A complete application in a minute — tailored resume and cover letter, ready to send.
The University of Utah is seeking a Cybersecurity Analyst Tier 2 (Security Operations Center) to drive mid-tier incident investigations and act as the escalation bridge between Tier 1 monitoring and Tier 3 engineering.
You will tune detection rules with Tier 3, refine response playbooks, mentor junior analysts, and collaborate with IT, cloud, and identity teams to harden the environment.
The University of Utah has an opportunity for a CybersecurityAnalyst Tier 2 (Security Operations Center) to help support ourInformation Security and Compliance goals. The Tier 2 SOC analystwill drive mid-tier incident investigations, perform root causeanalysis, and help optimize our operational capabilities. Operatingas the primary escalation bridge between Tier 1 monitoring and Tier3 engineering, you will handle complex security events, collaborateclosely with Tier 3 analysts to tune detection rules, refineresponse playbooks, and mentor junior analysts.
University Information Technology(UIT), the central IT service provider for theUniversity of Utah, reports to the U's Chief InformationOfficer and is responsible for many of the U's sharedIT services including the wired and wireless network; CampusInformation Services (CIS) portal; UMail, telephone, and onlinecollaboration; digital learning technologies; information security;software licensing; and a host of other IT systems andservices.
Located in Salt LakeCity, the U is the flagship institution of the State of Utah'ssystem of higher education, home to arts and museumvenues and a member of the BIG-12 Conference. Skiing andsnowboarding opportunities are a short distance fromcampus, and opportunities to pursue activities from biking to hiking to fishing abound. Salt Lake City ishome to the Utah Symphony andOpera, Ballet West, professional sports teams, and a wide range ofother cultural and recreational activities.
Job Code: P34212Grade: P17
EQUIVALENCY STATEMENT: 1 year of higher educationcan be substituted for 1 year of directly related work experience(Example: bachelor's degree = 4 years of directly related workexperience).
Information Security Analyst, II: Requires abachelor's (or equivalency) + 4 years or a master's (orequivalency) + 2 years of directly related work experience.
Experience: 4 years dedicated cybersecurityoperations, threat triage, or incident response experience in a SOCenvironment.
Technical mastery: Strong expertise analyzing logsacross Windows/Linux, cloud environments (AWS, Azure, GCP), networktraffic (PCAP, NetFlow), and identity platforms (Entra ID,Okta).
Querying & Log Analysis: Proficiency usingplatform query languages (e.g. KQL, SPL, YARA) for deepinvestigation, log correlation, and evaluating ruleperformance.
Framework Alignment: Practical working knowledgeof applying the MITRE ATT&CK framework to real-worldinvestigations, triage workflows, and post-incidentreporting.
Certifications (Preferred): GCIH, GCFA, GSOC,SC-200, CCSP.
Soft Skills: Excellent analytical problem-solvingskills and a strong passion for teaching and elevating junior teammembers. A demonstrated ability to write complex technical reportsfor a non-technical audience.
PRN46212B
Full Time
Four ten hour shifts a week. Positionwill rotate between day and evening shifts to include holidays andweekends.
00954 - UIT Systems & Security
Campus
$73,000.00 - 93,000.00
09/22/2026