University of Cincinnati - Cincinnati, OH

posted 4 months ago

Full-time - Entry Level
Cincinnati, OH
10,001+ employees
Educational Services

About the position

The Information Security Analyst 2 position at the University of Cincinnati is a full-time role that involves joining a dedicated team of information security professionals. This team supports the office of information security, focusing on critical areas such as information security incident response, digital investigations, and digital forensics. The selected candidate will play a vital role in mentoring student workers in the security operations center (SOC) and will collaborate with other information security professionals across the university. In this role, the analyst will be responsible for clearly conveying complex security information to both technical and non-technical stakeholders. They will participate in the development of technical documentation, including designs, specifications, processes, and workflows, while also mentoring and delegating work assignments to student workers. The analyst will engage in multiple low to moderate risk projects, working collaboratively with the team to advance project goals and provide necessary technical assistance. The position requires the analyst to document individual progress on assigned deliverables, gather metrics for their area of responsibility, and ensure that all systems, products, and services meet organizational security standards. They will conduct risk and vulnerability assessments of information systems to identify vulnerabilities and protection needs, assist with providing artifacts for Governance, Risk & Compliance in relation to audits, and work with business units to achieve security objectives. Additionally, the analyst will develop subject matter expertise on security applications and services, conduct information security reviews, assist with cyber investigations, analyze logs and network data, and develop content for information security training programs. The role also involves mentoring non-security teams regarding risk management and incident response, ensuring a comprehensive approach to information security within the university.

Responsibilities

  • Clearly convey complex security information to both technical and non-technical stakeholders.
  • Participate in developing technical documentation (designs, specifications, processes, workflows) and communications.
  • Mentor and delegate work assignments to student workers.
  • Participate in multiple low and moderate risk projects.
  • Work with a team to advance project goals and provide technical assistance.
  • Document individual progress on assigned deliverables.
  • Gather metrics for area of responsibility.
  • Carry out procedures to ensure that all systems, products, and services meet organization security standards.
  • Research information security trends to understand the latest vulnerabilities and threats.
  • Conduct risk and vulnerability assessments of information systems to identify vulnerabilities, risk, and protection needs.
  • Assist with providing artifacts to Governance, Risk & Compliance in relation to internal & external audits.
  • Identify, report, and resolve security risks and violations.
  • Develop subject matter expertise on security applications and services in the area of responsibility.
  • Conduct information security reviews; determine and document risk and impact on the university; provide baseline remediation recommendations.
  • Assist with cyber investigations through forensic fact gathering with a focus on e-discovery.
  • Analyze high volumes of logs, network data, and other attack artifacts in support of incident investigations.
  • Develop content for and present information security training and awareness programs.
  • Develop familiarity with data security laws and regulations applicable to higher education.
  • Participate in troubleshooting processes during and outside of normal business hours and participate in change management.
  • Mentor non-security teams regarding risk management, information security controls, incident analysis, incident response, monitoring, and other operational tasks.

Requirements

  • Bachelor's Degree in Computer Science, Information Technology, Computer Engineering, or related field.
  • Four (4) years of relevant work experience and/or other specialized training can be used in lieu of education requirement.
  • Experience in security tool administration.
  • Basic scripting skills.
  • Basic project management skills.
  • Understanding of system administration.
  • Basic knowledge of network architecture.
  • Moderate understanding of risk and vulnerability management.
  • Basic awareness of incident response.
  • Experience with industry standard security and compliance frameworks.

Nice-to-haves

  • Knowledge of different Cybersecurity tools including EDR, SIEM, Network proxies and firewalls, Security Orchestration Automation and Response (SOAR), eDiscovery platforms, and/or digital forensic tools.
  • Security+, GSEC, or similar professional certification(s).

Benefits

  • Disability insurance
  • Employee assistance program
  • Flexible spending account
  • Health insurance
  • Paid parental leave
  • Paid time off
  • Parental leave
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service