Information Security Analyst

Syracuse University

New York (NY)

On-site

USD 87,000 - 92,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Syracuse University is seeking an Information Security Analyst to join the Information Security group within ITS. The role defends university data assets through policy controls, security operations, incident response, and AI-assisted tooling in a SOC environment.

The ideal candidate has a BS in a related field and 5+ years of IT experience with 2+ in information security, including hands-on SOC work, threat detection, and security tooling in a production setting.

Qualifications

  • Bachelor's degree in information security/Cybersecurity, Information Management, Computer Science, Computer Engineering, or related discipline.
  • Five (5+) plus years of experience in Information Technology, with a minimum of two (2) years in Information Security/Cybersecurity. Prior SOC experience is valued.
  • Hands-on experience in SOC operations, alert triage, log analysis, and security tooling in a production setting.

Responsibilities

  • Monitor network, endpoint, and identity telemetry using SIEM platforms (Splunk, Elastic/Opensearch, Kibana).
  • Triage alerts for relevance and severity; escalate as needed and provide final disposition.
  • Operate, tune, and enhance SOC monitoring and detection platforms including Defender and SIEM tools.
  • Write scripts to automate detection and response; assist in firewall rule maintenance.
  • Mentor student SOC employees and develop SOC processes and runbooks.

Skills

SOC operations
Microsoft Defender for Endpoint
Python 3 scripting
Firewall operation
Windows/Active Directory
PowerShell
Linux system administration
Digital forensics
AI-assisted security tools
MITRE ATT&CK
Cloud security fundamentals
SOAR

Education

Bachelor's degree in information security/Cybersecurity, Information Management, Computer Science, Computer Engineering, or related discipline

Tools

Splunk
Kibana
Microsoft Sentinel
Python 3

Job description

Information Security Analyst
Posting Details
  • Job # 042836
  • Department Code 20703-6034
  • Department Information Technology Services
  • Job Title Information Security Analyst
  • Location Syracuse, NY
  • Campus Syracuse, NY
  • Commitment to On-Campus Experience Syracuse University is committed to delivering an exceptional student experience… Remote work arrangements are limited in accordance with University policy.
  • Pay Range $87,000-$92,000
  • Staff Level S5
  • FLSA Status Exempt
  • Hours Standard University business hours (8:30am – 5:00pm academic year; 8:00am – 4:30pm summer; hours may vary based on operational needs).
  • Job Type Full-time
Job Description

The Information Security Analyst is a technical role within the Information Security (InfoSec) group of Information Technology Services (ITS), responsible for defending the University’s data assets through policy controls, security operations, incident response, and AI-assisted tooling. As a primary network defender, the analyst works at the intersection of threat detection, vulnerability management, and forensic investigation within a Security Operations Center (SOC).

The role requires hands‑on experience across several domains: SOC operations including alert triage, log analysis, and network traffic interpretation using tools such as Splunk, Kibana, or Microsoft Sentinel; Python 3 scripting for automation and detection support; firewall management for ruleset maintenance and network security enforcement; Microsoft Entra ID administration including identity architecture and PowerShell scripting; Linux system administration across mixed‑OS environments; and digital forensics at a first-responder level, including breach assessment, evidence preservation, and containment.

This role is responsible for developing and overseeing student SOC employees. The SOC functions as both a live security operation and a learning environment, requiring the analyst to serve as senior practitioner and mentor.

Education and Experience
Education

Bachelor’s degree in information security/Cybersecurity, Information Management, Computer Science, Computer Engineering, or related discipline.

Experience

Five (5+) plus years of experience in Information Technology, with a minimum of two (2) years in Information Security/Cybersecurity. Prior experience working in a functioning SOC or equivalent security operations environment is valued, including hands‑on work triaging live alerts, investigating active incidents, and operating security tooling in a production setting.

Skills and Knowledge
Required Experience (2+ years each)
  • SOC operations: IDS/EDR alert triage, log analysis, and network traffic interpretation using Splunk, Kibana, or Microsoft Sentinel
  • Microsoft Defender for Endpoint: alert triage, investigation, and response
  • Python 3 scripting for automation and SOC workflow support
  • Firewall operation and network security fundamentals
Required Experience (1+ years each)
  • Windows/Active Directory, endpoint log analysis, PowerShell, and group policies
  • Linux system administration
  • Digital forensics at a first-responder level
  • AI‑assisted security tools (e.g., Copilot, AI‑enhanced SIEM features)
  • Broader Technical Knowledge: Network protocols; IDS/IPS platforms; MITRE ATT&CK and Cyber Kill Chain; vulnerability scanning; cloud security fundamentals; SOAR and scripting‑based automation; Microsoft security stack (Defender XDR, Sentinel, Purview, Entra ID) with KQL proficiency. Active use of AI tooling across all operational functions and the application of AI as a solution is a core expectation.
  • Soft Skills: Cross‑functional collaboration; student SOC mentorship; multi‑source analytical precision; clear written and verbal communication to technical and non‑technical audiences; composure during active incidents; commitment to continuous learning.
Responsibilities
Security Monitoring & Alert Triage
  • Monitor network, endpoint, and identity telemetry continuously using open‑source and enterprise SIEM platforms including Splunk, Elastic/Opensearch, and Kibana.
  • Review IDS alerts, system logs, and network traffic captures; triage for relevance and severity; distinguish genuine threats from false positives.
  • Provide second‑level analysis of alerts escalated by student SOC employees; final disposition and escalation authority rests with this position.
SOC Tools Operations & Engineering
  • Operate, tune, and recommend enhancements to the SOC’s monitoring and detection platforms including Microsoft Defender and SIEM tools; leverage AI‑assisted tooling to improve detection and response workflows.
  • Implement threat hunting and detection strategies; identify new data sources to augment detection capability; integrate new tools and applications as needed.
  • Write Python and PowerShell scripts to automate detection, response, and data analysis workflows.
  • Assist in maintenance of firewall rulesets.
Incident Response & Investigation
  • Serve as first responder for security incident investigation, conducting log and system‑level analysis to determine potential scope and impact.
  • Assist with containment, eradication, and recovery efforts.
  • Perform digital forensic analysis at the first‑responder level to determine whether a breach has occurred and what steps are required to contain it.
  • Provide written and verbal summaries of incident findings to be shared with ITS leadership and relevant stakeholders.
Vulnerability Management
  • Assist in maintaining and operating the University’s vulnerability assessment program, including scan configuration, finding analysis, risk prioritization based on exploitability and business impact, and remediation coordination with system owners.
  • Track patching effectiveness and validate closure of critical findings.
Student Employee Development
  • Assist in the hiring, continuous training, mentoring, and operational oversight of student SOC employees.
  • Develop and maintain the SOC processes, runbooks, and escalation procedures that student analysts follow.
  • Provide direct coaching on alert investigation techniques, log analysis, and documentation standards.
EEO Statement

Syracuse University is an equal‑opportunity institution. The University prohibits discrimination and harassment based on race, color, creed, religion, sex, gender, national origin, citizenship, ethnicity, marital status, age, disability, sexual orientation, gender identity and gender expression, veteran status, or any other status protected by applicable law to the extent prohibited by law. This nondiscrimination policy covers admissions, employment, and access to and treatment in University programs, services, and activities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analysts
Information Security Analysts

University of Utah • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Participating employer with Utah Retirement Systems
Veterans' preference extended to qualified applicants
Senior Information Security Analyst & SOC Lead
Senior Information Security Analyst & SOC Lead

Syracuse University • New York (NY)

On-site
USD 87,000 - 92,000
Senior Information Security Analyst
Senior Information Security Analyst

UMass Amherst • Amherst (MA)

Hybrid
USD 120,000 - 150,000
Senior Security Analyst
Senior Security Analyst

Troy University • Troy (AL)

On-site
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Binghamton University • City of Binghamton (NY)

On-site
USD 70,000 - 100,000
Senior Information Security Analyst
Senior Information Security Analyst

University of Massachusetts Amherst • Amherst (MA)

Hybrid
USD 110,000 - 140,000
Security Operations Specialist
Security Operations Specialist

The University of North Carolina • Charlotte (NC)

On-site
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Clearcapital • Reno (NV)

On-site
USD 113,800 - 139,000
Comprehensive medical, dental, and vision insurance
401(k) retirement plan with employer match
Paid time off (PTO) and paid holidays
SOC Analyst 2
SOC Analyst 2

Mbi Llc • Harrisburg

On-site
USD 60,000 - 90,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000