About University at Albany:
The University atAlbany is a Carnegie-classified Research 1 institution drivenby academic excellence, pioneering research and scientificdiscovery, and service to community. UAlbany's world-class faculty experts and approximately 17,500 students arecreating new knowledge in fields such as artificial intelligence, semiconductor engineering, atmospheric and environmental sciences, cybersecurity, public health, public administration and socialwelfare while deepening our understanding of our world throughscholarship and creative activity in the social sciences andhumanities. As one of the most diverse public research institutionsin the nation, the University is a national leader in publicengagement, educational equity and social mobility. For over 180years, UAlbany has molded bright, curious and engaged students andlaunched them toward success.
Located in Albany, New York, New York State's capital, theUniversity is convenient to Boston, New York City, and theAdirondacks.
Job Description:
Join the University at Albany's Information Technology Services(ITS) as an Information Security Analyst/Engineer and help protectcritical infrastructure, institutional data, and research assets ina fast-moving, research-intensive environment at a Carnegie R1research institution.
We're looking for someone to join a small, senior team thatoperates with real ownership. You'll work directly with the ChiefInformation Security Officer (CISO) and partner with network,systems, and application teams. You'll handle modern incidentresponse and network security on a stack that includes MicrosoftDefender extended detection and response (XDR), Palo Alto andCloudflare.
You'll investigate and respond to incidents end-to-end, buildautomation playbooks that make the next response faster, and managefirewall policy for an institution that takes security seriously.You'll also handle day-to-day triage and ticket work - but theexpectation is that you're building systems that reduce that burdenover time, not just clearing the queue.
This is an excellent opportunity if you want breadth - incidentresponse (IR), network defense, automation, and engineering -without being siloed into one function.
Primary Responsibilities:
- Incident detection, response, and automation
- Monitor and triage security alerts across endpoints, identity,and cloud workloads using tools such as Microsoft Defender andSentinel.
- Investigate and respond to incidents end-to-end (scope,contain, eradicate, recover); document actions and elevate asneeded.
- Build and improve incident response workflows, including cloudautomation playbooks (security orchestration, automation, andresponse (SOAR) and scripts that reduce time-to-detect andtime-to-respond.
- Partner with network, systems, and application teams to containthreats, remediate root causes, and improve detections andpreventive controls.
- Network security (firewalls, visibility, and threat-drivenmonitoring)
- Design, review, and maintain next-generation firewall policiesand exceptions (Palo Alto) and web application protections(Cloudflare), including change control and documentation.
- Analyze network telemetry for anomalies; build detections andworkflows that correlate network, endpoint, identity, and cloudsignals.
- Vulnerability management (secondary/backup)
- Run regular vulnerability scans using Tenable (and similartools).
- Automate vulnerability tracking and reporting.
- Coordinate remediation with system owners and technicalteams.
- Risk and compliance (secondary/backup)
- Support risk assessments, audits, and policy updates.
- Promote security awareness and best practices acrosscampus.
- Engineering and integration (supporting IR and networksecurity)
- Develop and maintain scripts and automation workflowssupporting incident response and network security.
- Integrate security tools and data sources (firewall, cloud,endpoint detection and response (EDR)) to improve correlation andresponse automation.
- Evaluate emerging capabilities to enhance detection, response,and network controls; prioritize solutions that can beoperationalized and automated.
- Other reasonable duties as assigned
Functional and Supervisory Relationships:
- Reports to: Chief Information Security Officer
- May supervise employees as assigned
Job Requirements:
- Excellent communication skills and the ability to workeffectively with infrastructure teams in a fast-paced environmentwhile balancing security, availability, and operational needs.
- Strong troubleshooting and organizational skills, with theability to prioritize work and solve complex problemsindependently.
- Applicants must demonstrate an ability to develop inclusive andequitable relationships within our diverse campus community.
- Applicants must demonstrate an ability to support diversity,equity, access, inclusion, and belonging relative to theirrole.
Minimum Qualifications:
- Bachelor's degree from a college or university accredited by aU.S. Department of Education (DOE) or an internationally recognizedaccrediting organization.
- At least 3 years of professional experience in modern incidentresponse, including investigation, containment, remediation, anduse of enterprise security tooling such as Microsoft Defender,Microsoft Sentinel, or comparable platforms.
- At least 3 years of professional experience in networksecurity, including hands-on work with technologies and practicessuch as next-generation firewalls, intrusion detectionsystem/intrusion prevention system (IDS/IPS), segmentation, trafficanalysis, or related controls.
- Demonstrated experience collaborating with infrastructure,systems, or application teams to implement security controls,support remediation efforts, or improve operational processes in anenterprise environment.
- Experience using scripting (such as Python or PowerShell),Artificial Intelligence, automation, or security workflows to improve detection, response, or efficiency.
Preferred Qualifications:
- Relevant security certifications (e.g., Certified InformationSystems Security Professional (CISSP), Certified Ethical Hacker(CEH), or GIAC Certified Detection Analyst (GCDA)).
- Experience securing cloud and web application environments,including platforms and tools such as Microsoft Azure, Amazon WebServices (AWS), Google Cloud, Cloudflare, Burp Suite, or OpenWorldwide Application Security Project (OWASP)-basedpractices.
- Experience with enterprise detection and response platforms,such as SIEM, XDR, or AI-assisted security operations tools.
- Experience working in higher education or similarly complexenvironments, including support for institutional AI use, riskmanagement, or compliance initiatives.
Working Environment:
- Available for scheduled after-hours support, includingoccasional evenings, weekends, or holidays.
- On-site in Albany Mondays, Wednesdays, and Fridays (and asneeded). Telecommuting on Tuesdays and Thursdays may be availableafter a probationary period, with supervisor approval.
Additional Information:
Professional Rank and Salary Grade: SeniorProgrammer/Analyst, SL4, $90,000-95,000
Special Note: Visa sponsorship is not available for thisposition. If you currently need sponsorship or will need it in thefuture to maintain employment authorization, you do not meeteligibility requirements. Additionally, please note that UAlbanyis not an E-Verify employer.
The Jeanne Clery Disclosure of Campus Security Policy and CampusCrime Statistics Act, or Clery Act, mandates that all Title IVinstitutions, without exception, prepare, publish and distribute anAnnual Security Report. This report consists of two basic parts:disclosure of the University's crime statistics for the past threeyears; and disclosures regarding the University's current campussecurity policies. The University at Albany's Annual SecurityReport is available in portable document format PDF by clicking this link http://police.albany.edu/ASR.shtml
Pursuant to New York Labor Law 194-a, the University will not seek,request, or rely upon an applicant's wage or salary history indetermining whether to interview, hire, or establish compensationfor an applicant. Applicants are not required to provide wage orsalary history information as a condition of employmentconsideration. Salary history may only be verified in the limitedcircumstances permitted by law.
THE UNIVERSITY AT ALBANY IS AN EO/AA/IRCA/ADA EMPLOYER
Preference will be given to applications received by September22.