> Markdown version of [/jobs/ext/3469579-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/3469579-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Gwynedd Mercy University - **Location:** Gwynedd Valley, PA, United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, User Authentication, Cyber Security, Data Security, Linux, Multi-Factor Authentication, Monitoring of Systems, Identity and Access Management, Microsoft Security Essentials, Windows Servers, PCI Data Security Standards, Cloud Services, Anti-Phishing, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Data Logging, Firewalls (Computer Science), Microsoft InTune, Information Technology, Network Server, Vulnerability Analysis - **Published:** September 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c7424ab42bd6ba98 ## About the Role We do not expect candidates to arrive knowing every system we use. Experience with our technology environment is a plus, but strong security fundamentals, intellectual curiosity, sound judgment, communication skills, and the ability to learn are more important. We are looking for someone who brings the curiosity, judgment, initiative, technical foundation, and collaborative mindset that are much harder to teach., Candidates should have professional experience in cybersecurity, systems administration, networking, infrastructure, or a related technical field, along with a strong understanding of cybersecurity fundamentals such as endpoint security, identity and access management, networking, logging and monitoring, vulnerability management, authentication, and incident response. Experience with EDR, SIEM/logging platforms, vulnerability scanners, firewalls, identity systems, or similar security technologies is expected. A bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field is welcome but is not required with equivalent relevant professional experience. Experience with our environment is preferred but not required. Technologies currently used at the university include Microsoft Defender and Microsoft security technologies, Entra ID, Microsoft 365, Intune, Windows and Windows Server, macOS, Linux, MFA/SSO technologies, vulnerability and monitoring tools, and KnowBe4. Experience with Microsoft security technologies, higher education, NIST/CIS frameworks, FERPA, GLBA, PCI-DSS, or relevant certifications such as Security+, CySA+, CISSP, or GIAC is helpful but not required. ## Description Gwynedd Mercy University is looking for an Information Security Analyst to help protect the university's systems, data, and people and continually improve our overall security posture. This is a broad, hands-on role within a collaborative IT team. The analyst will monitor and respond to security events, identify and remediate vulnerabilities, strengthen identity and access controls, help secure endpoints and infrastructure, review technology and vendors for security risk, and support the university's security awareness and compliance efforts. We are looking for someone who takes ownership of problems rather than simply identifying them for someone else to solve. At the same time, this is a team environment. The right person knows when to act independently, when to collaborate, and when to escalate. This position also works directly with students, faculty, and staff when security issues affect them. We want someone who is patient, respectful, and helpful while remaining professional and security-conscious. Being helpful does not always mean giving someone the answer they want., * Monitor security alerts, logs, endpoints, accounts, and other sources for suspicious activity; investigate events and take or coordinate appropriate action. * Serve as a primary technical resource for cybersecurity incidents, including phishing, compromised accounts, malware, and other security events. * Identify, prioritize, and help remediate vulnerabilities and security configuration weaknesses across endpoints, servers, networks, applications, and cloud services. * Help secure identity and access systems, including MFA, privileged access, administrative and service accounts, authentication, permissions, and account lifecycle processes. * Work with Infrastructure, Technical Services, and other IT staff to improve endpoint, network, server, cloud, and data security. * Review software, cloud services, vendors, applications, and integrations for cybersecurity and data-protection risk and recommend practical ways to mitigate identified concerns. * Support security frameworks, regulatory requirements, audits, cyber insurance activities, documentation, security awareness, and incident-response planning. * Develop and track meaningful security metrics and help identify trends, recurring weaknesses, and opportunities for improvement. * Work directly with students, faculty, and staff affected by security incidents, helping them restore secure access while ensuring appropriate security measures are completed. Who We Are Looking For The way you approach your work matters as much as the specific products you already know. We are looking for someone who: * Is intellectually curious and wants to understand how and why things work. * Takes ownership and follows problems through to resolution. * Wants to do excellent work and leave the organization better than they found it. * Communicates clearly and professionally with both technical and non-technical people. * Treats people with patience and respect without compromising appropriate security practices. * Uses good judgment when balancing security, usability, and institutional needs. * Works well as part of a team and can disagree constructively, explain their reasoning, and listen to other perspectives. * Takes initiative without becoming a cowboy and knows when to involve others. * Continually learns and adapts as technology and cybersecurity threats change. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)