> Markdown version of [/jobs/ext/1581600-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/1581600-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Christopher Newport University - **Location:** Newport News, United States (Remote available) - **Salary:** $68,534.0 - $89,094.0 - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Burp Suite, Cyber Security, Information Systems, Computer Programming, Query Languages, IT Management, Intrusion Detection Systems, Automation of Marketing, Parsing, Role-Based Access Control, Security Information and Event Management, Subsystems, Software Vulnerability Management, Cloud Platform System, Firewalls (Computer Science), Information Technology, Nessus, Microsoft Sentinel, Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 7, 2026 - **Apply:** https://jobs.cnu.edu/postings/20981/pre_apply ## About the Role * Knowledge of general concepts of information security best practices; IT Governance, Risk Management, and Compliance (GRC) for example NIST CSF, NIST SP 800-39 and NIST SP 800-30 * Knowledge of NIST SP 800-53 rev 5 security controls and the Risk Management Framework (e.g. NIST SP 800-37) * Knowledge of vulnerability scanning and threat mitigation tools such as Microsoft Defender, Tenable Security Center / Nessus, Burp Suite * Knowledge of centralized log management tools such as Splunk, Graylog, Microsoft Sentinel, AWS CloudTrail * Knowledge of common vulnerability management frameworks such as CIS or STIGs * Knowledge of security concepts such as Least Privilege; and Separation of Duties * Ability to think critically, analyze risk, consider possible solutions, and make recommendations * Ability to communicate effectively both verbally and in writing with diverse groups of organizations and people * Ability to develop relationships with and provide guidance to all levels of management regarding employee system access * Willingness to be very flexible, ability to maintain the highest professional standards and competence to be accurate, thorough, and productive with all work * Understanding of system administration for both on-premises and cloud systems * Understanding of defense-in-depth and common security elements * Understanding of the IT Incident Response processes * Regulations such as FERPA, GLBA, PCI * Knowledge of firewalls and IDS/IPS concepts, such as Palo Alto * Demonstrated understanding of technical, engineering, and programmatic capabilities related to information systems and/or subsystems * Familiarity with programming and query languages Education, Experience, Licensure, Certification Required Education: * High school diploma or equivalent education/experience that equates to a high school diploma Experience: * Previous experience in an information security environment * Possession of a current and maintained Information Security certification * Experience documenting security issues, * BA or BS in Information Security, Information Assurance, Computer Science, or related equivalent professional experience * A Master's degree in Computer Science, Cybersecurity, or related technical field Experience: * Experience with security awareness initiatives and training * Experience with information security to include managing systems security architecture, design, and/or operational planning on an enterprise level * Experience with information security to include managing systems security installation and risk remediation activities on an enterprise level * Experience with system authorizations and supporting security documentation development such as System Security Plans (SSP) * Experience with system authorizations and supporting security documentation development such as System Access Requests * Experience with system authorizations and supporting security documentation development such as Plans of Actions and Milestones (POA&M) * Significant experience working with centralized logging solutions (Security Incident and Event Management, SIEM) * Experience working with parsing events for SIEM ingestion * Experience developing SIEM dashboards/reports * Demonstrated hands-on experience with continuous monitoring, including vulnerability and compliance verification (using solutions such as Tenable Security Center / Nessus, Microsoft Defender, and/or other similar solutions) * Experience working in a higher education environment, 6. * Do you have a high school diploma or equivalent education/experience that equates to a high school diploma? + Yes + No 7. * Do you have previous experience in an information security environment? ## Description Designated Personnel Yes Responsible Employee This position is designated as a "responsible employee" who has the authority to redress sexual violence, who has the duty to report incidents of sexual violence or other student misconduct, or who a student could reasonably believe has this authority or duty. If Designated Personnel, please paste statement This position is a "designated position" meaning this position could potentially be required to work (depending on the event) during an emergency closing. Statement of Economic Interest No If Statement of Economic Interest, please paste statement Is this a restricted position subject to availability of funding? If Restricted Position, please paste statement Departmental Objective To inspire and foster partnerships that focus on innovative solutions for ubiquitous access and use of information services to support educational and cultural opportunities that benefit the CNU community. Purpose of the Position The Information Security Analyst is responsible for implementing the campus' information security program to include reviewing security plans and role-based training requirements, operating security tools and scanners, and responding to security alerts. Knowledge, Skills, and Abilities Related to Position, * This is a classified position. New and returning classified employees are required to complete a 12-month probationary period. * Selected candidate must attend a 2-day New Employee Orientation Program. * This position is designated as an on-campus position and requires regular in-person work at the university's campus. + Selected candidate must be able to perform their duties on campus during assigned work hours. + This position is not eligible for full-time remote work, and requests to negotiate a fully remote arrangement will not be considered. + Any telework opportunities are limited, subject to university policy and departmental approval, and may be modified or discontinued at any time. Is this position telework eligible? Yes Telework Eligibility Disclaimer This position is eligible for periodic telework as determined by the department. Eligibility is not guaranteed, and is subject to supervisor approval. Eligibility will depend on the likelihood of the employee's success in a telework arrangement and the supervisor's ability to manage telework. Departments and/or Human Resources may modify or revoke eligibility at any time. Employees will be required to sign a Telework Agreement. Physical/Cognitive Requirements Light Lifting (less than 20 lbs.) Essential Moderate Lifting (20-50 lbs.) Essential Heavy Lifting (more than 50 lbs.) Marginal Pushing/Pulling Essential Standing Essential Sitting Essential Bending Non-Applicable Walking Marginal Climbing Non-Applicable Reaching Non-Applicable Repetitive Motion Non-Applicable List other physical requirements Emotional Demands Fast Pace Essential Average Pace Essential Multiple Priorities Essential Intense Customer Interaction Essential Multiple Stimuli Essential Frequency Changes Essential Mental/Sensory Demands Memory Essential Reasoning Essential Hearing Essential Reading Essential Analyzing Essential Logic Essential Verbal Communication Essential Written Communication Essential List other mental/sensory requirements Posting Detail Information, In order to be considered for this position, your application must provide evidence of experience and/or education supporting the requirements outlined in the posting. We encourage you to be clear and specific when describing your experience. *Responses to supplemental questions alone are not considered evidence of experience and/or education. Quick Link for Direct Access to Posting https://jobs.cnu.edu/postings/20976 Advertising Text EEO/Diversity Statement(s) Christopher Newport University, an EO Employer, is fully Committed to Access and Opportunity. Notice of Non-Discrimination & Title IX Policy Statement Reasonable Accommodation Request Christopher Newport University (CNU) will make a reasonable effort to accommodate persons with disabilities in the application and/or interview process. Persons with disabilities who require accommodation should contact the CNU Human Resources Office by calling (757) 594-7145. Alternative Hiring Process In support of the Commonwealth's commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth's Alternative Hiring Process. To be considered for this opportunity, applicants will need to upload an approved AHP Letter received from the Department for Aging & Rehabilitative Services (DARS) or from the Department for the Blind & Vision Impaired (DBVI) to their applications. Note: Certificates of Disability provided by DARS or DBVI dated April 1, 2022, through February 29, 2024, will still be accepted as applicable for the AHP. The name change to AHP Letter became effective March 1, 2024. Service-Connected Veterans are encouraged to answer Veteran status questions and submit their disability documentation, if applicable, to DARS to get their AHP Letter. Requesting an AHP Letter can be found at AHP Letter or by calling DARS at 800-552-5019. Background Check Applicant finalists are required to complete a CNU sponsored background check. After accepting employment, individuals are required to complete a USCIS Form I-9 (employment eligibility verification) and present documentation from the USCIS List of Acceptable Documents that establishes both their identity and employment authorization to work in the United States. The provided documents will be verified through the Department of Homeland Security E-Verify website., + No 8. * Do you possess and maintain a current Information Security certification? + Yes + No 9. * Do you have experience documenting security issues? + Yes + No 10. Do you have a BA or BS in Information Security, Information Assurance, Computer Science, or related equivalent professional experience? + Yes + No 11. Do you have a Master's degree in Computer Science, Cybersecurity, or a related technical field? + Yes + No 12. Do you have experience with security awareness initiatives and training? + Yes + No 13. Do you have experience with information security to include managing systems security architecture, design, and/or operational planning on an enterprise level? + Yes + No 14. Do you have experience with information security to include managing systems security installation and risk remediation activities on an enterprise level? + Yes + No 15. Do you have experience with system authorizations and supporting security documentation development such as System Security Plans (SSP)? + Yes + No 16. Do you have experience with system authorizations and supporting security documentation development such as System Access Requests? + Yes + No 17. Do you have experience with system authorizations and supporting security documentation development such as Plans of Actions and Milestones (POA&M)? + Yes + No 18. Do you have significant experience working with centralized logging solutions (Security Incident and Event Management, SIEM)? + Yes + No 19. Do you have experience working with parsing events for SIEM ingestion? + Yes + No 20. Do you have experience developing SIEM dashboards/reports? + Yes + No 21. Do you have demonstrated hands-on experience with continuous monitoring, including vulnerability and compliance verification (using solutions such as Tenable Security Center / Nessus, Microsoft Defender, and/or other similar solutions)? + Yes + No 22. Do you have experience working in a higher education environment? + Yes + No 23. * This position is not eligible for full-time remote work and requires regular on-campus presence. Are you able to meet this requirement? + Yes + No Documents Needed To Apply Required Documents Optional Documents 1. Cover Letter 2. Resume 3. Transcripts 4. Licensure/Certification 5. Other Application Materials 6. DD214 7. Yellow Layoff Form 8. Blue Layoff Card 9. AHP Letter ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Building a Compiler with C#](https://www.wearedevelopers.com/videos/116-building-a-compiler-with-c) - [Scrape, Train, Predict: The Lifecycle of Data for AI Applications](https://www.wearedevelopers.com/videos/1652-scrape-train-predict-the-lifecycle-of-data-for-ai-applications) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)