University of Utah

Information Security Analysts

University of Utah$73K — $93K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent plus 4 years related experience; or Master's degree plus 2 years experience.
  • 4 years of cybersecurity operations, threat triage, or incident response experience.
  • Strong expertise in log analysis across various platforms: Windows/Linux, cloud (AWS, Azure, GCP), network traffic analysis.
  • Proficiency in querying and log analysis using languages like KQL, SPL, YARA.
  • Working knowledge of the MITRE ATT&CK framework for investigations and reporting.

Responsibilities

  • Perform in-depth investigations and root cause analysis for complex security incidents.
  • Serve as primary escalation point for Tier 1 analysts, providing technical guidance.
  • Draft detailed incident postmortem reports for internal stakeholders.
  • Partner with Tier 3 analysts to optimize detection logic and reduce false positives.
  • Analyze adversary behavior using the MITRE ATT&CK framework and assist in threat hunting campaigns.
  • Mentor Tier 1 SOC analysts through shift handovers and investigation reviews.
  • Identify operational bottlenecks and propose SOC workflow improvements.

Benefits

  • Eligible for participation in Utah Retirement Systems.
  • Comprehensive health benefits including medical, dental, and vision coverage.
  • Generous paid time off including holidays and vacation.
  • Access to professional development opportunities and continuing education.
  • Supportive work environment with emphasis on diversity and inclusion.
Full Job Description
Announcement

Details

Open Date
09/14/2026

Requisition Number
PRN46212B

Job Title
Information Security Analysts

Working Title
Cybersecurity Analyst Tier 2

Career Progression Track
P00

Track Level
P2 - Developing

FLSA Code
Computer Employee

Patient Sensitive Job Code?
No

Standard Hours per Week
40

Full Time or Part Time?
Full Time

Shift
Rotating

Work Schedule Summary

Four ten hour shifts a week. Position will rotate between day and evening shifts to include holidays and weekends.

VP Area
President

Department
00954 - UIT Systems & Security

Location
Campus

City
Salt Lake City, UT

Type of Recruitment
External Posting

Pay Rate Range
$73,000.00 - 93,000.00

Close Date
09/22/2026

Priority Review Date (Note - Posting may close at any time)

Job Summary

Information Security Analysts

The University of Utah has an opportunity for a Cybersecurity Analyst Tier 2 (Security Operations Center) to help support our Information Security and Compliance goals. The Tier 2 SOC analyst will drive mid-tier incident investigations, perform root cause analysis, and help optimize our operational capabilities. Operating as the primary escalation bridge between Tier 1 monitoring and Tier 3 engineering, you will handle complex security events, collaborate closely with Tier 3 analysts to tune detection rules, refine response playbooks, and mentor junior analysts.

Responsibilities

Information Security Analyst II

Incident Response:
- Perform in-depth investigations, root cause analysis, and containment activities for escalated, complex, or multi-vector security incidents across endpoint, network, cloud, and identity domains
- Serve as the primary escalation point for Tier 1 analysts, providing technical guidance during active triage and validating escalation quality.
- Perform initial scoping and technical artifact analysis to support response actions and prevent incident propagation.
- Draft clear, detailed incident postmortem reports and document technical findings for internal stakeholders.

Detection & Playbook Optimization:
- Partner with Tier 3 analysts to tune, refine, and update existing detection logic across SIEM, EDR, and cloud security platforms to reduce false positives and improve alert fidelity.
- Identify detection coverage gaps and telemetry blind spots during investigations, providing actionable recommendations to Tier 3 for new rules or detection enhancements.
- Assist Tier 3 analysts in testing, providing feedback on, and maintaining automated response workflows (SOAR) to streamline routine SOC tasks.

Threat Analysis:
- Analyze complex adversary behavior from escalated alerts, mapping attack paths to the MITRE ATT&CK framework.
- Assist Tier 3 analysts in executing structured, hypothesis-driven threat hunting campaigns across corporate and cloud environments.
- Operationalize threat intelligence updates by executing indicator-of-compromise (IOC) sweeps (threat hunting) and validating threat exposure.

Leadership & Team Support:
- Mentor and develop Tier 1 SOC analysts through regular shift handovers, technical guidance, and investigation peer reviews.
- Identify operational bottlenecks and propose improvements to SOC workflows and triage procedures.
- Partner with internal IT and platform teams to address logging gaps and remediate host- or network-level security weaknesses.

Job Code: P34212

Grade: P17

Minimum Qualifications

EQUIVALENCY STATEMENT: 1 year of higher education can be substituted for 1 year of directly related work experience (Example: bachelor's degree = 4 years of directly related work experience).

Information Security Analyst, II: Requires a bachelor's (or equivalency) + 4 years or a master's (or equivalency) + 2 years of directly related work experience.

Preferences

Experience: 4 years dedicated cybersecurity operations, threat triage, or incident response experience in a SOC environment.

Technical mastery: Strong expertise analyzing logs across Windows/Linux, cloud environments (AWS, Azure, GCP), network traffic (PCAP, NetFlow), and identity platforms (Entra ID, Okta).

Querying & Log Analysis: Proficiency using platform query languages (e.g. KQL, SPL, YARA) for deep investigation, log correlation, and evaluating rule performance.

Framework Alignment: Practical working knowledge of applying the MITRE ATT&CK framework to real-world investigations, triage workflows, and post-incident reporting.

Certifications (Preferred): GCIH, GCFA, GSOC, SC-200, CCSP.

Soft Skills: Excellent analytical problem-solving skills and a strong passion for teaching and elevating junior team members. A demonstrated ability to write complex technical reports for a non-technical audience.

Type
Benefited Staff

Special Instructions Summary

Additional Information

The University is a participating employer with Utah Retirement Systems ("URS"). Eligible new hires with prior URS service, may elect to enroll in URS if they make the election before they become eligible for retirement (usually the first day of work). Contact Human Resources at (801) 581-7447 for information. Individuals who previously retired and are receiving monthly retirement benefits from URS are subject to URS' post-retirement rules and restrictions. Please contact Utah Retirement Systems at (801) 366-7770 or (800) 695-4877 or University Human Resource Management at (801) 581-7447 if you have questions regarding the post-retirement rules.

This position may require the successful completion of a criminal background check and/or drug screen.

The University of Utah values candidates who have experience working in settings with students and possess a strong commitment to improving access to higher education.

Veterans' preference is extended to qualified applicants, upon request and consistent with University policy and Utah state law. Upon request, reasonable accommodations in the application process will be provided to individuals with disabilities.

Consistent with state and federal law, the University of Utah does not discriminate based upon race, ethnicity, color, religion, national origin, age, disability, sex, sexual orientation, gender, gender identity, gender expression, pregnancy, pregnancy-related conditions, genetic information, or protected veteran's status. The University does not discriminate on the basis of sex in the education program or activity that it operates, as required by Title IX and 34 CFR part 106. The requirement not to discriminate in education programs or activities extends to admission and employment. Inquiries about the application of Title IX and its regulations may be referred to the Title IX Coordinator, to the Department of Education, Office for Civil Rights, or both.

To request a reasonable accommodation for a disability or if you or someone you know has experienced discrimination or sexual misconduct including sexual harassment, you may contact the Director/Title IX Coordinator in the Office of Equal Opportunity and Title IX (OEO). More information, including the Director/Title IX Coordinator's office address, electronic mail address, and telephone number can be located at the: University of Utah Non-Discrimination page.

Online reports may be submitted at https://oeo.utah.edu

https://publicsafety.utah.edu/safetyreport/ This report includes statistics about criminal offenses, hate crimes, arrests and referrals for disciplinary action, and Violence Against Women Act offenses. They also provide information about safety and security-related services offered by the University of Utah. A paper copy can be obtained by request at the Department of Public Safety located at 1658 East 500 South.

As per University of Utah policy 5-108: Transfer of Benefits Eligible Staff Members, a new hire to the University of Utah who is still serving a 12 month probationary period will not be hired into another University of Utah job (a transfer) until the successful completion of the probationary period.

Similar Jobs

More Jobs at University of Utah

More Information Technology Jobs

Find similar Information Security Analysts jobs: