EG
Information Security Analyst (32634)
Examworks Group
80–100 k $US par an · Télétravail · États-Unis
ExamWorks Group operates in a high-stakes data environment. The company is a leading provider of independent medical examinations, peer reviews, bill reviews, Medicare compliance, record retrieval, and document management services for the insurance, legal, and government sectors. The threat model here is direct: the systems handle sensitive medical records, legal documents, and compliance data across the United States, Canada, the United Kingdom, and Australia. A breach doesn't just mean lost data; it means compromised patient privacy, regulatory penalties, and damaged trust in critical legal and insurance processes. The technical footprint is built around a private cloud network, custom portals, and integrated applications that support complex clinical and administrative workflows. Security operations would be focused on protecting this specific stack - defending the perimeter and internal segments of the private cloud, securing the data flowing between custom portals and back-end systems, and hardening the various applications that handle document management and record retrieval. The work involves systems integration points where vulnerabilities could be introduced, making secure development and rigorous access controls central concerns. For cybersecurity professionals, the environment offers concrete, domain-specific challenges. It's not theoretical; it's about safeguarding the platforms that manage real medical-legal data under strict compliance frameworks like HIPAA and Medicare regulations. The team's work directly enables the integrity of peer reviews and bill analyses that determine financial and legal outcomes. The geographic spread and industry verticals add layers of complexity to identity management, data residency, and threat monitoring.
ExamWorks Group operates in a high-stakes data environment. The company is a leading provider of independent medical examinations, peer reviews, bill reviews, Medicare compliance, record retrieval, and document management services for the insurance, legal, and government sectors. The threat model here is direct: the systems handle sensitive medical records, legal documents, and compliance data across the United States, Canada, the United Kingdom, and Australia. A breach doesn't just mean lost data; it means compromised patient privacy, regulatory penalties, and damaged trust in critical legal and insurance processes.
The technical footprint is built around a private cloud network, custom portals, and integrated applications that support complex clinical and administrative workflows. Security operations would be focused on protecting this specific stack - defending the perimeter and internal segments of the private cloud, securing the data flowing between custom portals and back-end systems, and hardening the various applications that handle document management and record retrieval. The work involves systems integration points where vulnerabilities could be introduced, making secure development and rigorous access controls central concerns.
For cybersecurity professionals, the environment offers concrete, domain-specific challenges. It's not theoretical; it's about safeguarding the platforms that manage real medical-legal data under strict compliance frameworks like HIPAA and Medicare regulations. The team's work directly enables the integrity of peer reviews and bill analyses that determine financial and legal outcomes. The geographic spread and industry verticals add layers of complexity to identity management, data residency, and threat monitoring.