validating that automated provisioning yields correct in-application authorization and usable audit trails.

Mentorship & Operational Excellence
  • Mentor and quality-review work performed by Level II analysts; establish standard work, runbooks, knowledge articles, and queue hygiene practices.

  • Track and improve key operational metrics (turnaround time, rework/defect rate, exception volume, access quality) and drive measurable process improvement.

JOB REQUIREMENTS
  • Associates degree OR equivalent education or experience

  • Epic certification(s), Security strongly preferred.

  • 5+ years of experience in Epic security/access, application access governance, or closely related healthcare IT security operations with substantial Epic access responsibility.

  • Strong Epic import/export, Microsoft Excel skills and experience.

  • Demonstrated expertise in Attribute Based Access Control (ABAC)/least privilege, access standardization, and governing elevated access in a complex clinical/operational environment.

  • Proven ability to thrive in a high-volume ticket environment while maintaining quality, consistency, and audit-ready documentation.

  • Strong cross-functional collaboration skills (Epic teams, operations, HR, IAM/IGA, IT) and clear written communication.

Preferred
  • Bachelor’s degree; majors in Computer Science, Information Systems, Cybersecurity, Healthcare Informatics, or related fields are preferred.

  • Additional Epic certifications.

  • Strong Data Governance knowledge and experience.

  • Experience implementing or partnering with IAM/IGA platforms (Okta LCM or SailPoint ISC/IIQ preferred; similar tools acceptable).

  • Experience with access reviews/attestations, segregation-of-duties concepts, and audit support in healthcare.

  • Microsoft Access database experience.

This Role Will
  • Sit inside Cybersecurity under the CISO organization with meaningful influence on enterprise access strategy.

  • Help shape the application authorization layer that makes IGA automation successful (Epic first; broader application portfolio next).

  • Have real scale: high operational volume, high-impact clinical workflows, and a multi-year IAM/IGA automation program modernizing access lifecycle controls.

Compensation Range:

$89,500.00- $130,000.00

This range offers an estimate based on the minimum job qualifications. However, our approach to determining base pay is comprehensive, and a broad range of factors is considered when making an offer. This includes education, experience, skills, and certifications/licensures as they directly relate to position requirements; as well as business/organizational needs, internal equity, and market-competitiveness. In addition, BMCHS offers generous total compensation that includes, but is not limited to, benefits (medical, dental, vision, pharmacy), discretionary annual bonuses and merit increases, Flexible Spending Accounts, 403(b) savings matches, paid time off, career advancement opportunities, and resources to support employee and family well-being. 

NOTE: This range is based on Boston-area data, and is subject to modification based on geographic location.

Equal Opportunity Employer/Disabled/Veterans

According to the FTC, there has been a rise in employment offer scams. Our current job openings are listed on our website and applications are received only through our website. We do not ask or require downloads of any applications, or “apps” job offers are not extended over text messages or social media platforms. We do not ask individuals to purchase equipment for or prior to employment. 

Top Skills

Epic
Excel
Sailpoint
Servicenow

Similar Jobs

3 Hours Ago
Remote or Hybrid
United States
142K-195K Annually
Senior level
142K-195K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead CFO-level advisory engagements for physician practices by modernizing finance operations, overseeing client teams, analyzing KPIs, building budgets/forecasts, driving process and technology improvements, collaborating cross-functionally, and mentoring staff.
Top Skills: Intacct,Quickbooks Online,Netsuite,Bill.Com
11 Hours Ago
Remote or Hybrid
Santa Clara, CA, USA
191K-334K Annually
Senior level
191K-334K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead and manage software development teams, coordinate with product, design, and support, oversee daily development activities, mentor staff, integrate AI into workflows, enforce coding standards and best practices, and deliver high-quality solutions aligned with company priorities.
Top Skills: Java,C++,Ruby,Shell,Javascript,Servicenow,Ai
11 Hours Ago
In-Office or Remote
Long Beach, CA, USA
105K-198K Annually
Senior level
105K-198K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Design, build, and maintain secure CI/CD pipelines and tooling for safety-critical avionics software. Automate deployment, integration, testing, and security controls across cloud, container, and hybrid environments while supporting certification and cross-functional teams.
Top Skills: AWSAzureCi/CdDevsecopsDockerGCPJavaKubernetesLinuxPythonWindows

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account