IT Security Analyst

University of California, San Francisco

San Francisco (CA)

On-site

USD 140,000 - 190,000

Full time

30 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

University of California, San Francisco seeks a Cybersecurity Awareness Analyst to design and execute security awareness programs across our healthcare and research mission. You will balance communications, training, and technical expertise to foster a culture of security among faculty, staff, students, and affiliated personnel.

The role collaborates with the CISO and Risk Management to support policy development, HIPAA/FERPA compliance, and broader security initiatives, ensuring clear,

Qualifications

  • Translate complex security concepts into clear messages for diverse audiences (students, faculty, clinicians, IT staff).
  • Broad knowledge of information security principles, risk management and threat landscape; familiarity with NIST or similar frameworks.

Responsibilities

  • Design and lead security awareness programs and training across the organization.
  • Develop and deliver programs to reduce institutional risk and ensure compliance (HIPAA, FERPA).
  • Support policy implementation and security governance initiatives across campus.

Skills

Communication
Security expertise
Project management
Collaboration

Education

Bachelor’s degree in Computer Science/Information Security/Education/Communications

Job description

Job Description

Certain terms and conditions of employment for this position, including the rate of pay, benefits, etc., are currently subject to negotiation with the appropriate union.

Job Description

Certain terms and conditions of employment for this position, including the rate of pay, benefits, etc., are currently subject to negotiation with the appropriate union.

The Cybersecurity Awareness Analyst leads the design and execution of the organization’s security awareness and training programs in support of its healthcare and research mission. This role develops and delivers programs that ensure faculty, staff, students, and affiliated personnel “know, understand, and follow [security] requirements” in order to reduce institutional risk. The Analyst works closely with the Cybersecurity Risk Management Manager and CISO to support broader security initiatives, policy development, and compliance (e.g. HIPAA, FERPA, institutional data protection). The position balances communications, training, and technical expertise to foster a culture of security across research, academic, healthcare, and IT communities.

This experienced IT security professional applies specialized expertise in security awareness, governance, and training. The Analyst designs and recommends methods and strategies to achieve security awareness goals, leveraging advanced knowledge of cybersecurity principles, regulatory requirements, and learning best practices. The individual works independently to develop creative, long-term awareness solutions and provides technical and strategic support on security policy implementation throughout the institution.

Department Overview

UCSF Cybersecurity protects and responds to both internal and external threats. It monitors for vulnerabilities, risks, and exposures and mitigates issues prior to exploitation. If an incident does occur, IT Security investigates, determines impact, and recommends controls for reduced recurrence likelihood.

  • Vulnerability Management
  • Network Security
  • Application Security
  • E-Discovery service
  • Incident response and forensic analysis
  • Threat hunting and event analysis
  • Establishing policies and standards for information security
  • Providing guidance and conducting risk assessments of systems and solutions
  • Governance, risk, and compliance
  • Architecting secure business solutions
  • Architecting threat detection, security monitoring and forensic solutions
  • Outreach and security awareness training and education
  • Endpoint security, such as encryption, anti-malware, endpoint detection and response
Qualifications
REQUIRED QUALIFICATIONS
  • Bachelor’s degree in Computer Science, Information Security, Education, Communications, or a related field (or equivalent experience).
  • Minimum related experience, 5+ years
  • Communication: Able to translate complex security concepts into clear, concise messages for diverse audiences (students, faculty, clinicians, IT staff)
  • Security Expertise: Broad knowledge of information security principles, risk management and threat landscape. Familiarity with NIST or similar frameworks. Understanding of healthcare and research privacy requirements (HIPAA, FERPA) and how to incorporate them into training
  • Project Management: Strong organizational and planning skills. Experience managing projects from conception through implementation, including scheduling, resource coordination, and reporting
  • Collaboration: Proven ability to work cross-functionally with IT, legal/compliance, clinical, and academic stakeholders. Skilled at coordinating people and tasks across departments to achieve security goals.
Required Certifications
  • Relevant professional certifications preferred (e.g. CISSP, CISM, Security+). Certification or coursework in security awareness, instructional design, or project management is desirable.
Preferred Qualifications
  • Training & Education: Proficiency with training design and delivery (e.g. adult learning, e-learning platforms, phishing simulation tools). Ability to evaluate training effectiveness and metrics (completion rates, assessment results).
  • Analytical Skills: Problem-solving mindset and attention to detail. Able to assess program outcomes, identify areas for improvement, and adapt strategies accordingly. Basic understanding of information risk concepts is required
About Us
About UCSF

The University of California, San Francisco (UCSF) is a leading university dedicated to promoting health worldwide through advanced biomedical research, graduate-level education in the life sciences and health professions, and excellence in patient care. It is the only campus in the 10-campus UC system dedicated exclusively to the health sciences. We bring together the world’s leading experts in nearly every area of health. We are home to five Nobel laureates who have advanced the understanding of cancer, neurodegenerative diseases, aging and stem cells.

Pride Values

UCSF is a diverse community made of people with many skills and talents. We seek candidates whose work experience or community service has prepared them to contribute to our commitment to professionalism, respect, integrity, diversity and excellence – also known as our PRIDE values .

In addition to our PRIDE values, UCSF is committed to equity – both in how we deliver care as well as our workforce. We are committed to building a broadly diverse community, nurturing a culture that is welcoming and supportive, and engaging diverse ideas for the provision of culturally competent education, discovery, and patient care. Additional information about UCSF is available here .

Join us to find a rewarding career contributing to improving healthcare worldwide.

Equal Employment Opportunity

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.

Salary Information

The final salary and offer components are subject to additional approvals based on UC policy.

Your placement within the salary range is dependent on a number of factors including your work experience and internal equity within this position classification at UCSF. For positions that are represented by a labor union, placement within the salary range will be guided by the rules in the collective bargaining agreement.

To learn more about the benefits of working at UCSF, including total compensation, please visit: https://ucnet.universityofcalifornia.edu/compensation-and-benefits/index.html

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Analyst
IT Security Analyst

University-of-California---SAN-Francisc • San Francisco (CA)

On-site
USD 120,000 - 175,000
Network Security Administrator
Network Security Administrator

University of California, San Francisco • San Francisco (CA)

On-site
USD 120,000 - 180,000
Network Security Engineer (San Francisco) at University of California - San Francisco Campus an[...]
Network Security Engineer (San Francisco) at University of California - San Francisco Campus an[...]

Shell Lubricants Hub Hamburg • San Francisco (CA)

On-site
USD 136,000 - 204,000
IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California, Berkeley • Berkeley (CA)

On-site
ERP Security Lead
ERP Security Lead

University of California, San Francisco • San Francisco (CA)

On-site
USD 120,000 - 170,000
Security Awareness Analyst – Healthcare & Research IT
Security Awareness Analyst – Healthcare & Research IT

University of California, San Francisco • San Francisco (CA)

On-site
USD 140,000 - 190,000
IT Security Analyst (5353C), Information Security Office #87490
IT Security Analyst (5353C), Information Security Office #87490

University of California-Berkeley • Berkeley (CA)

On-site
USD 91,000 - 120,000
Security Awareness Lead - Healthcare & Research IT
Security Awareness Lead - Healthcare & Research IT

University-of-California---SAN-Francisc • San Francisco (CA)

On-site
USD 120,000 - 175,000
ERP Security Lead
ERP Security Lead

UC San Francisco (UCSF) • San Francisco (CA)

On-site
USD 120,000 - 180,000
Security Supervisor - Oakland
Security Supervisor - Oakland

UCSF Health • Oakland (CA)

On-site
USD 85,000 - 120,000