Senior Information Security Analyst
The University of Arizona Foundation · Tucson, AZ · 1 mo ago
On-siteInformation TechnologyFull-time
General Position Summary
As a Senior Information Security Analyst, you’ll have the opportunity to make a meaningful impact by fostering a security-first mindset across the organization. If you’re passionate about cybersecurity, we’d love to hear from you!
Essential Functions/Major Responsibilities
- Monitor security alerts and logs using organization's cybersecurity tools.
- Investigate and respond to security incidents, breaches, and vulnerabilities.
- Perform root cause analysis and recommend corrective actions.
- Conduct vendor security risk assessments and prepare formal reports.
- Analyze security risks and provide recommendations for mitigation.
- Lead security audits, compliance audits, risk assessments, and penetration testing efforts.
- Assist with third-party risk assessments and vendor due diligence.
- Support the development and maintenance of security policies, standards, and procedures.
- Ensure compliance with regulatory requirements and security frameworks.
Knowledge, Skills, and Abilities
- Conduct information cybersecurity training sessions for new employees as part of the onboarding process.
- Develop engaging and informative cybersecurity training materials tailored to different employee roles.
- Provide ongoing cybersecurity awareness education through various training methods (e-learning, webinars, in-person sessions).
- Facilitate personalized training sessions for employees who require additional cybersecurity training.
- Act as a cybersecurity awareness resource, addressing employee inquiries and concerns related to cybersecurity.
- Create and manage phishing simulation campaigns to assess employee awareness and response.
- Track, analyze, and report on phishing campaign results to identify trends and areas for improvement.
- Ensure compliance with security policies by monitoring and reporting on repeated phishing failures.
- Review reported phish emails and follow up with submitter.
- Support compliance audits by ensuring complete and accurate documentation.
- Cook up with key stakeholders to update and maintain the business continuity and disaster recovery plan.
- Update and maintain the incident response plan.
- Serve as the primary liaison with the University of Arizona's Information Security Office, ensuring compliance with its cybersecurity policies.
Minimum Qualifications
- Bachelor’s degree in computer, cybersecurity, or a related field (or equivalent experience).
- 3+ years of experience in cybersecurity work experience required.
- Strong understanding of information security principles, phishing threats, and social engineering tactics.
- Experience with phishing simulation tools and security awareness platforms.
- Excellent communication, presentation, and superb customer service.
- Excellent problem-solving, analytical, and organizational skills.
- High attention to detail and commitment to confidentiality and integrity.
- Ability to work collaboratively with teams across the organization.
- Knowledge of security compliance frameworks (e.g., NIST, ISO 27001, SOC 2) is a plus.