Logo
Binghamton University

Binghamton University is hiring: Information Security Analyst in Binghamton

Binghamton University, Binghamton, NY, United States


Location: Binghamton, NY Category: Professional Posted On: Tue Sep 10 2024 Job Description:

Budget Title: Lead Programmer/Analyst (SL-3)

Salary: Commensurate with qualifications and experience

The Information Security Analyst will be responsible for assisting the Chief Information Security Officer/Director of Information Security in developing and maintaining Binghamton University's information security capabilities, implementing security controls, responding to information security incidents, and monitoring administrative, academic systems and the University network for policy enforcement and compliance. The Information Security Analyst will work with cross-functional teams to design and implement security initiatives; and serve as a resource person on specific information security technologies and technology-related compliance requirements.

The Information Security Analyst reports to the Chief Information Security Officer/Director of Information Security and works closely with Information Technology Services (ITS) leadership to build awareness and implementation of security controls, within the department and across the University.

In addition, the Information Security Analyst will:

+ Triage, process, and close out technical client requests

+ Track and ensure adequate and timely resolution to all audit and risk assessment findings or issues relating to information security

+ Recommend remediation strategies and technologies for mitigating risks

+ Evaluate current and future requirements and develop or recommend technical and operational solutions accordingly

+ Support and manage risk mitigation tools as needed

+ Develop specifications and standards for equipment, software, and procedures in support of University policies

+ Investigate internal and external reports of information security issues

+ Assist in analyzing results from intrusion detection systems, intrusion prevention systems, network mapping software, log analysis, and other tools to detect, respond to, and mitigate information security-related vulnerabilities and incidents

+ Maintain audit and oversight of processes, procedures, and tools used to ensure security controls

+ Maintain metrics and prepare reports

+ Perform trend and root cause analysis

+ Liaison with various University constituencies on behalf of the CISO as needed

+ Serves as a resource person in assessing systems, processes, and projects against compliance requirements, control objectives, and security best practices; interacts with internal and external technical staff and consults with project teams at various stages of project cycles.

+ Must be able to maintain data confidentiality and compliance with regulatory requirements (HIPAA, FERPA, PCI, etc.)

Job Requirements:

+ Bachelor's degree or Bachelor's degree completion by January 2025, or Associates degree plus 2 years' experience. Relevant certifications may be substituted for 2 years' experience.

+ Demonstrated competence in information security concepts

+ Demonstrated strong written and oral communication skills

+ Effective problem-solving, interpersonal, and multitasking skills

+ Ability to work with multiple constituencies within a culturally diverse environment

+ Excellent interpersonal skills, strong analytical skills, demonstrated ability to work in a team environment, and the ability to deal with ambiguity in a changing business

Preferences:

+ Experience with cybersecurity

+ Experience with Incident Management/Response

+ Experience with Endpoint Detection and Response, Carbon Black EDR

+ Experience with Splunk or log files

+ A demonstrated understanding of network topologies, architectures, protocols, and addressing schemes. Network management experience is desirable

+ Knowledge of and a demonstrated ability to operate Unix and Windows-based security tools (e.g., nmap, Snort, group policy)

+ Programming or scripting languages (e.g., python, php, ruby, bash)

+ Experience with Data Loss Prevention (DLP)

+ Knowledge or experience in regulatory compliance frameworks such as NIST, PCI-DSS, FERPA, GLBA, HIPAA, DFARS, CMMC, ITAR

+ Experience working in a large complex academic organization or experience in health care or research environment

+ A portfolio of web applications/projects that demonstrate required skills. You may upload a document or links during the application process which demonstrates how the above technical requirements are met.

Visa sponsorship is not available for this position

Additional Information:

Offers of employment may be contingent upon successful completion of a pre-employment background check and verification of degree(s) and credentials.

Binghamton University is a tobacco-free campus.

Pursuant to Executive Order 161, no State entity, as defined by the Executive Order, is permitted to ask, or mandate, in any form, that an applicant for employment provide his or her current compensation, or any prior compensation history, until such time as the applicant is extended a conditional offer of employment with compensation. If such information has been requested from you before such time, please contact the Governor's Office of Employee Relations at (518) 474-6988 or via email at info@goer.ny.gov

Payroll information can be found on our website https://www.binghamton.edu/offices/human-resources/payroll/

Cover letters may be addressed "To the Search Committee."

Postings active on the website, accept applications until closure.

For information on the Dual Career Program, please visit:

https://www.binghamton.edu/offices/human-resources/prospective/dual-career/index.html

Equal Opportunity/Affirmative Action Employer

The State University of New York is an Equal Opportunity/Affirmative Action Employer. It is the policy of Binghamton University to provide for and promote equal opportunity employment, compensation, and other terms and conditions of employment without discrimination on the basis of age, race, color, religion, disability, national origin, gender identity or expression, sexual orientation, veteran or military service member status, marital status, domestic violence victim status, genetic predisposition or carrier status, or arrest and/or criminal conviction record unless based upon a bona fide occupational qualification or other exception.

As required by Title IX and its implementing regulations Binghamton University does not discriminate on the basis of sex in the educational programs and activities which it operates. This requirement extends to employment and admission. Inquiries about sex discrimination may be directed to the University Title IX Coordinator or directly to the Office of Civil Rights (OCR). Contact information for the Title IX Coordinator and OCR, as well as the University's complete Non-Discrimination Notice may be found here (https://www.binghamton.edu/diversity-equity-inclusion/policies-and-procedures/title-ix-.html) .