Summary
The University of California, Riverside is seeking an Information Security Analyst to support its Information Security Office governance, risk management, compliance, and awareness program. The role conducts risk assessments, coordinates audits, maintains security policies and procedures, manages awareness training, performs vulnerability assessments and security reviews, and recommends risk mitigation controls.
Responsibilities
- The Information Security Analyst is responsible for the implementation of the Information Security Office governance, risk management, compliance, and awareness program
- The position will conduct risk assessments; coordinate audit engagements with relevant parties; maintain policies, standards and procedures designed to safeguard information and resources; manage information security awareness training
- In addition, conduct vulnerability assessments and security reviews through vulnerability scans and penetration tests to determine deviations from acceptable configurations, policies, and standards
- Finally, the incumbent will assess levels of risk and recommend appropriate mitigation controls
Skills
- Bachelor's degree in related area and/or equivalent experience/training
- Minimum of 4 - 7 years of related experience in information security, IT risk management, compliance, or a related field
- Experience managing, configuring, or auditing security controls across multiple operating systems (e.g., Windows, Linux, UNIX)
- Experience conducting IT risk assessments or Third-Party Risk Assessments using industry-standard frameworks
- Experience with security and privacy related regulations such as FERPA, HIPAA, PCI, etc
- Basic skill at reading and interpreting security logs
- Ability to follow department processes and procedures
- Interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization
- Experience using IT security systems and tools
- Knowledge of data encryption techniques
- Experience analyzing logs for security breaches
- Demonstrated skills applying security controls to computer software and hardware
- Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks
- Knowledge of computer hardware, software and network security issues and approaches
- Demonstrated experience selecting and applying appropriate data encryption technologies
- Experience designing, executing, or supporting cybersecurity awareness training or campus-wide outreach programs (such as phishing simulations)
- Experience working in higher education
- Knowledge of other areas of IT, department processes and procedures
- Experience in incident response and digital forensics including data collection, examination and analysis
- Familiarity with leveraging Artificial Intelligence (AI) tools to automate or streamline administrative tasks, report writing, or content generation
Qualifications
Must Haves
- Bachelor's degree in related area and/or equivalent experience/training
- Minimum of 4 - 7 years of related experience in information security, IT risk management, compliance, or a related field
- Experience managing, configuring, or auditing security controls across multiple operating systems (e.g., Windows, Linux, UNIX)
- Experience conducting IT risk assessments or Third-Party Risk Assessments using industry-standard frameworks
- Experience with security and privacy related regulations such as FERPA, HIPAA, PCI, etc
- Basic skill at reading and interpreting security logs
- Ability to follow department processes and procedures
- Interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization
- Experience using IT security systems and tools
- Knowledge of data encryption techniques
- Experience analyzing logs for security breaches
- Demonstrated skills applying security controls to computer software and hardware
- Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks
- Knowledge of computer hardware, software and network security issues and approaches
- Demonstrated experience selecting and applying appropriate data encryption technologies
Nice to Haves
- Experience designing, executing, or supporting cybersecurity awareness training or campus-wide outreach programs (such as phishing simulations)
- Experience working in higher education
- Knowledge of other areas of IT, department processes and procedures
- Experience in incident response and digital forensics including data collection, examination and analysis
- Familiarity with leveraging Artificial Intelligence (AI) tools to automate or streamline administrative tasks, report writing, or content generation
Benefits
- This position is classified as predominantly remote with occasional visits to campus as needed.