Information Security Analyst (Remote)
3 days ago
Denver
Job Description Evio Overview Evio is a highly unique pharmacy solutions company that was founded by and works closely with health plans to implement transformative (to cost, quality, access and experience) initiatives primarily focused on specialty and other high-cost medication solutions. In 2020, a group of five amazing Blue Cross Blue Shield health plans that in total serve more than 20 million members recognized that the way medications get to patients needs significant reform—rapidly rising costs and massive system complexities are detrimental to patients and the entire industry. In 2025, Wellmark joined as Evio's first non-founding investor and sixth owner health plan. Each company made, and continues to make, significant investments to establish Evio as an independent entity to lead this transformation. Evio has advanced analytics and contracting capabilities at scale, and a suite of digital tools, to power our high-cost medication solutions. Our solutions act as a self-reinforcing "flywheel" where each element strengthens and feeds into the next, and support an "Only Evio can do that," mindset and prioritization. Evio is also a company that has invested heavily in and been highly intentional about people, team and culture. We believe we have created a very special place to work and encourage candidates to observe and ask us about our culture and decide for themselves. Evio's Values • Empathy – The people our business serves always come first. We care for our teammates and put ourselves in the shoes of our health plan customers and the patients and clinicians our solutions benefit., • Diversity – We are committed to fostering a culture where everyone belongs and is valued for their background, experience and insights – one that encourages diversity of ideas, and is a nurturing, trusting, and accepting place for all., • Adventure – We are flexible, thrive in ambiguity, fail fast, and pivot quickly to get to a better answer. We celebrate wins and pivots with equal intensity., • Relentless – Guided by evidence and data, we are creative, curious, and unwavering in our pursuit of challenging the status quo and each other., • Transparency – Just as we seek to bring transparency to the pharmacy supply chain, authenticity and integrity are core to the way we communicate., • Excellence – We strive to raise the bar in all we do by hiring and developing exceptional talent and holding ourselves and our thinking to the highest standard. About the role Evio is seeking a proactive and detail-oriented Information Security Analyst to help protect our systems, data, and infrastructure across a regulated health care environment. This role plays an important part in strengthening and maturing our security program while enabling secure, efficient business operations. You will execute and improve security controls, manage user and privileged access, run monitoring and response activities, and coordinate recurring program work driven by Evio's Cybersecurity Calendar. You'll work cross-functionally with teammates across IT, Legal, Compliance, and business teams. This is a hands-on role with broad visibility, where you'll help shape how security operates at Evio. What you'll do Identity & access control / user lifecycle • Own and execute user access management, including provisioning and deprovisioning across AWS, O365, HRIS, SaaS platforms, and databases)., • Implement and maintain least-privilege RBAC, access control matrices, and entitlement catalogs., • Administer identity and access systems, including IdP/SSO integrations (SAML, OAuth) and SCIM provisioning., • Enforce privileged access management (PAM), multi-factor authentication (MFA_, separation of duties, and key/secret rotation., • Conduct recurring access reviews (quarterly and annual) across systems., • Monitor, triage, and investigate security alerts., • Support incident response activities., • Support SOC 2, HIPAA, and HITRUST audits, including evidence collection and remediation tracking., • Maintain and update security policies, standards, and procedures., • Partner with Legal, Compliance, and IT teams to strengthen controls and resolve findings., • Run phishing simulations and track awareness metrics., • Support and improve teammate security awareness and training programs., • Maintain the enterprise risk register and track remediation progress., • Report on security KPIs and risk trends, • 3+ years of experience in information security, risk, or compliance., • Experience in regulated environments (health care preferred)., • Familiarity with frameworks such as HIPAA, SOC 2, HITRUST, or NIST., • Experience with cloud and SaaS security environments (AWS, O365)., • Strong analytical skills and the ability to clearly communicate risk., • Relevant certifications (Security+, CISSP, CISM, CISA) are a plus., • Excitement for continuing to mature and strengthen an established security program., • Someone who takes initiative, unearths problems, and leads with solutions., • Hands-on experience with IAM, IdP, SSO, SCIM, and privileged access management tools., • Experience with SIEM platforms, log analysis, and vulnerability management tools., • Scripting or automation experience (Python, PowerShell, or similar)., • Experience supporting audits (SOC 2, HIPAA, HITRUST) and preparing evidence. At Evio, we're committed to building a competitive compensation package to honor the value our teammates bring as well as attract and retain top talent that is aligned with our culture, mission, and values. Compensation includes base pay (range shown) and could include other variable compensation opportunities depending on job seniority, location, and date of hire. Evio Benefits Fraud Notice We've recently learned of fraudulent job postings and individuals falsely claiming to represent Evio. Protecting our candidates is incredibly important to us, and we want to share a few reminders: • All official communication will come from an email ending in @evio.com., • We will never conduct text-only interviews (SMS, WhatsApp, Telegram, etc.)., • We will never ask for payment, gift cards, fees, or purchases of any kind., • We will never request sensitive financial information during the recruiting process., • Our open roles are posted only on our official website, LinkedIn, and Greenhouse job board.If you believe you've encountered a scam, you can also report it to the Federal Trade Commission or the Internet Crime Complaint Center. Thank you for your care and vigilance — we're grateful to everyone who helps keep our community safe. Information Disclosure We value transparency in our hiring process and want applicants to understand how your information is used. We collect and use personal information you provide during the application process such as your resume, employment history, education, interview responses, and other job-related information, to evaluate your qualifications for employment. This may also include limited technical and interaction data, such as IP address and device or browser information. We may use technology systems, including automated or AI-assisted tools, to review applications, identify candidates whose qualifications align with the role, and detect, prevent, and investigate potentially fraudulent or deceptive activity. Human reviewers remain involved, and these tools assist, not replace, human judgment. These measures support a fair and secure hiring process for all candidates. If you require a reasonable accommodation, please inform us upon invitation to interview. California privacy notice Consistent with California law, we use this information for recruiting, hiring, and related business purposes, including evaluating your candidacy and improving our hiring processes.