> Markdown version of [/jobs/ext/1448729-it-security-analyst-5353c-information-security-office-87490](https://www.wearedevelopers.com/jobs/ext/1448729-it-security-analyst-5353c-information-security-office-87490). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Analyst (5353C), Information Security Office #87490 - **Company:** University of California - **Location:** Berkeley, CA, United States - **Salary:** $91,500.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Linux, DevOps, Digital Forensics, Distributed Systems, Domain Name System (DNS), Elasticsearch, Web Servers, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Log Analysis, Network Configuration and Change Management, Network Architecture, Red Hat Enterprise Linux, Logstash, Ansible, Ruby, Security Information and Event Management, EndPointSecurity, Load Balancing, Firewalls (Computer Science), Computer Equipment, Performance Monitor, Apache Kafka, Kibana, Terraform, Vulnerability Analysis, Golang - **Published:** July 26, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17710064?backUrl=%2Fcareer%2F17710064%2FIt-Security-Analyst-5353c-Information-Security-Office-87490-California-Berkeley ## About the Role * Experience reading and interpreting logs from a broad range of applications and services used in enterprise IT, with a focus on security relevant logs. * Ability to follow and/or ability to learn department processes and procedures. * Interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization. * Experience using IT security systems and tools, such as Intrusion Detection Systems, Vulnerability Scanners, Firewalls, Security Information and Event Management systems. * Advanced knowledge of computer security best practices and policies including demonstrated experience securing server-based software. * Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks. * Knowledge of computer hardware, software and network security issues and approaches. * Experience with Linux systems, particularly Redhat Enterprise Linux. * Familiarity with web servers, load balancers, firewalls, and DNS. * Ability to write technical documentation in a clear and concise manner. * Understanding of system performance monitoring and actions that can be taken to improve or correct performance. * General knowledge of other areas of IT. * Thorough understanding of and experience with systems and security issues and corrective actions. * Experience automating systems build and provisioning using tools such as Ansible and Terraform. Preferred Qualifications * Experience in incident response and digital forensics including data collection, examination and analysis. * Experience designing, deploying, and maintaining distributed systems, particularly Kafka and Elasticsearch. * Experience deploying containerized systems in a production environment. * Ability to read and write code in one or more of the following: Ruby, Python, Go. * Experience with the Elastic ecosystem, particularly Logstash, Kibana, and Elastic Security. Education / Training * Bachelor's degree in related area and / or equivalent experience / training. (Required) ## Description The Information Security Office (ISO) coordinates the risk management process for UC Berkeley's information systems and directs campus-wide efforts to adequately secure institutional data. ISO is led by the Chief Information Security Officer and consists of seven areas: Information Security Policy, Information Security Operations, Information Security Administration and Engineering, Identity and Access Management, Information Security Assessments, Outreach and Engagement, and Service Management., As a seasoned IT Security Analyst working collaboratively within the Security Engineering team at UC Berkeley, the candidate will focus on systems administration, managing Security Engineering systems, including installation, configuration, and patching of systems and software, while implementing security controls according to best practices to prevent malicious intrusion of systems. The candidate will research and implement systems, services, and technology solutions to support Information Security Office systems and services, writing and executing complex scripts in support of systems management, log analysis, and other system administration duties for multiple integrated systems. Additionally, the candidate will assist in implementing and maintaining various DevOps processes to automate systems provisioning and management. The role involves implementing complex and broad-scale security controls to prevent unauthorized access or changes to campus hardware, software, and network infrastructure, including systems such as Firewalls, TAPs, intrusion detection/prevention systems (IDS/IPS), Endpoint Detection and Remediation (EDR agents), Vulnerability Scanners, and the Security Information and Event Management system (SIEM). The candidate will provide research, analysis, and solutions to address attempted efforts to compromise security protocols, advise the campus community on security prevention, best practices, and secure software, and serve as a subject matter expert, providing analysis and context for security investigations and incidents., 30% * Manages Information Security Office systems, including the installation, configuration, maintenance, and support of systems and software. * Implements security controls according to best practices to prevent malicious intrusion of systems. 30% * Researches, evaluates, and implements systems, services, and technology solutions that support Information Security Office systems and services. * Performs system or device enhancements such as software, hardware, and network configuration, updates and installations for projects or services of moderately complex scope. 15% * Writes and executes complex scripts in support of systems management, log analysis and other duties for multiple integrated systems. * Assist in implementing and maintaining various DevOps processes to automate systems provisioning and management. 10% * Implements complex and broad-scale security controls to prevent and detect unauthorized access or changes to campus hardware, software, and network infrastructure. Systems such as FireWalls, Intrusion Detection/Prevention Systems(IDS/IPS), Endpoint Detection and Remediation (EDR agents), Vulnerability Scanners, and Security Information and Event Management systems (SIEM). * Responsible for providing research, analysis and solutions to address attempted efforts to compromise security protocols. * Advises the campus community on security prevention, best practices and secure software. 5% * Serves as a subject matter expert, providing analysis and context for security investigations and incidents. 5% * Triages security incidents and support tickets as part of a periodic analyst rotation; may participate in responding to security events and operational issues that may require immediate attention and arise during and/or outside of standard hours of operations, including evenings, weekends, and holidays. 5% * Participates in professional development and training activities to maintain expertise in information security, security engineering, and related technologies. * Stays current with evolving threats, tools, and industry best practices, contributes to team knowledge sharing and documentation efforts, and performs other duties as assigned., * This is not a visa opportunity. This position does not include sponsorship of a new consular H-1B visa petition that would require payment of the $100,000 supplemental fee. * This position is governed by the terms and conditions in the agreement for the Technical Unit (TX) between the University of California and the University Professional and Technical Employees (UPTE). The current bargaining agreement manual can be found at: http://ucnet.universityofcalifornia.edu/labor/bargaining-units/tx/index.html Conviction History Background This is a designated position requiring fingerprinting and a background check due to the nature of the job responsibilities. Berkeley does hire people with conviction histories and reviews information received in the context of the job responsibilities. The University reserves the right to make employment contingent upon successful completion of the background check. Misconduct As a condition of employment, the final candidate who accepts a conditional offer of employment will be required to disclose if they have been subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct; received notice of any allegations or are currently the subject of any administrative or disciplinary proceedings involving misconduct; have left a position after receiving notice of allegations or while under investigation in an administrative or disciplinary proceeding involving misconduct; or have filed an appeal of a finding of misconduct with a previous employer. "Misconduct" means any violation of the policies or laws governing conduct at the applicant's previous place of employment, including, but not limited to, violations of policies or laws prohibiting sexual harassment, sexual assault, or other forms of harassment, discrimination, dishonesty, or unethical conduct, as defined by the employer. For reference, below are UC's policies addressing some forms of misconduct: UC Sexual Violence and Sexual Harassment Policy UC Anti-Discrimination Policy Abusive Conduct in the Workplace ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)