Jobs · Vermont

Security Operations Analyst

University of Vermont · Burlington, VT · 2 wk ago
$65k–$75k/yrFull-time

About the role

Conduct in-depth analyses of operational security data sourced from Endpoint Detection and Response (EDR), Intrusion Detection and Prevention Systems (IDPS), and other telemetry sources to identify and mitigate threats to the confidentiality, integrity, and availability of information within the University of Vermont’s digital environment. Act on these analyses to proactively detect, investigate, and respond to security incidents, aligning with the Information Security Office’s mission to protect institutional data and assets.

Participate in UVM’s Cybersecurity Incident Response Team (CSIRT), contributing to real-time threat intelligence, forensic investigations, and response strategies. Work closely with ETS colleagues and partners to monitor and analyze data flow for anomalies, unauthorized access attempts, and potential exfiltration of sensitive data. Engage in continuous improvement of security monitoring and response mechanisms by refining alerting rules, tuning detection models, and leveraging automation where applicable.

Support the Identity and Account Management functions of Enterprise Technology Services by maintaining secure digital identities, enforcing access control policies, and addressing account-related security threats. Investigate and act upon policy violations, abuse complaints, and exceptions to automated identity management processes while upholding strict confidentiality and ensuring compliance with institutional security policies.

Exercise discretion and sound judgment in assessing security events. Maintain operational readiness by staying informed of emerging threats, contributing to proactive defense strategies, and continuously enhancing security response capabilities through ethical, repeatable, and defensible methodologies.

Responsibilities

  • Analyze security data from EDR, IDPS, and other telemetry sources to identify and mitigate threats.
  • Detect, investigate, and respond to security incidents as part of the Cybersecurity Incident Response Team (CSIRT).
  • Monitor and analyze data flow for anomalies, unauthorized access, and potential data exfiltration.
  • Refine alerting rules, tune detection models, and leverage automation to improve security monitoring and response.
  • Maintain secure digital identities and enforce access control policies.
  • Investigate policy violations, abuse complaints, and exceptions to identity management processes.
  • Produce high-quality procedural documentation and incident reports for audit readiness and continuous improvement.
  • Provide guidance to clients on account management and basic application usage.
  • Stay informed of emerging threats and enhance security response capabilities.

Requirements

  • Bachelor’s degree in cyber/information security or related field or equivalent experience.
  • Recognized information security certification (or ability to acquire within one year).
  • One to two years’ direct experience in information security analysis.
  • Understanding of technical concepts underpinning internet-connected enterprise services.
  • Proficiency with common productivity applications and command line interfaces in Windows, macOS, or Linux.
  • Effective customer service, communication, and interpersonal skills.
  • Ability to manage multiple concurrent tasks and support cases.
  • Demonstrated ability to apply judgment and work with accuracy in routine and exceptional situations.

Qualifications

  • Professional experience with cybersecurity incident response, endpoint/network forensics, and/or continuous security monitoring.
  • Ability to produce admissible documentation and maintain evidentiary chain of custody.
  • Experience with cyber threat intelligence platforms.
  • Experience with constituent education/outreach and proficiency presenting via remote instruction tools.
  • Familiarity with securing cloud-based email, file storage, and applications.
  • Experience with enterprise-level security information and event management (SIEM).

Pay

$65,000 - $75,000

Schedule

  • Occasional evening and/or weekend work required.
  • Hybrid schedule available, with the option to split time between campus and remote work in accordance with university telecommuting policy.

Background check required for this position.

Similar jobs

Security Operations Analyst

Crash ChampionsWestmont, IL· 1 mo ago
Information Technology$80k/yrapply on corporate-crashchampions.icims.com