Information Security Analyst

Security AnalystSecurity AnalystFull TimeHybridSeniorTeam 10,001+H1B No SponsorCompany SiteLinkedIn

Location

Wisconsin

Posted

33 days ago

Salary

$97K - $115K / year

Seniority

Senior

Job Description

Information Security Analyst

University of Wisconsin-Madison

Title: Information Security Analyst Requisition Number: JR10010344 Remote Type: Hybrid Location: Madison, Wisconsin Category: Information Technology Time Type: Full time Job Category: Academic Staff Employment Type: Regular Job Profile: Info Sec Analyst III (Inst) Job Summary: The Risk Management and Compliance (RMC) team within the Office of Cybersecurity is looking for an experienced risk analyst to address the internal security review requests from UW-Madison campus partners. This could include new tools, services, platforms or departmental risk reviews to ensure the security of UW-Madison data at all levels – Public to Restricted (ePHI). This position will work collaboratively with our campus partners, UW-Madison service providers, and third-party vendors to assess risk and present these risks to campus stakeholders. Responsibilities include evaluating current system use and data classification as entered by the system owner, collaboration with the Office of Compliance on privacy risks and presentation of overall risk with opportunities to improve security prior to utilization. Information gathered to establish the data flow and scope of these requests will be entered by campus partners in an enterprise risk review tool (OneTrust). A successful individual will have information security expertise as well as project management, business analysis, solution implementation skills, the ability to communicate to technical, non-technical staff and university leadership. This position reports to the Office of Cybersecurity and serves as a campus technical expert and authority on information security risk analysis and compliance matters. As a trusted advisor and partner with UW-Madison campus partners, UW System integration teams, project managers and system owners, this position will focus on the most efficient and impactful way to review risk of existing tools and present opportunities for improving overall security. This position will also have specific responsibility to assist in the establishment and maintenance of an RMC project management tool to improve overall efficiency. Acquiring feedback from campus partners and liaisons is also required to make procedural adjustments to the service this team offers. The candidate selected for this position may perform a combination of on-site and remote work subject to an approved flexible work arrangement (FWA), which is reviewed and approved annually. Remote work requires successful candidates to possess their own high-speed internet and phone to perform the work on a university provided computer. Per University policy, transportation between home and assigned work location is not payable/reimbursable and will be at the expense of the employee. This position will primarily work remotely but may occasionally need to come to campus for scheduled meetings, retreats, or workshops. The Division of Information Technology (DoIT) is an exciting and dynamic work environment grounded in organizational principles that include family and personal life/work balance; an inclusive, respectful, and supportive work environment; professional development opportunities; innovation; and alignment with the campus's teaching, learning, and research missions. DoIT provides core IT infrastructure services to the university, develops and implements services for the university and in some cases, for the Universities of Wisconsin, plays a major role in managing the state-wide higher education network and regional networks. Key Job Responsibilities: - Conducts vulnerability-scanning analysis, tests security controls, documents the results of risk assessments, and designs procedures to prevent future incidents - Assists in the design, development, and implementation of security methodology and infrastructure for major systems - Liaison with campus IT practitioners to gather needs and feedback for RMC to ensure efficiency - Configures, develops, and tests applications and security controls - Assist in development and documentation of an RMC project management tool to include processes and workflows Department: Division of Information Technology, Office of Cybersecurity, Risk Management & Compliance (RMC) The Office of Cybersecurity leads and manages university efforts to reduce risk through data protection, continuous diagnostics, cybersecurity awareness training, and effective processes and procedures to safeguard intellectual property and sensitive information. The office has four teams: Risk Management and Compliance, Cybersecurity Operations, Business Systems Security and Cybersecurity Programs, and IT Policies. The Risk Management & Compliance (RMC) team has established a formalized risk assessment program for campus. This program offers review and validation on technical, administrative, and physical controls that affect the security of a vendor or service handling UW–‍Madison data. RMC assessments are designed to communicate levels of risk and provide recommendations for risk reduction. Compensation: Starting salary will be based on experience and qualifications. Well qualified applicants can anticipate to earn between $97,000 - $115,000, with final salary based on experience and qualifications. Employees in this position can expect to receive benefits such as generous vacation, holidays, and sick leave; competitive insurances and savings accounts; retirement benefits. Required Qualifications: - Established professional experience conducting risk assessments against recognized standards (NIST, COBIT or ISO) with minimal oversight. - Established professional experience working with security requirements within a healthcare, higher ed, or research organization. - Working knowledge of NIST, HIPAA, or PCI Data Security standards along with virtual environment, AI and cloud computing services and demonstrate professional certification in Information Security or IT Audits. - Experience executing project management skills including setting expectations, design review, threat modeling and risk profiling while working across a large, distributed organization that is representative of diverse IT and business communities. - Experience working independently to conduct technical investigations with diverse constituents, providing detailed written reports and presentations. - Experience communicating effectively to and accepting feedback from leadership, peers, technical teams and risk assessment customers (all campus levels). Preferred Qualifications: - Experience in assessing vendors as part of procurement and implementation stagess - Experience using standard industry applications to create or update current documents to meet compliance reporting requirements (i.e. office productivity software, project management software) - Expertise using vulnerability management tools to analyze discovered vulnerabilities against current configurations to determine the organizational risk. - Experience serving as both a lead and a contributing team member on projects - Knowledge of enterprise project management tools and skills to navigate them (Ie JIRA). Education: Bachelor's Degree Preferred Minimum Institutional Statement on Diversity: Diversity is a source of strength, creativity, and innovation for UW-Madison. We value the contributions of each person and respect the profound ways their identity, culture, background, experience, status, abilities, and opinion enrich the university community. We commit ourselves to the pursuit of excellence in teaching, research, outreach, and diversity as inextricably linked goals. The University of Wisconsin-Madison fulfills its public mission by creating a welcoming and inclusive community for people from every background - people who as students, faculty, and staff serve Wisconsin and the world. The University of Wisconsin-Madison is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to, including but not limited to, race, color, religion, sex, sexual orientation, national origin, age, pregnancy, disability, or status as a protected veteran and other bases as defined by federal regulations and UW System policies. We promote excellence by acknowledging skills and expertise from all backgrounds and encourage all qualified individuals to apply.

Related Job Pages

More Security Analyst Jobs

TEKsystems logo

Epic Security Analyst

TEKsystems

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia.

Security Analyst34 days ago
ContractRemoteTeam 10,001H1B No Sponsor

Role Description This position will lead the development, support, and functionality rollout of an Electronic Health Record (EHR) system. - Using subject matter expertise, lead and coordinate the IT team members and collaborate with the organization in optimizing their workflow processes through building applications tailored to meet the organizations’ needs. - Responsible for learning the EHR system’s capabilities and functional use, and applying knowledge of Healthcare Business workflows to assist in the implementation of a system that meets process needs. Essential Responsibilities - Lead efforts to resolve complex technical issues and system errors, especially situations that require cross-team collaboration. - Work closely with operations to develop and coordinate team members to implement issue resolution plans. - Lead work efforts to perform routine maintenance tasks, such as software updates, patches, and upgrades, to ensure the stability and security of the EHR system. - Coordinate and lead testing and validation activities for system changes, enhancements, and upgrades, following pre-defined change management processes. - Play a key role in strategic planning initiatives related to EHR systems, collaborating with leadership to align technology investments with organizational goals and objectives. - Drive continuous improvement initiatives to enhance the functionality, usability, and interoperability of EHR systems. - Take on project management responsibilities for EHR implementation projects, system upgrades, and other initiatives. - Establish and enforce governance processes and procedures for EHR system management, ensuring compliance with regulatory requirements. - Provide leadership and mentorship to junior analysts and team members, fostering a culture of collaboration and continuous improvement. - This role will help the team’s supervisor shape the direction of the team in day-to-day work and coordinating needs for projects. Qualifications - 5+ years of experience in an Epic Security role - Certification in 1 or more Epic Applications - Multiple Epic implementation experience - Bachelor’s degree Requirements - Expert Level - This is a Contract to Hire position based out of Oklahoma City, OK. Benefits - The pay range for this position is $50.00 - $60.00/hr. - Medical, dental & vision - Critical Illness, Accident, and Hospital - 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available - Life Insurance (Voluntary Life & AD&D for the employee and dependents) - Short and long-term disability - Health Spending Account (HSA) - Transportation benefits - Employee Assistance Program - Time Off/Leave (PTO, Vacation or Sick Leave) Workplace Type - This is a fully remote position. Application Deadline - This position is anticipated to close on May 6, 2026.

United States
$50 - $60 / hour
spiderSilk logo

Threat Intelligence Analyst

spiderSilk

spiderSilk delivers tip of the spear threat detection technology for the public and private sectors, globally.

Security Analyst35 days ago
Full TimeRemoteTeam 11-50H1B No Sponsor

• Monitor and investigate activity across dark web forums, marketplaces, encrypted messaging platforms, and other covert channels. • Track threat actor behavior, campaigns, and emerging TTPs (tactics, techniques, and procedures). • Collect, tag, and analyze relevant data including leaks, malware distribution, initial access sales, and exploit trade. • Produce high-quality intelligence reports, alerts, and briefings tailored to both technical and executive audiences. • Work with product, research, and exposure teams to enrich findings with external data and client relevance. • Maintain strong operational security (OPSEC) protocols during intelligence gathering and engagement.

United Arab Emirates

• Ensure security controls are deployed, operating effectively, and aligned with organizational security policies and standards. • Monitor, review, analyze, and respond to security alerts generated from various security platforms. • Tune and optimize security alerts to reduce false positives and improve detection effectiveness. • Ensure assets are properly onboarded and reporting into required security monitoring and vulnerability management tools. • Lead and support the vulnerability management lifecycle, including: Conducting regular vulnerability scans using automated tools, Analyzing scan results and prioritizing findings based on risk, Working closely with infrastructure, application, and development teams to remediate vulnerabilities and validating fixes, Perform and manage web application security scans, interpret findings, and provide clear remediation guidance to development teams. • Monitor threat intelligence feeds and external advisories to identify emerging threats, vulnerabilities, or risks relevant to the organization. • Participate in incident response activities, including identification, containment, eradication, and recovery efforts. • Assess, develop, and apply updated or strengthened security measures to respond to changing threats, regulatory and business requirements, enhancing both cloud and on-premises security posture. • Work with IT, engineering, and business teams to develop, review, and implement secure configurations, standards, and policies. • Assists project teams in the implementation of security measures to meet UBC cybersecurity policies and external governances, e.g., HIPAA, GDPR, CCPA. • Maintain accurate and up-to-date security documentation for systems, applications, and processes. • Collaborate with other security team members on security initiatives and best practices Support annual security initiatives and defined deliverables aligned with the organization’s security roadmap. • Participate in special projects and perform additional duties as assigned.

United States
Job Closed
Keysight Technologies, Inc. logo

Security Analyst

Keysight Technologies, Inc.

Keysight is on the forefront of technology innovation, delivering breakthroughs and trusted insights in electronic design, simulation, prototyping, test, manufacturing, and optimization. Our ~15,000 employees create world-class solutions in communications, 5G, automotive, energy, quantum, aerospace, defense, and semiconductor markets for customers in over 100 countries. Diversity, equity & inclusion are integral parts of our culture and drivers of innovation at Keysight. We believe that when people feel a sense of belonging, they can be more creative, innovative, and thrive at all points in their careers.

Security Analyst36 days ago
Full TimeRemoteTeam 10,001

Role Description - Perform C and C++ code reviews and structured vulnerability analyses in accordance with security framework/certification requirements (e.g., OCP S.A.F.E., EMVCo). - Translate vulnerability analysis findings into clear and actionable input for the security testing team, aligning results with applicable scheme thresholds and evaluation metrics. - Perform embedded testing on devices under evaluation e.g. firmware reversing, MITM, interface probing, etc. - Contribute to technical aspects of evaluation projects by working with a project manager, technical lead, and other project team members to ensure compliance, technical rigor, and timely delivery. Qualifications - Bachelor’s degree in Computer Science, Computer Engineering or Electrical Engineering or equivalent experience. - Minimum of 2 years of experience in the security evaluation domain. - Proven proficiency in at least two of the following: C, C++, Assembly. - Experience with secure embedded systems, such as Smart Cards, Secure Elements, System-on-Chips (SoCs), Trusted Execution Environments, smart light, remote control, ECUs, etc. - Good understanding of low-level computer architecture, security concepts, embedded system architecture, OS internals, Trusted Execution Environments. - Good understanding of practical cryptography algorithms and protocols. - Able to develop exploits for embedded devices. - Excellent interpersonal and communication skills; thrives in team environments with diverse stakeholders (technical teams, project managers, and customers). - Experience with Android, Java, and Kotlin is a plus. - Willingness to travel to clients in North America, Europe, or Asia. Requirements - Santa Clara, CA Pay Range: MIN $122,000.00 - MAX $184,000.00 Benefits - Keysight is an Equal Opportunity Employer.

United States
$122K - $184K / year