Senior Security AnalystThe Senior Security Analyst position is responsible for technical and thought-leadership duties for multiple information security disciplines such as incident response, vulnerability management, intrusion detection and prevention, threat hunting, security operations, security policy, and awareness/education; oversight of information security incident response activities, risk assessment and risk management activities, and vulnerability assessment and vulnerability management activities spanning University and business units; managing detailed network, operating system, database, and application vulnerability assessments and security configuration audits; managing information security initiatives; oversight of operational tasks supporting information security functions such as intrusion detection and prevention, security event log analysis, management reporting, malware prevention and remediation, encryption, network segmentation, remote access, cloud security, and authentication; supporting, maintaining, monitoring, troubleshooting and enhancing security infrastructure tools, methodologies, software, and hardware; drafting and reviewing information security policies, processes, and procedures; reviewing information security awareness and education materials and other documentation; determining and documenting information security requirements and controls necessary for the protection of information resources; providing guidance and assistance regarding information security matters such as the interpretation of information security policies and requirements or their applicability to particular situations; independently maintaining automated tools and methodologies in support of Information Security functions; analyzing data from Information Security functions and providing reports and recommended response actions to Information Security management; representing Information Security to other organizations on information security related matters, as assigned; publishing regular status reports and submission to management; and performing other related tasks as assigned.Minimum Qualifications - 1. Bachelor's degree in a related field2. Minimum of five years of related IT experience3.
Demonstrated technical expertise in multiple information security domains4. OR an equivalent combination of education, training and experience5. Excellent team participation skills6.
Good written and verbal communication skillsPreferred Qualifications - 1. Knowledge of information security technologies, methodologies, and best practices in the domains of: security incident response, vulnerability assessment and management, intrusion detection and prevention, system administration (Windows, OS X, Linux, etc.), security administration of networks, operating systems, databases and applications, access control, encryption, firewalls and proxies, networking, security event log analysis, malware prevention and remediation, cloud technologies, programming/scripting, and risk assessment and management2. Security certifications (e.g.SANS/GIAC,CISSP,CISA,CISM).Will this position require driving (personal vehicle, university vehicle, utility vehicle, or golf cart) in order to perform the job duties?
- NoWork Hours - Monday through Friday8:00am-5:00pmAdditional hours as needed for various security updates and projectsList any hazardous conditions or physical demands required by this position - NADoes this position have supervisory responsibility? - No