Announcement
Details
Open Date
09/15/2026
Requisition Number
PRN46223B
Job Title
Information Security Analysts
Working Title
Information Security Analyst IV
Career Progression Track
P00
Track Level
P4 - Advanced
FLSA Code
Computer Employee
Patient Sensitive Job Code?
No
Standard Hours per Week
40
Full Time or Part Time?
Full Time
Shift
Day
Work Schedule Summary
Monday through Friday, 8:00 a.m. to 5:00 p.m., with flexibility to work additional hours as needed to meet business or operational requirements.
VP Area
President
Department
00954 - UIT Systems & Security
Location
Campus
City
Salt Lake City, UT
Type of Recruitment
External Posting
Pay Rate Range
$102,000.00 - 117,000.00
Close Date
12/15/2026
Priority Review Date (Note - Posting may close at any time)
Job Summary
Information Security Analyst IV
Monitor, analyze, and maintain systems and procedures to safeguard internal information systems, network, databases, and Web-based security. Conduct vulnerability assessments and monitor systems, network, databases, and Web for potential system breaches / intrusions. Install security measures and operate software to protect systems and information infrastructure, including firewalls and data encryption programs. Respond to alerts from information security tools. Report, investigate, and resolve security incidents. Educate and communicate security requirements and procedures to all users and new employees. Recommend and implement changes to enhance systems security and prevent unauthorized access. Research security trends, new methods, and techniques used in unauthorized access of data in order to preemptively eliminate the possibility of system breach. Ensure compliance with regulations and privacy laws. May oversee internal or external systems security (i.e. cloud services).
Responsibilities
Information Security Analyst IV
• Conduct formal cyber security risk assessments to identify and measure information security risks for applications, devices, systems and networks.
• Have a working knowledge of policies, rules, procedures and guidelines from the University of Utah's regulations website.
• Review and provide analysis for completed inherent risk questionnaires.
• Have an in-depth knowledge of the University Information Security Policy
• Familiarity with HIPAA/HITECH, GDPR, PCI-DSS, and FERPA compliance requirements.
• Have an in-depth knowledge of NIST and CIS controls.
• Prepare and present risk assessment reports.
• Collaborate closely with and strengthen partnerships with other divisions within ISO
• Identify opportunities to improve risk posture, proposing solutions for remediating or mitigating risk and assessing the residual risk.
• Manage relationships with security, technology, and business stakeholders to identify and communicate security risks and mitigation approaches.
• Assist in the continuous development, implementation, and ongoing maintenance of the information security training and awareness program.
• Assist with the development and implementation of solutions and processes to remediate policy gaps.
• Development of guidelines and best practice documents which provide direction to university students, staff and faculty on implementing appropriate controls.
• Participate in compliance assessments.
• Review and provide analysis for Exception to Policy requests.
This job description is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to the job.
Job Code: P34214
Grade: P21
Minimum Qualifications
EQUIVALENCY STATEMENT: 1 year of higher education can be substituted for 1 year of directly related work experience (Example: bachelor's degree = 4 years of directly related work experience).
Information Security Analyst, IV: Requires a bachelor's (or equivalency) + 8 years or a master's (or equivalency) + 6 years of directly related work experience.
Preferences
• A bachelor's degree in information technology or systems, computer science, or equivalent experience in related fields.
• One or more information security or technology risk assessment certifications (Security+, CIPT, CRISC, CISA, etc.)
• Experience developing and implementing information security policy and procedures.
• Experience with information security in a higher-education or healthcare environment.
• Experience assessing and documenting the design of technology controls to effectively mitigate risk.
Type
Benefited Staff
Special Instructions Summary
A writing sample (cover letter) is required. The writing sample should demonstrate the applicant's ability to explain a technical, cybersecurity, risk, or compliance topic to a professional audience.
Additional Information
The University is a participating employer with Utah Retirement Systems ("URS"). Eligible new hires with prior URS service, may elect to enroll in URS if they make the election before they become eligible for retirement (usually the first day of work). Contact Human Resources at (801) 581-7447 for information. Individuals who previously retired and are receiving monthly retirement benefits from URS are subject to URS' post-retirement rules and restrictions. Please contact Utah Retirement Systems at (801) 366-7770 or (800) 695-4877 or University Human Resource Management at (801) 581-7447 if you have questions regarding the post-retirement rules.
This position may require the successful completion of a criminal background check and/or drug screen.