Full Job Description
Information Security Analyst/Engineer - Information Technology Services
Job Description:
Join the University at Albany's Information Technology Services (ITS) as an Information Security Analyst/Engineer and help protect critical infrastructure, institutional data, and research assets in a fast-moving, research-intensive environment at a Carnegie R1 research institution.
We're looking for someone to join a small, senior team that operates with real ownership. You'll work directly with the Chief Information Security Officer (CISO) and partner with network, systems, and application teams. You'll handle modern incident response and network security on a stack that includes Microsoft Defender extended detection and response (XDR), Palo Alto and Cloudflare.
You'll investigate and respond to incidents end-to-end, build automation playbooks that make the next response faster, and manage firewall policy for an institution that takes security seriously. You'll also handle day-to-day triage and ticket work - but the expectation is that you're building systems that reduce that burden over time, not just clearing the queue.
This is an excellent opportunity if you want breadth - incident response (IR), network defense, automation, and engineering - without being siloed into one function.
Primary Responsibilities:
- Incident detection, response, and automation
- Monitor and triage security alerts across endpoints, identity, and cloud workloads using tools such as Microsoft Defender and Sentinel.
- Investigate and respond to incidents end-to-end (scope, contain, eradicate, recover); document actions and escalate as needed.
- Build and improve incident response workflows, including cloud automation playbooks (security orchestration, automation, and response (SOAR) and scripts that reduce time-to-detect and time-to-respond.
- Partner with network, systems, and application teams to contain threats, remediate root causes, and improve detections and preventive controls.
- Network security (firewalls, visibility, and threat-driven monitoring)
- Design, review, and maintain next-generation firewall policies and exceptions (Palo Alto) and web application protections (Cloudflare), including change control and documentation.
- Analyze network telemetry for anomalies; build detections and workflows that correlate network, endpoint, identity, and cloud signals.
- Vulnerability management (secondary/backup)
- Run regular vulnerability scans using Tenable (and similar tools).
- Automate vulnerability tracking and reporting.
- Coordinate remediation with system owners and technical teams.
- Risk and compliance (secondary/backup)
- Support risk assessments, audits, and policy updates.
- Promote security awareness and best practices across campus.
- Engineering and integration (supporting IR and network security)
- Develop and maintain scripts and automation workflows supporting incident response and network security.
- Integrate security tools and data sources (firewall, cloud, endpoint detection and response (EDR)) to improve correlation and response automation.
- Evaluate emerging capabilities to enhance detection, response, and network controls; prioritize solutions that can be operationalized and automated.
- Other reasonable duties as assigned
Functional and Supervisory Relationships:
- Reports to: Chief Information Security Officer
- May supervise employees as assigned
Job Requirements:
- Excellent communication skills and the ability to work effectively with infrastructure teams in a fast-paced environment while balancing security, availability, and operational needs.
- Strong troubleshooting and organizational skills, with the ability to prioritize work and solve complex problems independently.
- Applicants must demonstrate an ability to develop inclusive and equitable relationships within our diverse campus community.
- Applicants must demonstrate an ability to support diversity, equity, access, inclusion, and belonging relative to their role.
Requirements:
Minimum Qualifications:
- Bachelor's degree from a college or university accredited by a U.S. Department of Education (DOE) or an internationally recognized accrediting organization.
- At least 3 years of professional experience in modern incident response, including investigation, containment, remediation, and use of enterprise security tooling such as Microsoft Defender, Microsoft Sentinel, or comparable platforms.
- At least 3 years of professional experience in network security, including hands-on work with technologies and practices such as next-generation firewalls, intrusion detection system/intrusion prevention system (IDS/IPS), segmentation, traffic analysis, or related controls.
- Demonstrated experience collaborating with infrastructure, systems, or application teams to implement security controls, support remediation efforts, or improve operational processes in an enterprise environment.
- Experience using scripting (such as Python or PowerShell), Artificial Intelligence, automation, or security workflows to improve detection, response, or efficiency.
Preferred Qualifications:
- Relevant security certifications (e.g., Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or GIAC Certified Detection Analyst (GCDA)).
- Experience securing cloud and web application environments, including platforms and tools such as Microsoft Azure, Amazon Web Services (AWS), Google Cloud, Cloudflare, Burp Suite, or Open Worldwide Application Security Project (OWASP)-based practices.
- Experience with enterprise detection and response platforms, such as SIEM, XDR, or AI-assisted security operations tools.
- Experience working in higher education or similarly complex environments, including support for institutional AI use, risk management, or compliance initiatives.
Working Environment:
- Available for scheduled after-hours support, including occasional evenings, weekends, or holidays.
- On-site in Albany Mondays, Wednesdays, and Fridays (and as needed). Telecommuting on Tuesdays and Thursdays may be available after a probationary period, with supervisor approval.
Additional Information:
This is a promotional opportunity for current UAlbany employees.
Eligibility for Consideration:
- You must be employed at the University at Albany campus.
- You must be in a State-funded UUP professional position (MC employees are not eligible).
- You must have a permanent, term, or probationary appointment. Only temporary employees employed by UAlbany for three or more consecutive years can be considered eligible.
For details concerning the University's Promotion Policy for Professional Employees, please see HR Memorandum 88-4.
Professional Rank and Salary Grade: Senior Programmer/Analyst, SL4, $90,000-95,000
Special Note: Visa sponsorship is not available for this position. If you currently need sponsorship or will need it in the future to maintain employment authorization, you do not meet eligibility requirements.
Please apply online via http://albany.interviewexchange.com/candapply.jsp?JOBID=204078
Application Instructions:
Applicants MUST submit the following documents:
- Resume
- Cover letter stating all the required minimum qualifications and any of the applicable preferred qualifications
- List of 3 professional references with e-mail addresses and telephone numbers
Note: After submitting your resume, the subsequent pages give you instructions for uploading additional documents (i.e. cover letter etc.).
See the FAQ for using our online system. Please contact us if you need assistance applying through this website.
Returning Applicants - Login to your UAlbany Careers Account to check your completed application.
Closing date for receipt of applications: September 8.