SonicJobs Logo
Left arrow iconBack to search

Senior Information Security Analyst - Cloud and AI Security

UHS
Posted 2 months ago, valid for a day
Location

Tredyffrin, PA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Universal Health Services, Inc. (UHS) is seeking a Senior Information Security Analyst specializing in Application Security, with a minimum of 5-8 years of experience in information security and at least 3 years dedicated to Application Security.
  • The role involves securing applications and AI-enabled solutions, conducting security assessments, and integrating security practices throughout the software development lifecycle.
  • Candidates should possess a Bachelor's degree in Computer Science, Cybersecurity, or a related field, along with hands-on experience in various application security tools and methodologies.
  • The position offers competitive compensation, excellent medical and retirement benefits, and opportunities for growth within the organization.
  • Travel may be required for at least 10% of the time to support field projects.
Responsibilities

One of the nation’s largest and most respected providers of hospital and healthcare services, Universal Health Services, Inc. (UHS) has built an impressive record of achievement and performance. Growing steadily since its inception into an esteemed Fortune 500® corporation, annual revenues  during 2025 were $17.4 billion. In 2026, UHS was again recognized as one of Fortune World’s Most Admired Companies™ and in 2025, was listed in Forbes ranking of America’s Largest Public Companies.  

 

Headquartered in King of Prussia, PA, UHS has approximately 101,500 employees and continues to grow through its subsidiaries. Operating acute care hospitals, behavioral health facilities, outpatient facilities and ambulatory care access points, an insurance offering, a physician network and various related services located in 40 U.S. states, Washington, D.C., Puerto Rico and the United Kingdom. For additional information visit www.uhs.com. 

 

The Corporate Information Services Department is seeking a dynamic and talented Sr. Information Security Analyst-Application Security.

 

As a key member of our collaborative Cybersecurity team, the Senior Information Security Analyst will serve as a technical lead for securing applications, AI-enabled solutions, and autonomous AI agents across UHS and affiliates. In this role, you will identify, assess, document, and mitigate security vulnerabilities in our traditional and AI-powered applications, guide secure development practices, and partner with architecture, development, infrastructure, and business teams to embed security throughout the software development lifecycle (SDLC) and across emerging AI workflows. Provide technical guidance and independent validation while platform and application owners retain operational responsibility. Works with technical and non-technical staff to ensure that deployed technologies are effectively and efficiently providing the intended controls consistent with established policies and procedures. Where appropriate, trains and supports technical staff in UHS affiliated locations to deploy, manage,

and support selected technologies. Adheres to UHS standards of service excellence, professionalism, and integrity while performing duties.

 

Key responsibilities include:

  • Maintains selected information security technologies within guidelines of policies and in keeping with good project management principles.  Monitors the resolution of maintenance or enhancement issues assigned by the UHS Customer Support Center.
  • Lead and perform in-depth security assessments of web, mobile, API, cloud-based, and AI-enabled applications and autonomous AI agents through code reviews, using tools such as SAST, DAST, IAST, SCA, manual techniques, and penetration testing, including adversarial AI testing (prompt injection, jailbreak and guardrail bypass, model poisoning, RAG and MCP review, and AI agent abuse).
  • Periodically reviews deployed security technologies to ensure that the solutions continue to provide the intended protections efficiently and effectively.
  • Work closely with DevOps and engineering teams to integrate security into CI/CD pipelines (DevSecOps) and AI/ML pipelines, and develop secure coding guidance, AI security standards, and runtime control baselines.
  • Identifies gaps in protection and recommends solutions to remediate or mitigate the risks associated with the protection gaps.
  • Document findings and assist in creating reports and metrics for technical and non-technical audiences.
  • Works with staff at all levels in the organization, vendors and contractors to ensure protections are effective, efficient and non-disruptive to the appropriate duties, rights and mission of the individuals and the organization(s) affected. 
  • Acts as the subject matter expert (SME) for at least one technology or process, and guides the efforts of 1-3 less experienced staff who assist with the assigned technology or process.
  • Monitors the resolution of maintenance or enhancement issues assigned by the UHS Customer Support Center.

Qualifications

Position Requirements:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field required.
  • Minimum 5-8 experience in information security, with at least 3 years of dedicated Application Security experience (secure code review or penetration testing).
  • Hands-on experience in Application Security (SAST, SCA, DAST, WAF, ASPM) with a background in secure code development (DevSecOps, SSDLC) required.
  • Experience with security tools such as GitHub Advanced Security, Veracode, Snyk, or similar is preferred.
  • Hands-on experience securing and assessing AI-enabled applications, autonomous AI agents, and AI/ML pipelines is a plus
  • Proficient with design, configuration, management and support of some or all of the following or similar information security technologies or processes.
    • Anti-malware protections and analysis
    • Web filtering and security
    • Vulnerability scanning and management
    • Encryption technologies for data at rest and data in transit
    • Mobile device and removable media protection or management systems
    • Authentication – including various forms of SSO and MFA
    • Cloud application security
    • Security Information and Event Management (SIEM) systems
    • Interpreting Common Vulnerabilities and Exposures (CVE) data
    • OWASP Top 10
    • NIST AI Risk Management Framework (AI RMF)
    • Device control
    • Data Loss Prevention (DLP)
    • Forensic analysis 
  • Familiarity with risk assessment and risk management concepts or processes.
  • Working knowledge of various regulatory security requirements – particularly Sarbanes-Oxley (SOX), HIPAA, and HITECH.
  • Working knowledge of common cyber security frameworks such as HITRUST, NIST, or others.
  • Working knowledge of scripting languages such as Python, PowerShell, and VB is a plus.
  • Able to plan, organize, manage and execute projects, working with other technical staff, to implement cyber and information security technologies or processes.
  • Able to prioritize multiple tasks and be detail oriented.
  • One or more information security certifications are required – AppSec preferred. (OffSec, TCM, SANS, HTB, ISC²)
  • Excellent communication, interpersonal and project management skills

 

Travel Requirements: At least 10 % US travel to field locations may be necessary to complete assigned projects.

 

This opportunity provides the following:

  • Challenging and rewarding work environment
  • Growth and development opportunities within UHS and its subsidiaries
  • Competitive Compensation
  • Excellent Medical, Dental, Vision and Prescription Drug Plan
  • 401k plan with company match
  • Generous Paid Time Off

 

*UHS is a registered trademark of UHS of Delaware, Inc., the management company for Universal Health Services, Inc. and a wholly-owned subsidiary of Universal Health Services, Inc. Universal Health Services, Inc. is a holding company and operates through its subsidiaries including its management company, UHS of Delaware, Inc. All healthcare and management operations are conducted by subsidiaries of Universal Health Services, Inc. To the extent any reference to "UHS or UHS facilities" on this website including any statements, articles or other publications contained herein relates to our healthcare or management operations it is referring to Universal Health Services' subsidiaries including UHS of Delaware. Further, the terms "we," "us," "our" or "the company" in such context similarly refer to the operations of Universal Health Services' subsidiaries including UHS of Delaware. Any employment referenced in this website is not with Universal Health Services, Inc. but solely with one of its subsidiaries including but not limited to UHS of Delaware, Inc.

 

UHS is not accepting unsolicited assistance from search firms for this employment opportunity. Please, no phone calls or emails. All resumes submitted by search firms to any employee at UHS via-email, the Internet or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of UHS. No fee will be paid in the event the candidate is hired by UHS as a result of the referral or through other means.

 

EEO Statement

All UHS subsidiaries are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and teammates. UHS subsidiaries are equal opportunity employers and as such, openly support and fully commit to recruitment, selection, placement, promotion and compensation of individuals without regard to race, color, religion, age, sex (including pregnancy, gender identity, and sexual orientation), genetic information, national origin, disability status, protected veteran status or any other characteristic protected by federal, state or local laws.

We believe that diversity and inclusion among our teammates is critical to our success.

Avoid and Report Recruitment Scams  

We are aware of a scam whereby imposters are posing as Recruiters from UHS, and our subsidiary hospitals and facilities. Beware of anyone requesting financial or personal information. 

 

At UHS and all our subsidiaries, our Human Resources departments and recruiters are here to help prospective candidates by matching skill set and experience with the best possible career path at UHS and our subsidiaries. During the recruitment process, no recruiter or employee will request financial or personal information (e.g., Social Security Number, credit card or bank information, etc.) from you via email. Our recruiters will not email you from a public webmail client like Hotmail, Gmail, Yahoo Mail, etc. 

 

If you suspect a fraudulent job posting or job-related email mentioning UHS or its subsidiaries, we encourage you to report such concerns to appropriate law enforcement. We encourage you to refer to legitimate UHS and UHS subsidiary career websites to verify job opportunities and not rely on unsolicited calls from recruiters. 

 




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.