Information Security Analyst

Gwynedd Mercy University
Gwynedd Valley, PA, United States
23 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Apple Mac Systems User Authentication Cyber Security Data Security Linux Multi-Factor Authentication Monitoring of Systems Identity and Access Management Microsoft Security Essentials Windows Servers PCI Data Security Standards
+11 more
Cloud Services Anti-Phishing Security Information and Event Management Systems Integration Software Vulnerability Management Data Logging Firewalls (Computer Science) Microsoft InTune Information Technology Network Server Vulnerability Analysis

Job description

Gwynedd Mercy University is looking for an Information Security Analyst to help protect the university’s systems, data, and people and continually improve our overall security posture.

This is a broad, hands-on role within a collaborative IT team. The analyst will monitor and respond to security events, identify and remediate vulnerabilities, strengthen identity and access controls, help secure endpoints and infrastructure, review technology and vendors for security risk, and support the university’s security awareness and compliance efforts.

We are looking for someone who takes ownership of problems rather than simply identifying them for someone else to solve. At the same time, this is a team environment. The right person knows when to act independently, when to collaborate, and when to escalate.

This position also works directly with students, faculty, and staff when security issues affect them. We want someone who is patient, respectful, and helpful while remaining professional and security-conscious. Being helpful does not always mean giving someone the answer they want., * Monitor security alerts, logs, endpoints, accounts, and other sources for suspicious activity; investigate events and take or coordinate appropriate action.

  • Serve as a primary technical resource for cybersecurity incidents, including phishing, compromised accounts, malware, and other security events.
  • Identify, prioritize, and help remediate vulnerabilities and security configuration weaknesses across endpoints, servers, networks, applications, and cloud services.
  • Help secure identity and access systems, including MFA, privileged access, administrative and service accounts, authentication, permissions, and account lifecycle processes.
  • Work with Infrastructure, Technical Services, and other IT staff to improve endpoint, network, server, cloud, and data security.
  • Review software, cloud services, vendors, applications, and integrations for cybersecurity and data-protection risk and recommend practical ways to mitigate identified concerns.
  • Support security frameworks, regulatory requirements, audits, cyber insurance activities, documentation, security awareness, and incident-response planning.
  • Develop and track meaningful security metrics and help identify trends, recurring weaknesses, and opportunities for improvement.
  • Work directly with students, faculty, and staff affected by security incidents, helping them restore secure access while ensuring appropriate security measures are completed.

Who We Are Looking For

The way you approach your work matters as much as the specific products you already know. We are looking for someone who:

  • Is intellectually curious and wants to understand how and why things work.
  • Takes ownership and follows problems through to resolution.
  • Wants to do excellent work and leave the organization better than they found it.
  • Communicates clearly and professionally with both technical and non-technical people.
  • Treats people with patience and respect without compromising appropriate security practices.
  • Uses good judgment when balancing security, usability, and institutional needs.
  • Works well as part of a team and can disagree constructively, explain their reasoning, and listen to other perspectives.
  • Takes initiative without becoming a cowboy and knows when to involve others.
  • Continually learns and adapts as technology and cybersecurity threats change.

Requirements

We do not expect candidates to arrive knowing every system we use. Experience with our technology environment is a plus, but strong security fundamentals, intellectual curiosity, sound judgment, communication skills, and the ability to learn are more important.

We are looking for someone who brings the curiosity, judgment, initiative, technical foundation, and collaborative mindset that are much harder to teach., Candidates should have professional experience in cybersecurity, systems administration, networking, infrastructure, or a related technical field, along with a strong understanding of cybersecurity fundamentals such as endpoint security, identity and access management, networking, logging and monitoring, vulnerability management, authentication, and incident response.

Experience with EDR, SIEM/logging platforms, vulnerability scanners, firewalls, identity systems, or similar security technologies is expected.

A bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field is welcome but is not required with equivalent relevant professional experience.

Experience with our environment is preferred but not required. Technologies currently used at the university include Microsoft Defender and Microsoft security technologies, Entra ID, Microsoft 365, Intune, Windows and Windows Server, macOS, Linux, MFA/SSO technologies, vulnerability and monitoring tools, and KnowBe4.

Experience with Microsoft security technologies, higher education, NIST/CIS frameworks, FERPA, GLBA, PCI-DSS, or relevant certifications such as Security+, CySA+, CISSP, or GIAC is helpful but not required.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

6:24 min

Common information security tools and terminologies

Antonio De Mello +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all