Information Security Analysts
University Information Technology (UIT) is the central IT service provider for the University of Utah, reporting to the Chief Information Officer. UIT manages shared IT services including wired and wireless networks, the Campus Information Services (CIS) portal, UMail, telephone and online collaboration tools, digital learning technologies, information security, software licensing, and other IT systems and services.
The University of Utah, located in Salt Lake City, is the flagship institution of Utah’s higher education system. It offers arts and museum venues, is a member of the BIG-12 Conference, and provides access to outdoor activities such as skiing, snowboarding, biking, hiking, and fishing. Salt Lake City is home to cultural institutions like the Utah Symphony and Opera, Ballet West, professional sports teams, and a wide range of recreational opportunities.
About the role
The Information Security Office is seeking a motivated Information Security Analyst II to join the Security Assurance team, primarily focused on Vulnerability Management. In this role, you will help safeguard the University’s educational, hospital, and clinics IT infrastructures by identifying and addressing vulnerabilities while collaborating with cross-functional teams to enhance overall security. This position offers opportunities for skill development and career advancement in a fast-paced, inclusive environment.
Responsibilities
- Lead efforts to identify and track vulnerabilities across systems, applications, and networks using tools like Qualys VMDR, Microsoft Defender for Endpoint, and Tanium.
- Evaluate identified vulnerabilities to determine business risk based on severity, exposure to threats, and potential impact on organizational systems and operations.
- Analyze scan results from vulnerability management tools to prioritize remediation and provide actionable recommendations through detailed reports to stakeholders.
- Collaborate with IT teams responsible for infrastructure to ensure vulnerabilities are effectively addressed.
- Maintain comprehensive records of vulnerabilities, mitigation steps, and monitoring practices. Create dashboards in relevant tools.
- Stay informed about emerging threats, vulnerabilities, and industry best practices to enhance security measures.
- Support adherence to security policies, standards, and relevant regulatory frameworks.
- Perform other duties as assigned.
Requirements
- Bachelor’s degree (or equivalency) plus 4 years of directly related work experience, or a master’s degree (or equivalency) plus 2 years of directly related work experience.
- Equivalency: 1 year of higher education may substitute for 1 year of directly related work experience (e.g., a bachelor’s degree equals 4 years of experience).
Qualifications
- Strong understanding of information technologies, operating systems, and IT vulnerability management.
- Experience with systems administration for servers and/or desktops.
- Analytical and problem-solving skills to assess threats and recommend solutions.
- Effective communication skills for reporting vulnerabilities and collaborating with IT stakeholders.
- Passion for learning and staying ahead of emerging cybersecurity trends.
- Industry certifications such as GIAC GCIH (Global Certified Incident Handler) or CompTIA Security+ (preferred).
Benefits
- The University is a participating employer with Utah Retirement Systems (URS). Eligible new hires with prior URS service may elect to enroll if they make the election before becoming eligible for retirement (usually the first day of work). Contact Human Resources at (801) 581-7447 for details.
- Individuals previously retired and receiving monthly retirement benefits from URS are subject to URS’ post-retirement rules and restrictions. Contact URS at (801) 366-7770 or (800) 695-4877, or University Human Resource Management at (801) 581-7447 for questions.
- This position may require the successful completion of a criminal background check and/or drug screen.