What are the responsibilities and job description for the Security Analyst position at The University of St. Augustine for Health...?
The mission of the University of St. Augustine for Health Sciences is the development of professional health care practitioners through innovation, individualized, and quality classroom, clinical, and distance education.
GENERAL SUMMARY
The Security Analyst is responsible for keeping the University safe and secure, and monitors all aspects of data security, with respect to information systems that stores and transmits data that traverses across University assets. This includes ensuring that all information systems are up to date, monitored, and vulnerabilities are remediated.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Collaborate with University IT teams and departments to identify areas of risk to the organization and assist with reducing those risks to acceptable levels.
- Coordinate with systems administrators, developers, and other teams to embed best practices in design and development.
- Ensure network and computing systems devices are up to date with latest versions of software and patches.
- Ensure that all systems are resilient to cyber events using the University Security Information and Event Management (SIEM) tool(s).
- Manage inbound and outbound security rules for email (filtering, whitelists, spam, etc.) through the University tools
- Conduct regular security assessments and audits to identify and remediate any potential security risks to systems and data.
- Work with Crowdstrike on prevention and investigation of security incidents and breaches that may occur.
- Participate in quarterly audit reporting, including reports to leadership and external compliance entities.
- Conduct, monitor, evaluate, and report Key Performance and Key Risk Indicators (KPIs and KRIs) to provide leadership with accurate and timely information regarding the effectiveness of the information security strategy.
- Gather and analyze University data to ensure actionable information is available and responded to in accordance with defined SLAs.
- Communicate, promote and educate the University population on the awareness of information security, information risk, and privacy to business units, customers, and partners.
- Build and maintain a comprehensive vulnerability testing and reporting schedule. This includes actively threat hunting to identify vulnerabilities within university assets and building a plan for remediation of vulnerabilities using CrowdStrike Spotlight.
- Provide backup services for the University systems and data.
OTHER DUTIES AND RESPONSIBILITIES
May perform other duties and responsibilities that management may deem necessary from time to time.
POSITION IN ORGANIZATION
Reports to: Director, Information Security
Positions Supervised: None
EDUCATION and/or EXPERIENCE
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or related field.
- 1-2 years in a Cybersecurity role.
- Strong understanding and/or experience with Security Information and Event Management (SIEM), vulnerability management, penetration testing, authentication methods, Identity and Access Management (IAM), anti-malware and malware analysis/remediation, Endpoint Detection Response (EDR/XDR), Intrusion Detection and Intrusion Prevention Systems (IDS/IPS), web application firewalls, File Integrity Monitoring (FIM), incident response/forensics, physical access controls and security best practices
- Understand security & policy configurations in Office 365 is a plus.
- The ability to understand firewall and network configurations (Meraki) is a plus.
- Experience and knowledge of back-up services (cloud and physical).
- Practical experience in monitoring networks, investigating security incidents, and analyzing threats.
- Current certifications such as CompTIA Security , CEH (Certified Ethical Hacker), Cisco CCNA Security, Microsoft MTA Security Fundamentals and AWS Certified Security.
- Ability to work collaboratively as part of a team, and to interact effectively with colleagues, administrators, faculty, staff and students as well as external constituencies.
- Excellent written and verbal communication skills and a proactive mindset.
- Ability to a work a flexible schedule, including evenings.
TRAVEL
Up to 20% travel required to campus locations in the U.S.
BUSINESS COMPETENCIES
To perform the job successfully, an individual should demonstrate the following competencies:
- Collaborates - Building partnerships and working collaboratively with others to meet shared objectives.
- Being Resilient - Rebounding from setbacks and adversity when facing difficult situations.
- Instills Trust - Gaining the confidence and trust of others through honesty, integrity, and authenticity.
- Drives Results - Consistently achieving results, even under tough circumstances.
- Innovation - Creating new and better ways for the organization to be successful.
- Customer Focus - Building strong customer relationships and delivering customer-centric solutions.
WORK ENVIRONMENT
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; and talk or hear. The employee frequently is required to stand and walk. The employee is occasionally required to reach with hands and arms and stoop, kneel, crouch, or crawl. The employee must occasionally lift and/or move up to 40 pounds. Specific vision abilities required by this job include close vision, distance vision, color vision, peripheral vision, depth perception, and ability to adjust focus. Work involves operation of personal computer equipment for six to eight hours daily and includes physical demands associated with a traditional office setting such as communicating and other physical functions as necessary.