> Markdown version of [/jobs/ext/2290542-information-security-consultant-vra-assessor-it-scrty-anl-4-tx](https://www.wearedevelopers.com/jobs/ext/2290542-information-security-consultant-vra-assessor-it-scrty-anl-4-tx). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Consultant, VRA Assessor (IT SCRTY ANL 4 TX) - **Company:** University of California, Davis - **Location:** Davis, CA, United States (Remote available) - **Experience:** Experienced - **Salary:** $107,511.0 - **Contract:** Permanent contract - **Skills:** Microsoft Excel, Artificial Intelligence, Cyber Security, Data Security, Network Security, Microsoft Visio, Open Source Technology, Peer-To-Peer (P2P), Productivity Software, Software Requirements Analysis, Information Technology, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88166116/1 ## About the Role Minimum Qualifications - For full consideration, applicants are encouraged to upload license and/or certification if required of the position * Bachelor's degree in related area or an equivalent experience/training * Minimum of four years of experience reviewing and/or assessing information security reports, advisories, bulletins, or other relevant intelligence and conduct risk assessments. * Experience using information assurance (IA) principles and organizational requirements that are relevant to condentiality, integrity, availability, authentication, and non-repudiation. * Experience consulting with clients/customers. * Experience working with information security frameworks and standards such as ISO, NIST and regulations related to information security such as PCI, HIPAA, FISMA, SB 1386, etc. * Experience coordinating multiple simultaneous activities with strict deadlines, complex scheduling requirements while effectively organizing and managing time to achieve project goals and provide project status reports to clients and management. * Strong proficiency with common productivity software such as Microsoft Visio and Excel., * Information security certification (e.g., CRISC, CISSP, CISA, GIAC or PCI). * Experience working in higher education. * Experience working with and/or developing AI assisted risk assessments. * Experience with conducting numerical risk analysis. * Incident handling and forensics experience. * Knowledge of network security architecture concepts, including topology, protocols, components, and principles (e.g., application of defense-in-depth). * Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard information technology [IT]) for safety, performance, and reliability. * Knowledge of computer network defense (CND) and vulnerability assessment tools, including open-source tools, and their capabilities. * Familiarity with IT supply chain security/risk management policies, requirements and procedures. * Understanding of security requirements and strategies for "cloud hosted" environments., * Chemicals, dust, gases, or fumes - Never 0 Hours * Loud noise levels - Never 0 Hours * Marked changes in humidity or temperature - Never 0 Hours * Microwave/Radiation - Never 0 Hours * Operating motor vehicles and/or equipment - Never 0 Hours * Extreme Temperatures - Never 0 Hours * Uneven Surfaces or Elevations - Never 0 Hours Mental Demands * Sustained attention and concentration - Continuous 6 to 8+ Hours * Complex problem solving/reasoning - Continuous 6 to 8+ Hours * Ability to organize & prioritize - Continuous 6 to 8+ Hours * Communication skills - Continuous 6 to 8+ Hours * Numerical skills - Frequent 3 to 6 Hours * Constant Interaction - Continuous 6 to 8+ Hours * Customer/Patient Contact - Continuous 6 to 8+ Hours * Multiple Concurrent Tasks - Continuous 6 to 8+ Hours ## Description Under the general direction of the Cyber Risk and Compliance Manager, the Information Security Consultant (ISC) manages security and data protection solutions that support the mission of the university and protect the confidentiality, integrity, and availability of information assets owned or entrusted to UC Davis. The ISC evaluates, and supports the documentation, validation, assessment, and accreditation processes necessary to assure that new and existing information technology (IT) systems and services meet the University's information assurance (IA) and security requirements. The ISC prepares/maintains various security reports and dashboards, participates in security assessments and audit activities, prepares and reviews system security architecture designs, actively participates with business and campus units throughout the university community. The ISC tracks and reports on security risks and control effectiveness to the CISO and other campus stakeholders such as the Chief Information Officer, peers located on the Davis and Sacramento campuses as well as across the systems. The ISC Serves as an example and a peer to others on the team and on campus for the purpose of peer-to-peer knowledge transfer, and to help develop a collaborative community of security professionals. The ISC must stay abreast of evolving campus needs, technology capabilities, and threat intelligence from a variety of sources to optimize data protection measures. The ISC will work with campus stakeholders to ensure data security needs and controls are aligned to support organizational goals and objectives and uses independent thinking to creatively solve problems and issues, makes independent decisions, and must maintain or preserve confidentiality when required to do so. To be considered for this position, candidates must already have authorization to work in the United States. Unfortunately, we are unable to provide visa sponsorship at this time., * 50% - Risk Assessment * 20% - Information Security Consulting * 15% - Incident Response, Vulnerability, And Threat Management * 15% - Documentation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)