Information Security Analyst
Role details
Job location
Tech stack
Job description
The Information Security Analyst will be responsible for assisting the Chief Information Security Officer/Director of Information Security in developing and maintaining Binghamton University's information security capabilities, implementing security controls, responding to information security incidents, and monitoring administrative, academic systems, and the University network for policy enforcement and compliance. The Information Security Analyst will work with cross-functional teams to design and implement security initiatives; serve as a resource person on specific information security technologies and technology-related compliance requirements.
The Information Security Analyst reports to the Chief Information Security Officer/Director of Information Security and works closely with Information Technology Services (ITS) leadership to build awareness and implementation of security controls within the department and across the University.
In addition, the Information Security Analyst will:Triage, process, and close out technical client requestsTrack and ensure adequate and timely resolution to all audit and risk assessment findings or issues relating to information securityRecommend remediation strategies and technologies for mitigating risksEvaluate current and future requirements and develop or recommend technical and operational solutions accordinglySupport and manage risk mitigation tools as neededDevelop specifications and standards for equipment, software, and procedures in support of University policiesInvestigate internal and external reports of information security issuesAssist in analyzing results from intrusion detection systems, intrusion prevention systems, network mapping software, log analysis, and other tools to detect, respond to, and mitigate information security related vulnerabilities and incidentsMaintain audit and oversight of processes, procedures, and tools used to ensure security controlsMaintain metrics and prepare reportsPerform trend and root cause analysisLiaison with various University constituencies on behalf of the CISO as neededServes as a resource person in assessing systems, processes, and projects against compliance requirements, control objectives, and security best practices; interacts with internal and external technical staff and consults with project teams at various stages of project cyclesMust be able to maintain data confidentiality and compliance with regulatory requirements (GLBA, CMMC, HIPAA, FERPA, PCI, etc.)This is a fully in-person position located at Binghamton University's main campus in Vestal, NY.
Requirements
Requirements:Bachelor's degree in a relevant field (completed by May 2026), OR an Associate's degree plus 2 years of professional Information Security experienceProven ability to apply core Information Security concepts (e.g., CIA triad, risk assessment, or encryption) through completed coursework, certifications, or professional projectsExperience producing technical documentation, such as lab reports, incident summaries, or system walkthroughs, for a technical or non-technical audienceDocumented experience contributing to a shared goal within a team environment (e.g., senior capstone projects, professional workgroups, or student organizations)Demonstrated ability to manage multiple concurrent tasks or projects with competing deadlines in an academic or professional settingPreferred:Professional experience with Incident Management/Response and EDR toolsTechnical proficiency in querying and analyzing log files within SPLUNK, Microsoft Sentinel, or similar SIEM platformsHands-on experience navigating Google Security Center or Microsoft 365 Security CenterWorking knowledge of network topologies, architectures (OSI model), protocols (TCP/IP), and addressing schemesExperience operating Unix and Windows-based security tools (e.g., nmap, Snort, or Group Policy Management)Ability to write or modify scripts in Python, PHP, or Powershell to automate security tasksExperience implementing or auditing Data Loss Prevention (DLP) strategiesKnowledge of regulatory frameworks, including NIST, PCI-DSS, FERPA, GLBA, HIPAA, DFARS, CMMC, ITIL/ITSM or ITARExperience working within large-scale, complex environments such as Higher Education, Healthcare, or Research facilitiesExperience using, configuring, or securing AI models and automated agentsVisa sponsorship is not available for this position. If you currently need sponsorship or will need it in the future to maintain employment authorization, you do not meet eligibility requirements. Additionally, please note that Binghamton University is not an E-Verify employer.
Benefits & conditions
Salary: Commensurate with experience