What are the responsibilities and job description for the Information Security Analyst (GRC & Microsoft 365 Security) position at Samsung Healthcare USA?
- Location: On-site in Danvers, MA
Samsung HME America (Healthcare and Medical Equipment) is Samsung’s U.S. medical imaging organization, delivering advanced diagnostic solutions across Ultrasound, Digital Radiography, and Computed Tomography. We lead nationwide sales, marketing, service, and distribution of Samsung’s imaging technologies, partnering with healthcare providers to strengthen diagnostic capabilities, streamline clinical workflows, and support better patient care. Samsung HME America also serves as the global manufacturing center for Samsung’s mobile Computed Tomography (mCT) business, leading the development of advanced CT systems used by healthcare providers worldwide.
Backed by Samsung Electronics’ global technology leadership, our teams work closely with clinicians to translate real-world challenges into innovative imaging solutions. Our culture combines a sense of urgency, customer focus, and clinical collaboration to advance the future of medical imaging.
Role Description
We are seeking a junior-to-mid level Information Security Analyst to support and own key elements of our information security and compliance program, with a strong emphasis on ISO 27001 and CMMC frameworks. This role focuses on policy creation, documentation, and audit readiness while supporting operational security across Microsoft 365, DLP, and incident response.
The analyst will work closely with IT and Compliance to maintain a strong security posture and will play a key role in driving compliance initiatives, managing documentation, and coordinating security processes. This role requires a hands-on approach, including participation in help desk support and day-to-day IT security operations.
Key Duties And Responsibilities, Other Duties May Be Assigned
Compliance Ownership & Governance (ISO 27001 / CMMC):
- Own and maintain ISO 27001 and CMMC compliance programs
- Manage evidence, remediation tracking, and audit readiness
- Perform gap assessments and risk analyses
- Develop and maintain security policies, procedures, and runbooks
- Ensure documentation is audit-ready and version controlled
- Configure and manage DLP policies across Microsoft 365
- Support Microsoft Purview and identity security controls
- Monitor alerts using SIEM tools
- Support incident response and tabletop exercises
- Support the development and maintenance of an Acceptable AI Usage Policy
- Evaluate AI models and use cases to determine appropriate application across organizational roles
- Support tracking, logging, and governance methodologies for AI usage
- Support the development and maintenance of an Acceptable AI Usage Policy
- Evaluate AI models and use cases to determine appropriate application across organizational roles
- Support tracking, logging, and governance methodologies for AI usage
- Provide help desk support and security guidance to end users
- Assist with day-to-day IT security operations and user education
Skills & Experience
- 2–5 years of experience in IT or information security
- Experience with ISO 27001 and/or CMMC
- Strong documentation and policy writing skills
- Familiarity with Microsoft 365 security
- Understanding of DLP, incident response, and DR
- Understanding of AI models and their use within an organization
- Willingness to support help desk operations
- Experience supporting ISO or CMMC audits
- Familiarity with Microsoft Purview
- Experience with SIEM tools (e.g., Microsoft Sentinel, Splunk)
- Knowledge of NIST frameworks
- Relevant certifications (Security , SC-900, etc.)
- Strong documentation skills
- Ownership and accountability
- Attention to detail
- Collaboration
- Problem-solving
- Customer service mindset
- Occasionally lift and /or move up to 25 pounds
- Frequently required to sit; use hands to finger, handle, or feel; reach with hands; and talk or hear
- Must be able to sit for long periods of time
We offer a comprehensive benefit package which includes:
- Medical (Blue Benefit Administrators): 5 PPO Plans (with up to 95% employer contribution)
- Dental (Blue Cross Blue Shield): 2 PPO Plans (with up to 80% employer contribution)
- Vision (Blue Cross Blue Shield): 100% company paid
- Short/Long Term Disability, Life & AD&D (The Standard): 100% company paid
- 401k Retirement (Fidelity): 100% company match up to 5%
- Tax Deferred Health Care Savings Programs
- Accident Insurance, Critical Illness, Hospital Indemnity, Pet, Legal, ID Theft
- Generous paid time off, tuition reimbursement, and more!
Salary : $100,000 - $125,000