DescriptionThe Information Security Analyst plays a critical role in protecting the University's digital infrastructure and ensuring compliance with security policies and regulatory requirements. This position supports the implementation and management of security technologies, monitors and responds to threats, and helps maintain the confidentiality, integrity, and availability of institutional data. The Analyst collaborates with Information Technology Services (ITS) staff on a variety of tasks, initiatives, and projects to proactively detect, investigate, and remediate security incidents, while also contributing to awareness training and continuous improvement of the University's security posture.
Position Duties- Use programming skills and logic to create automation workflows, playbook development, work with APIs, and troubleshoot within SOAR platforms.
- Develop and optimize searches using query and scripting languages to perform security investigations and threat hunting in SIEM, EDR, and security analytics platforms.
- Monitor, investigate, and respond to incidents using SIEM and security analytics platforms.
- Remediate information security-related service requests in a timely manner based on priority.
- Configure, implement, and test various security systems and technologies.
- Manage and configure host firewalls to restrict access to high-value ports and services.
- Administer endpoint privilege management controls.
- Report and manage vulnerabilities using vulnerability management solutions.
- Occasional ethical use of "Red Team" tools, such as those included in Kali Linux.
- Assist with ongoing security risk assessments, scanning, intrusion detection, monitoring, and remediation.
- Research and stay current on security technologies, trends, legislation, threats, and solutions.
- Administer and deliver security awareness training to faculty, staff, and students.
- Performs other such duties as may be assigned from time to time.
Position Qualifications- Bachelor's degree in Computer Science, Information Systems, Information Security, or a related field is required.
- Strong programming ability (e.g., Python) to support automation workflows, playbook development, and troubleshooting within SOAR platforms.
- Ability to write and optimize searches using query or scripting languages within SIEM and security analytics platforms.
- Familiarity with APIs and modular functions used in security automation tools.
- Familiarity with SIEM technologies.
- Ability to interpret device event logs and identify anomalies in enterprise environments.
- Perform incident response and threat hunting using tools such as EDR, SIEM platforms, and firewalls.
- Ability to test, configure, and deploy endpoint privilege management controls and host firewalls to reduce the attack surface area.
- Interpret and report vulnerabilities using industry-standard tools.
- Familiarity with Active Directory (AD), Group Policy Objects (GPO), and enterprise-level device and application management.
- Knowledge of the OSI model and tools such as Wireshark and Nmap.
- Basic understanding of free cybersecurity tools used for both offensive and defensive purposes (e.g., Kali Linux).
- General understanding of cybersecurity trends, application and device management, and vulnerability management practices.
- Excellent communication and interpersonal skills, including diplomacy in dealing with sensitive information is required.
- Strong analytical skills are required.
- Demonstrated initiative and commitment to continuous learning and skill development.
Supervision ExercisedThe Analyst supports the implementation of a comprehensive University-wide Information Security Program and may supervise student employees from time to time.
Work HoursTypical work hours are Monday through Friday, 9:00 a.m.-5:00 p.m. Some evenings, overnights, and weekends may be necessary. The position participates in on-call rotations to respond to security events outside of normal business hours. This position is based on Pace's Pleasantville campus. It is a hybrid position requiring the employee to be on-site several days per week.