This job was posted by https://www.vermontjoblink.com : For more
information, please see: https://www.vermontjoblink.com/jobs/1410596

Security Operations Analyst
Posting Summary
Conduct in-depth analyses of operational security data sourced from
Endpoint Detection and Response (EDR), Intrusion Detection and
Prevention Systems (IDPS), and other telemetry sources to identify and
mitigate threats to the confidentiality, integrity, and availability of
information within the University of Vermont's digital environment. Act
on these analyses to proactively detect, investigate, and respond to
security incidents, aligning with the Information Security Office's
mission to protect institutional data and assets.
Participate in UVM's Cybersecurity Incident Response Team (CSIRT),
contributing to real-time threat intelligence, forensic investigations,
and response strategies. Work closely with ETS colleagues and partners
to monitor and analyze data flow for anomalies, unauthorized access
attempts, and potential exfiltration of sensitive data. Engage in
continuous improvement of security monitoring and response mechanisms by
refining alerting rules, tuning detection models, and leveraging
automation where applicable.
Support the Identity and Account Management functions of Enterprise
Technology Services by maintaining secure digital identities, enforcing
access control policies, and addressing account-related security
threats. Investigate and act upon policy violations, abuse complaints,
and exceptions to automated identity management processes while
upholding strict confidentiality and ensuring compliance with
institutional security policies.
Exercise discretion and sound judgment in assessing security events.
Maintain operational readiness by staying informed of emerging threats,
contributing to proactive defense strategies, and continuously enhancing
security response capabilities through ethical, repeatable, and
defensible methodologies.
ETS consists of five core units: Client Services, Network Services,
Information Security Office, Systems Architecture and Administration
(SAA), and Database Administration/Enterprise Application Services.
Within this structure, the Information Security Office (ISO) is
responsible for daily activities to monitor, document and remediate
incidents and risks to the University.
**Minimum Qualifications (or equivalent combination of education and
experience)**
Bachelor's degree in cyber/information security or related field or
equivalent experience
Recognized information security certification (or ability to acquire
within one year).
One to two years' direct experience in information security
analysis
Understanding of technical concepts underpinning internet-connected
enterprise services
Ability to communicate effectively in writing, producing
high-quality procedural documentation and comprehensive activity and
incident reports that enable accurate self-assessment, audit
readiness, and continuous improvement within the Information
Security Office.
Effective customer service, communication, and interpersonal skills;
Ability to instruct or guide clients at all levels of experience in
basic account operations, including account management and basic
usage of common applications;
Effective organizational skills, including ability to manage
multiple concurrent tasks and support cases;
Demonstrated ability to apply judgment and work with accuracy in
routine cases and in exceptional situations;
Proficiency with common productivity applications and command line
interfaces in Windows, macOS, or Linux.
Desirable Qualifications
Professional experience with cybersecurity incident response,
endpoint/network forensics, and/or continuous security monitoring;
Ability to produce admissible documentation and maintain evidentiary
chain of custody;
Experience with cyber threat intelligence platforms;
Experience with constituent education/outreach and proficiency
presenting via remote instruction tools;
Familiarity with securing cloud-based email, file storage, and
applications; experience with enterprise-level security information
and event management (SIEM).
Anticipated Pay Range
$65000-$75000
Other Information
Special Conditions
Occasional evening and/or weekends required (if non-exempt position, may
result in overtime), This position is eligible for a hybrid schedule
with an option to split time between campus and elsewhere, in accordance
with the university telecommuting policy, Background Check required for
this position
FLSA
Exempt
Union Position
No
Job Location
Burlington, Vermont, United States
Job Close Date (Jobs close at 11:59 PM EST.)
Open Until Filled
Department
Information Secu