Security Operations Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
Advertising/Posting Title Security Operations Analyst Posting Summary Conduct in-depth analyses of operational security data sourced from Endpoint Detection and Response (EDR), Intrusion Detection and Prevention Systems (IDPS), and other telemetry sources to identify and mitigate threats to the confidentiality, integrity, and availability of information within the University of Vermont’s digital environment. Act on these analyses to proactively detect, investigate, and respond to security incidents, aligning with the Information Security Office’s mission to protect institutional data and assets.
Participate in UVM’s Cybersecurity Incident Response Team (CSIRT), contributing to real-time threat intelligence, forensic investigations, and response strategies. Work closely with ETS colleagues and partners to monitor and analyze data flow for anomalies, unauthorized access attempts, and potential exfiltration of sensitive data. Engage in continuous improvement of security monitoring and response mechanisms by refining alerting rules, tuning detection models, and leveraging automation where applicable.
Support the Identity and Account Management functions of Enterprise Technology Services by maintaining secure digital identities, enforcing access control policies, and addressing account-related security threats. Investigate and act upon policy violations, abuse complaints, and exceptions to automated identity management processes while upholding strict confidentiality and ensuring compliance with institutional security policies.
Exercise discretion and sound judgment in assessing security events. Maintain operational readiness by staying informed of emerging threats, contributing to proactive defense strategies, and continuously enhancing security response capabilities through ethical, repeatable, and defensible methodologies.
ETS consists of five core units: Client Services, Network Services, Information Security Office, Systems Architecture and Administration (SAA), and Database Administration/Enterprise Application Services. Within this structure, the Information Security Office (ISO) is responsible for daily activities to monitor, document and remediate incidents and risks to the University.
Requirements
Minimum Qualifications (or equivalent combination of education and experience)
- Bachelor’s degree in cyber/information security or related field or equivalent experience
- Recognized information security certification (or ability to acquire within one year).
- One to two years’ direct experience in information security analysis
- Understanding of technical concepts underpinning internet-connected enterprise services
- Ability to communicate effectively in writing, producing high-quality procedural documentation and comprehensive activity and incident reports that enable accurate self-assessment, audit readiness, and continuous improvement within the Information Security Office.
- Effective customer service, communication, and interpersonal skills;
- Ability to instruct or guide clients at all levels of experience in basic account operations, including account management and basic usage of common applications;
- Effective organizational skills, including ability to manage multiple concurrent tasks and support cases;
- Demonstrated ability to apply judgment and work with accuracy in routine cases and in exceptional situations;
- Proficiency with common productivity applications and command line interfaces in Windows, macOS, or Linux., * Professional experience with cybersecurity incident response, endpoint/network forensics, and/or continuous security monitoring;
- Ability to produce admissible documentation and maintain evidentiary chain of custody;
- Experience with cyber threat intelligence platforms;
- Experience with constituent education/outreach and proficiency presenting via remote instruction tools;
- Familiarity with securing cloud-based email, file storage, and applications; experience with enterprise-level security information and event management (SIEM).
Benefits & conditions
Special Conditions Occasional evening and/or weekends required (if non-exempt position, may result in overtime), This position is eligible for a hybrid schedule with an option to split time between campus and elsewhere, in accordance with the university telecommuting policy, Background Check required for this position FLSA Exempt Union Position No Posting Details
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Best Paying Jobs in Technology
Data Analyst Salary in the UK
Dev Digest 134 - Where pixels sing?