Educause Security Discussion mailing list archives
Job opening: UC Berkeley - Security Analyst 4 - IS Assessments
From: Kate Riley <ktriley () BERKELEY EDU>
Date: Thu, 11 Jul 2013 12:48:10 -0700
We are currently recruiting for an IT Security Analyst 4 for our
Assessment and Compliance team. Please see the full job description
below and if interested apply at jobs.berkeley.edu, Job ID 16295
IT Security Analyst 4 - IS Assessments
Departmental Overview
The Information Security Office (ISO) coordinates the risk management
process for UC Berkeley's information systems and directs campus-wide
efforts to adequately secure institutional data. The Information
Security Office is led by the Chief Information Security Officer and
consists of two teams, the Operations team and the Assessment team. The
Operations team, System and Network Security (SNS), is responsible for
implementing and operating detection programs and security services for
the campus, as well as incident response and breach management. The
Assessment team is responsible for managing the campus information
system asset inventory and overseeing compliance activities for campus
information systems.
The ISO works closely with IT Policy to develop and maintain the
security policy framework for campus. The ISO also coordinates with
other key groups involved in risk management for the campus and
collaborates with peer institutions to share information and solutions
to information security challenges.
This position is part of the security assessment team and reports to the
assessment manager. The position is a one-year contract with the
potential to extend.
Responsibilities
This position will work with a team of four others to identify and track
critical information assets utilized by UC Berkeley and assess the
compliance of these systems with internal security standards and
external compliance requirements. A key deliverable for this team is
defining and implementing programs for ongoing verification of critical
assets, ensuring such assets have adequate protection and meet
appropriate compliance requirements. The program must also engage key
campus participants for ongoing data protection.
The primary focus of this position will be defining and implementing
assessment processes for networked devices to ensure compliance with
applicable requirements. The position will also be expected to serve as
a subject matter expert in security in the context of assessment and
compliance activities; conduct assessments consisting of interviews,
evidence collection and user education. Each team member is expected to
participate in campus security guideline development, to have working
knowledge of all applicable laws/regulations/policies, and to be able to
participate in any type of assessment.
In the particular, the position:
Completes automated and manual application security tests
documenting process and findings
Completes data analysis, writes report detailing findings,
remediation steps, and explains results to internal stakeholders and
external vendors
Applies advanced IT security concepts to evaluate highly complex and
campus-impacting security controls when assessing mission critical
systems across the campus
Proactively addresses the negative impact on the campus caused by
theft, destruction, alteration or denial of access of information.
Applies advanced IT security concepts to help shape, define or
revise incident response processes
Develops metrics for measuring success in incident and resource
management
Identifies and analyzes changes in the campus threat landscape in
order to help ensure continued alignment between security policy and key
risks
Required Qualifications:
Minimum of five years of direct full-time security work experience
in two or more security fields.
Hands-on Penetration Testing and Application Security experience
Requires advanced knowledge of IT security function
Experience analyzing complex IT systems for information risks
Knowledge of other related areas of IT, including but not limited to
network engineering, secure application development, quality assurance,
requirements gathering, design/build engineering, systems
administration, and desktop management
Demonstrated ability to quickly understand diverse and complex
business environments
Knowledge of assessment methodologies, information security
frameworks, and regulations that define information security controls
Strong analytic skills with proven ability to communicate verbally
and in writing with a variety of audiences
Requires organizational acumen and interpersonal skills in order to
work with both technical and non-technical personnel at various levels
in the organization
Must be self-starter with demonstrated ability to manage complex set
of tasks from inception through completion
Preferred Qualifications:
Relevant security certifications (GIAC, ISACA, ISC2)
Experience assessing applications for common vulnerabilities using
open source or commercial products
Experience with Nmap, Wireshark, Metasploit, Burp Suite, WebScarab,
Nessus, Acunetix, IBM Appscan, IDA Pro or similar tools
Experience designing and implementing information security controls
Knowledge relating to the design of security programs within higher
education
Knowledge of federal, state, University of California and industry
requirements for the protection of personally identifiable information
(e.g., Payment Card Industry Data Security Standards (PCI-DSS), UC
Berkeley's Minimum Security Standards for Electronic Information
(MSSEI), California Information Practices Act, and the Health Insurance
Portability and Accountability Act (HIPAA))
Salary & Benefits:
The salary range for the position of IT Security Analyst 4 is $71,600 -
$140,800 annually, depending on qualifications and experience. The
midpoint salary is $106,200. The position is a one-year contract
with the potential to extend.
For information on the comprehensive benefits package offered by the
University visit:
http://atyourservice.ucop.edu/forms_pubs/misc/benefits_of_belonging.pdf
How to Apply
Please visit jobs.berkeley.edu and look for this posting.
Submit your cover letter and resume as a single attachment when
applying. Applications must include a cover letter to be considered;
applications without cover letters will not be considered.
Criminal Background Check
This position has been designated as sensitive and requires a Criminal
Background Check. We reserve the right to make employment contingent
upon successful completion of a Criminal Background Check.
Other Information
This posting is for a contract appointment. The work location is
downtown Berkeley within an easy walk to BART.
Equal Employment Opportunity
The University of California, Berkeley is an Equal
Opportunity/Affirmative Action Employer
--
Kate Riley
IT Security Analyst
University of California, Berkeley
ktriley () berkeley edu
510-642-0141
Current thread:
- Job opening: UC Berkeley - Security Analyst 4 - IS Assessments Kate Riley (Jul 11)
