Information Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+11 more
Job description
Gwynedd Mercy University is looking for an Information Security Analyst to help protect the university’s systems, data, and people and continually improve our overall security posture.
This is a broad, hands-on role within a collaborative IT team. The analyst will monitor and respond to security events, identify and remediate vulnerabilities, strengthen identity and access controls, help secure endpoints and infrastructure, review technology and vendors for security risk, and support the university’s security awareness and compliance efforts.
We are looking for someone who takes ownership of problems rather than simply identifying them for someone else to solve. At the same time, this is a team environment. The right person knows when to act independently, when to collaborate, and when to escalate.
This position also works directly with students, faculty, and staff when security issues affect them. We want someone who is patient, respectful, and helpful while remaining professional and security-conscious. Being helpful does not always mean giving someone the answer they want., * Monitor security alerts, logs, endpoints, accounts, and other sources for suspicious activity; investigate events and take or coordinate appropriate action.
- Serve as a primary technical resource for cybersecurity incidents, including phishing, compromised accounts, malware, and other security events.
- Identify, prioritize, and help remediate vulnerabilities and security configuration weaknesses across endpoints, servers, networks, applications, and cloud services.
- Help secure identity and access systems, including MFA, privileged access, administrative and service accounts, authentication, permissions, and account lifecycle processes.
- Work with Infrastructure, Technical Services, and other IT staff to improve endpoint, network, server, cloud, and data security.
- Review software, cloud services, vendors, applications, and integrations for cybersecurity and data-protection risk and recommend practical ways to mitigate identified concerns.
- Support security frameworks, regulatory requirements, audits, cyber insurance activities, documentation, security awareness, and incident-response planning.
- Develop and track meaningful security metrics and help identify trends, recurring weaknesses, and opportunities for improvement.
- Work directly with students, faculty, and staff affected by security incidents, helping them restore secure access while ensuring appropriate security measures are completed.
Who We Are Looking For
The way you approach your work matters as much as the specific products you already know. We are looking for someone who:
- Is intellectually curious and wants to understand how and why things work.
- Takes ownership and follows problems through to resolution.
- Wants to do excellent work and leave the organization better than they found it.
- Communicates clearly and professionally with both technical and non-technical people.
- Treats people with patience and respect without compromising appropriate security practices.
- Uses good judgment when balancing security, usability, and institutional needs.
- Works well as part of a team and can disagree constructively, explain their reasoning, and listen to other perspectives.
- Takes initiative without becoming a cowboy and knows when to involve others.
- Continually learns and adapts as technology and cybersecurity threats change.
Requirements
We do not expect candidates to arrive knowing every system we use. Experience with our technology environment is a plus, but strong security fundamentals, intellectual curiosity, sound judgment, communication skills, and the ability to learn are more important.
We are looking for someone who brings the curiosity, judgment, initiative, technical foundation, and collaborative mindset that are much harder to teach., Candidates should have professional experience in cybersecurity, systems administration, networking, infrastructure, or a related technical field, along with a strong understanding of cybersecurity fundamentals such as endpoint security, identity and access management, networking, logging and monitoring, vulnerability management, authentication, and incident response.
Experience with EDR, SIEM/logging platforms, vulnerability scanners, firewalls, identity systems, or similar security technologies is expected.
A bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field is welcome but is not required with equivalent relevant professional experience.
Experience with our environment is preferred but not required. Technologies currently used at the university include Microsoft Defender and Microsoft security technologies, Entra ID, Microsoft 365, Intune, Windows and Windows Server, macOS, Linux, MFA/SSO technologies, vulnerability and monitoring tools, and KnowBe4.
Experience with Microsoft security technologies, higher education, NIST/CIS frameworks, FERPA, GLBA, PCI-DSS, or relevant certifications such as Security+, CySA+, CISSP, or GIAC is helpful but not required.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Best Coding Boot Camps in Germany
The Overflow: Security and Privacy
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents