Information Security Operations Analyst (0661U), Berkeley IT - #87198

University of California, Berkeley

Berkeley (CA)

On-site

USD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive benefits package
Full UC benefits

Job summary

The University of California, Berkeley is hiring an Information Security Operations Analyst to enhance the protection of its information systems. Candidates must have at least 5 years in IT and 3 years in security operations, focusing on incident response and log analysis.

This full-time position provides comprehensive benefits and requires a collaborative mindset to improve campus-wide security measures. Strong interpersonal skills and a Bachelor’s degree or equivalent experience are preferred.

Qualifications

  • Minimum of 5 years in IT support and security best practices.
  • At least 3 years in a Security Operations role.
  • Solid understanding of information security principles.

Responsibilities

  • Implement and maintain security controls to protect systems.
  • Advise on security measures to protect sensitive information.
  • Research and respond to security incidents.

Skills

General IT knowledge
Network log analysis
Incident response
Strong communication skills
Collaboration

Education

Bachelor’s degree in a related field or equivalent experience

Tools

EDR
SIEM
Vulnerability scanning tools
Intrusion detection systems

Job description

Information Security Operations Analyst (0661U), Berkeley IT - 87198
Departmental Overview

The Information Security Office (ISO) coordinates the risk management process for UC Berkeley's information systems and directs campus-wide efforts to adequately secure institutional data. ISO is led by the Chief Information Security Officer and consists of five teams: Policy and Outreach, Security Operations, Development and Engineering, Identity Management, and Security Assessments. This position is part of the Security Operations team and reports to the Information Security Operations Supervisor.

The Information Security Operations team is a close-knit group of talented information security professionals performing critical information security functions for the institution, including monitoring for intrusion, vulnerability scanning, incident/breach response, asset registration, designing and building security systems to help reduce risk, and the management of systems in support of these functions both on‑premises and in multiple cloud environments.

This position supports the activities of the Security Operations team as a Security Analyst, including security log/alert review, incident handling, security consulting, and architecture review. The successful candidate should have sufficient knowledge and experience to analyze and respond to security incidents of moderate scope and complexity, design and build security systems, and deploy commercial security tools and integrate with existing production operations.

Position Summary
  • Strong foundation in IT and a passion for security. At least 5 years of hands‑on experience in general IT supporting systems, troubleshooting issues, and applying security best practices across desktop and server environments.
  • At least three years in a Security Operations role, with experience in network log analysis, EDR, SIEM, vulnerability scanning, cloud security, or incident response. Comfortable in several of these areas and eager to keep learning.
  • Strong communicator who can explain technical concepts clearly to IT peers and campus partners with less technical background. Capable of collaborating across teams and mentoring less experienced colleagues.
  • Solid understanding of information security principles and best practices, including host and network forensics. Ability to think pragmatically, solve problems creatively, and collaborate closely with architects, engineers, developers, and service providers.
  • Experience leading or contributing to security efforts across on‑prem and cloud environments, familiar with SaaS, IaaS, and PaaS. Understanding of incident response processes and security frameworks such as NIST and CIS.
  • Inclusive mindset, curiosity, adaptability, and genuine appreciation for different perspectives, actively contributing to an inclusive work environment.
  • Bachelor’s degree in a related field is preferred but equivalent experience and training are recognized.
  • Ability to quickly learn organizational policies and standards and work independently or as part of a collaborative, cross‑functional security team.
Responsibilities
  • Implement complex and broad‑scale security controls to detect and prevent unauthorized access or changes to campus hardware, software, and network infrastructure using firewalls, network TAPs, IDS/IPS, EDR agents, and SIEM systems.
  • Advise and recommend broad‑scope security controls to protect critical information and sensitive systems both on‑premises and in multiple cloud environments.
  • Research and address attempts to compromise endpoints using EDR agents.
  • Identify, develop, implement, and maintain systems for detecting and identifying malicious activity using IDS/IPS across campus and cloud environments.
  • Research and analyze security alerts that may indicate attempts to compromise campus IT resources, and appropriately escalating alerts for further review.
  • Design and maintain highly complex security systems, administer advanced security policies and configurations, and apply advanced encryption methods.
  • Track and monitor incoming security incidents, applying security concepts and established campus procedures to ensure an appropriate incident response.
  • Advise and provide leadership to campus IT personnel responding to security incidents, aiding in execution of incident response plans.
  • Direct forensic activity and produce reports for highly complex or broad‑scale security incidents, leading a team of IT security professionals when necessary.
  • Monitor incident status and workflows, escalating unusual or problematic incidents for further action.
  • Advise campus community members with questions about security configuration of campus IT systems.
  • Triage security incidents and support tickets during periodic analyst rotation.
  • Engage in continuous professional development and training and other duties as assigned.
Required Qualifications
  • Minimum of 5 years of general IT knowledge and experience, including support, troubleshooting, and security best practices for a variety of desktop/server operating systems and software.
  • Excellent written and verbal communication skills, and ability to communicate across a broad range of campus audiences.
  • Strong interpersonal skills to work with both technical and non‑technical personnel at various organizational levels.
  • Ability to serve as a lead for less experienced professionals on campus.
  • Advanced knowledge of key information security concepts, functions, and general best practices.
  • Commitment to understanding different perspectives and cultures, contributing to a work climate where differences are valued and supported.
  • Bachelor’s degree in a related area and/or equivalent experience/training.
Preferred Qualifications
  • At least 3 years of experience as a Security Operations Analyst, utilizing network forensics and hands‑on experience with network IDS/firewall log analysis, EDR, SIEM, vulnerability scanning, Cloud Security Posture Management, or incident handling/response.
  • Strong technologist with a pragmatic view and creative mind, and a natural collaborator with architects, engineers, developers, application owners, and service providers.
  • Experience serving as technical lead for engaging communities on information security issues in both on‑premises and cloud environments.
  • Ability to quickly learn and work within UC Berkeley campus and system‑wide (Office of the President) security policies and standards.
  • Proficiency in working as part of a collaborative, cross‑functional, modern security team.
  • Demonstrated ability to assume independent and team‑based responsibilities.
  • Advanced knowledge of intrusion detection, firewall, host, and network forensics.
  • Experience with technologies such as SaaS, IaaS, PaaS, and other cloud environments.
  • Knowledge of incident handling policies and procedures.
  • Experience in the design and development of security architectures for cloud‑native and hybrid cloud‑based systems.
  • Ability to develop technical solutions to mitigate observed security gaps and vulnerabilities.
  • Experience applying controls in alignment with identified security frameworks such as NIST, CIS, CSA, MITRE ATT&CK.
Salary & Benefits

For information on the comprehensive benefits package offered by the University, please visit the University of California's Compensation & Benefits website.

  • This is an exempt monthly‑paid position.
  • This is a full‑time (40 hours/week) career position eligible for full UC benefits.
Equal Employment Opportunity

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California-Berkeley • Berkeley (CA)

On-site
USD 91,000 - 120,000
IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California, Berkeley • Berkeley (CA)

On-site
IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California • Berkeley (CA)

On-site
USD 91,500 - 120,000
Information Systems Analyst 2, SSALLEX (5461C) #87759
Information Systems Analyst 2, SSALLEX (5461C) #87759

University of California-Berkeley • Berkeley (CA)

On-site
On-site work at Main Campus-Berkeley
Senior Identity and Access Management Manager (6019U) Berkeley IT, #87641
Senior Identity and Access Management Manager (6019U) Berkeley IT, #87641

University of California • Berkeley (CA)

On-site
USD 150,000 - 210,000
Remote work eligibility
Information Systems Analyst 2, SSALLEX (5461C) #87759
Information Systems Analyst 2, SSALLEX (5461C) #87759

University of California, Berkeley • Berkeley (CA)

On-site
USD 78,000 - 109,000
Information Systems Analyst 2, SSALLEX (5461C) #87759
Information Systems Analyst 2, SSALLEX (5461C) #87759

University of California • Berkeley (CA)

On-site
USD 52,348 - 71,635
Senior Information Security Analyst
Senior Information Security Analyst

UMass Amherst • Amherst (MA)

Hybrid
USD 120,000 - 150,000
Senior IT Security Analyst – Systems & SIEM
Senior IT Security Analyst – Systems & SIEM

University of California, Berkeley • Berkeley (CA)

On-site
IT Security Engineer: SIEM, IDS/IPS & Automation
IT Security Engineer: SIEM, IDS/IPS & Automation

University of California • Berkeley (CA)

On-site
USD 91,500 - 120,000