Information Security Analyst

University of California, Riverside

Riverside (CA)

Hybrid

USD 88,000 - 162,000

Full time

24 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Information Security Analyst at University of California, Riverside is responsible for implementing the Information Security Office governance, risk management, compliance, and awareness program.

The position will conduct risk assessments; coordinate audit engagements with relevant parties; maintain policies, standards and procedures designed to safeguard information and resources; manage information security awareness training.

Qualifications

  • Bachelor's degree in a related area or equivalent experience.
  • 4-7 years of information security or IT risk management experience.
  • Experience auditing security controls across Windows, Linux, UNIX.
  • Familiarity with FERPA, HIPAA, PCI regulations (preferred).

Responsibilities

  • Conduct risk assessments and coordinate audits across parties.
  • Maintain policies, standards, and procedures for information security.
  • Run vulnerability assessments and penetration tests to verify configurations.
  • Support campus phishing simulations and awareness training.
  • Use AI tools to assist risk workflows.

Skills

risk assessments
audits
security awareness
encryption
security logs
security controls
data protection

Education

Bachelor's degree in related area

Tools

Windows
Linux
UNIX

Job description

Overview
  • Job ID 37879163
  • Category Information Technology
  • Organization Info Technology Solutions
  • Department IT Risk Management Dept
  • Location Remote/Hybrid
  • Salary $88,302 - $162,426
  • Date Posted August 20, 2026
  • Application Deadline Open Until Filled
  • Schedule 8AM - 5PM
  • Full/Part Time Full-time(100%)
  • Level of Supervision General Supervision
  • Personnel Program Code Professional & Support Staff
  • Other Information Qualifies for Employee Referral Bonus: No; UC Internal Job: No
Position Information

The Information Security Analyst is responsible for the implementation of the Information Security Office governance, risk management, compliance, and awareness program. The position will conduct risk assessments; coordinate audit engagements with relevant parties; maintain policies, standards and procedures designed to safeguard information and resources; manage information security awareness training. In addition, conduct vulnerability assessments and security reviews through vulnerability scans and penetration tests to determine deviations from acceptable configurations, policies, and standards. Finally, the incumbent will assess levels of risk and recommend appropriate mitigation controls. This position is classified as predominantly remote with occasional visits to campus as needed. Working hours will be based on Pacific Standard Time (PST). The full salary range for the Information Security Analyst is $88,301.52 - $162,425.52 annually. However, the pay scale for this position is up to $121,785.30 annually. We base salary offers on a variety of considerations, such as education, licensure and certifications, experience, and other business and organizational needs. Applicants must have current work authorization when accepting a UCR staff position. Currently, UCR is unable to sponsor or take over sponsorship of an employment Visa for staff. As a University employee, you will be required to comply with all applicable University policies and/or collective bargaining agreements, as may be amended from time to time. Federal, state, or local government directives may impose additional requirements.

Educational Requirements

Bachelor's degree in related area and/or equivalent experience/training. Required

Experience Requirements
  • Minimum of 4 - 7 years of related experience in information security, IT risk management, compliance, or a related field. Required
  • Experience managing, configuring, or auditing security controls across multiple operating systems (e.g., Windows, Linux, UNIX). Required
  • Experience conducting IT risk assessments or Third-Party Risk Assessments using industry-standard frameworks. Required
  • Experience with security and privacy related regulations such as FERPA, HIPAA, PCI, etc. Preferred
  • Experience designing, executing, or supporting cybersecurity awareness training or campus-wide outreach programs (such as phishing simulations). Preferred
  • Experience working in higher education. Preferred
Certification Requirements
  • Certified Information Systems Auditor (CISA) Preferred
  • Certified Ethical Hacking (CEH) Preferred
  • Security+ Preferred
  • Certified Information Systems Security Professional (CISSP) Preferred
Special Conditions
  • Must pass a background check. Required
  • Occasional travel for university related business meetings, conferences and/or professional development. Required
  • Travel Outside of Normal Business Hours Required
  • Exercise the utmost discretion in managing sensitive information learned in the course of performing their duties. Sensitive information includes but is not limited to employee and student records, health and patient records, financial data, strategic plans, proprietary information, and any other sensitive or non-public information learned during the course and scope of employment. Understands that sensitive information should be shared on a limited basis and actively takes steps to limit access to sensitive information to individuals who have legitimate business need to know. Ensure that sensitive information is properly safeguarded. Follow all organizational policies and laws on data protection and privacy. This includes secure handling of physical and digital records and proper usage of IT systems to prevent data leaks. The unauthorized or improper disclosure of confidential work-related information obtained from any source on any work-related matter is a violation of these expectations. Required
Minimum Requirements
  • Basic skill at reading and interpreting security logs.
  • Ability to follow department processes and procedures.
  • Interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.
  • Experience using IT security systems and tools.
  • Knowledge of data encryption techniques.
  • Experience analyzing logs for security breaches.
  • Demonstrated skills applying security controls to computer software and hardware.
  • Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks.
  • Knowledge of computer hardware, software and network security issues and approaches.
  • Demonstrated experience selecting and applying appropriate data encryption technologies.
Preferred Qualifications
  • Knowledge of other areas of IT, department processes and procedures.
  • Experience in incident response and digital forensics including data collection, examination and analysis.
  • Familiarity with leveraging Artificial Intelligence (AI) tools to automate or streamline administrative tasks, report writing, or content generation.
Additional Information

In the Heart of Inland Southern California, UC Riverside is located on nearly 1,200 acres near Box Springs Mountain in Southern California; the park-like campus provides convenient access to the vibrant and growing Inland region. The campus is a living laboratory for the exploration of issues critical to growing communities' air, water, energy, transportation, politics, the arts, history, and culture. UCR gives every student, faculty and staff member the resources to explore, engage, imagine and excel.

UC Riverside is recognized as one of the most ethnically diverse research universities in the country boasting several key rankings of which we are extremely proud.

  • UC Riverside is proud to be ranked No. 12 among all U.S. universities, according to Money Magazine's 2020 rankings, and among the top 1 percent of universities worldwide, according to the 2019-20 Center for World University rankings.
  • UC Riverside is the top university in the United States for social mobility. - U.S. News 2020
  • UCR is a member of the University Innovation Alliance, the leading national coalition of public research universities committed to improving student success for low-income, first-generation, and students of color.
  • Among top-tier universities, UC Riverside ranks No. 2 in financial aid. - Business Insider 2019
  • Ranked No. 2 in the world for research, UCR's Department of Entomology maintains one of the largest collections of insect specimens the nation. - Center for World University Rankings
  • UCR's distinguished faculty boasts 2 Nobel Laureates, and 13 members of the National Academies of Science and Medicine.

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected categories under state or federal law. It is the policy of the University of California to undertake affirmative action and anti-discrimination efforts, consistent with its obligations as a Federal and State contractor.

For information about our generous employee benefits package, visit: Employee Benefits Overview

Job Description Details
General Information

Job Title IT SCRTY ANL 3 TX

Job Code 005353

Grade 238

Department Head Dewight Kramer

Supervisor Munawar Rangoonwala

Generic Scope

Experienced professional who knows how to apply theory and put it into practice with in-depth understanding of the professional field; independently performs the full range of responsibilities within the function; possesses broad job knowledge; analyzes problems/issues of diverse scope and determines solutions.

Custom Scope

Applies skills as a seasoned, experienced IT security professional with a full understanding of industry practices, governmental regulations and campus, medical center or Office of the President policies and procedures to resolve a wide range of complex issues. Demonstrates competency in recommending methods and techniques to obtain results.

Department Custom Scope

The Information Security Analyst is responsible for the implementation of the Information Security Office governance, risk management, compliance, and awareness program. The position will conduct risk assessments; coordinate audit engagements with relevant parties; maintain policies, standards and procedures designed to safeguard information and resources; manage information security awareness training. In addition, conduct vulnerability assessments and security reviews through vulnerability scans and penetration tests to determine deviations from acceptable configurations, policies, and standards. Finally, the incumbent will assess levels of risk and recommend appropriate mitigation controls.

Key Responsibilities
  • Conducts various types of Risk Assessments related to various security frameworks as required. Evaluates vendor security postures based on UCOP and campus policies. Reviews and coordinates the execution of UC Data Security agreements. Supports standard risk assessment methodologies and compliance tracking workflows. 35%
  • Supports campus-wide cybersecurity awareness programs and educational initiatives. Coordinates and assists in running campus phishing simulations, and drafts educational content for students, staff, and faculty (including material for new student orientation). Advises campus departments on basic security prevention, data protection levels, and safe digital practices. 25%
  • Applies and administers standard security configurations to control access to networks, hardware, and systems. Implements moderate-scale security controls to prevent unauthorized changes to campus information and infrastructure. 15%
  • Conducts standard vulnerability assessments and mitigation activities. Collects, analyzes, and reports on security incidents to identify causes and implications. Assists in responding to and escalating complex IT security incidents in accordance with established campus and UCOP policies. 15%
  • Evaluates and utilizes approved Artificial Intelligence (AI) tools to assist in cybersecurity risk workflows. Employs AI to streamline the initial analysis of vendor documentation, draft initial risk assessment reports, generate realistic scenarios for campus phishing simulations, and support the creation of adaptive security training content. 10%
Other Requirements
  • Standard Office Equipment
  • Bend: N/A
  • Sit: Frequently
  • Squat: N/A
  • Stand: Occasionally
  • Crawl: N/A
  • Walk: Occasionally
  • Climb: N/A
  • Read/Comprehend: Constantly
  • Write: Frequently
  • Perform Calculations: Occasionally
  • Communicate Orally: Frequently
  • Reason & Analyze: Constantly
  • Is exposed to excessive noise: No
  • Is around moving machinery: No
  • Is exposed to marked changes in temperature and/or humidity: No
  • Drives motorized equipment: No
  • Works in confined quarters: No
  • Dust: No
  • Fumes: No
  • Yes
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Financial and Administrative Coordinator
Financial and Administrative Coordinator

University-of-California,-Riversid • Riverside (CA)

On-site
USD 61,000 - 87,000
IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California, Berkeley • Berkeley (CA)

On-site
IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California-Berkeley • Berkeley (CA)

On-site
USD 91,000 - 120,000
IT Security Engineer
IT Security Engineer

University of California, Riverside • Riverside (CA)

Hybrid
USD 81,000 - 151,000
Athletics Academic Counselor & Tutorial Coordinator
Athletics Academic Counselor & Tutorial Coordinator

University-of-California,-Riversid • Riverside (CA)

On-site
USD 64,000 - 112,000
IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California • Berkeley (CA)

On-site
USD 91,500 - 120,000
IT Security Analyst
IT Security Analyst

University of California, Riverside • Riverside (CA)

Hybrid
USD 116,000
IT Security Analyst
IT Security Analyst

University-of-California---SAN-Francisc • San Francisco (CA)

On-site
USD 120,000 - 175,000
Regulated Research Cybersecurity Team Lead - 140972
Regulated Research Cybersecurity Team Lead - 140972

University of California San Diego • California (MO), Northern (KY)

Hybrid
USD 114,000 - 155,000
Health/Dental/Vision Insurance
Vacation/Holidays
Work/Life Balance
+2
Information Security Operations Analyst (0661U), Berkeley IT - #87198
Information Security Operations Analyst (0661U), Berkeley IT - #87198

University of California, Berkeley • Berkeley (CA)

On-site
USD 80,000 - 120,000
Comprehensive benefits package
Full UC benefits