Sr. User Security & Access Analyst - Hybrid - 140754

University of California San Diego

San Diego (CA)

Hybrid

USD 125,000 - 176,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

UC San Diego Health is seeking a Sr. User Security & Access Analyst to lead identity, access management, and governance initiatives.

You will provide expert direction on SailPoint, Okta, Azure AD, and Epic security, while guiding complex access models and provisioning workflows. The role requires advanced security knowledge and leadership in cross-functional teams, with a hybrid work arrangement reflecting onsite Towne Centre Drive and remote work.

Qualifications

  • Nine years of related experience or a Bachelor's degree plus five years.
  • Advanced interpersonal skills to work with technical and non-technical staff.
  • Extensive IT security systems and tools experience.
  • Knowledge of department processes and procedures.
  • Experience applying security controls to software and hardware.
  • Ability to administer complex security controls and configurations.

Responsibilities

  • Lead analysis and resolution of complex access and security issues.
  • Serve as technical lead for identity platforms (SailPoint/Okta/Azure AD).
  • Develop access management processes, RBAC models, provisioning workflows.
  • Evaluate complex access requirements and design secure solutions.
  • Lead security analyses across multiple applications and departments.
  • Assess risks related to access decisions and compliance.
  • Identify and remediate overly complex or conflicting access structures.
  • Provide guidance on Epic roles, provisioning models, and standardization.
  • Lead or support major projects and enterprise initiatives.
  • Recommend improvements to security standards and governance.
  • Drive process improvement and automation with broad impact.
  • Collaborate with leadership and stakeholders on security matters.
  • Support audit readiness and remediation strategies.
  • Mentor junior analysts and provide technical guidance.
  • Contribute to procedures, standards, and training programs.
  • Identify emerging security risks and propose solutions.
  • Provide management with policy and strategic recommendations.
  • On-call coverage for User Security and Access rotation.

Skills

Identity & Access Management
Epic security
SailPoint
Okta
Azure AD / Entra ID
Active Directory
RBAC / least privilege
Access governance
Provisioning workflows
Security risk assessment
Security policy & governance
Audit controls & remediation

Education

Bachelor's degree in related area

Tools

SailPoint
Okta
Azure AD
Active Directory

Job description

Payroll Title: IT SCRTY ANL 4 TX

Department: INFORMATION SERVICES

Hiring Pay Scale: $125,000 - 176,000 / Year

Worksite: Towne Centre Drive

Appointment Type: Career

Appointment Percent: 100%

Union: TX Contract

Total Openings: 1

Work Schedule: Days, 8 hrs/day, Monday-Friday

#140754 Sr. User Security & Access Analyst - Hybrid

Filing Deadline: Wed 9/30/2026

Reassignment Applicants: Eligible Reassignment clients should contact their Disability Counselor for assistance.

This position has recently been accreted by UPTE TX and will be a part of that union moving forward.

This position will work a hybrid schedule which includes a combination of working both onsite at Towne Centre Drive (San Diego, CA) and remote.

DESCRIPTION

The User Security & Access Analyst IV is an advanced individual contributor and recognized subject matter expert responsible for leading highly complex and high-impact identity, access management, Epic security, and access governance initiatives. This position provides advanced technical direction, leads complex security analysis and process improvements, influences enterprise access standards, and serves as a trusted technical resource for leadership and cross-functional stakeholders.

Primary Responsibilities:

  • Lead analysis and resolution of highly complex, high-impact, or cross-functional access and security issues.
  • Serve as a technical lead for enterprise identity platforms, including SailPoint, Okta, Microsoft Entra ID (Azure AD), and Active Directory, ensuring system reliability, integration effectiveness, and alignment with standards.
  • Develop and enhance access management processes, role-based security models, provisioning workflows, and governance controls while providing advanced troubleshooting, risk assessment, and guidance on complex identity and access matters.
  • Evaluate complex or unprecedented access requirements and develop secure, sustainable solutions when existing processes do not adequately address the need.
  • Lead security analysis involving multiple applications, departments, workflows, or organizational areas.
  • Evaluate technical, operational, compliance, and security risks associated with access decisions.
  • Lead efforts to identify and remediate excessive, conflicting, outdated, or unnecessarily complex access structures.
  • Provide advanced guidance regarding Epic roles, security templates, provisioning models, and access standardization.
  • Lead or serve as the security subject matter expert for major projects and enterprise initiatives.
  • Develop and recommend improvements to security standards, procedures, governance, and access-management practices.
  • Lead strategic process-improvement and automation initiatives with broader organizational impact.
  • Partner with leadership, application owners, compliance, risk, HR, IT, and operational stakeholders on complex security matters.
  • Lead audit-readiness activities and assist in developing sustainable remediation strategies.
  • Expected to mentor and provide technical guidance to junior analysts on complex security and access matters.
  • Support leadership in the development, implementation, and continuous improvement of procedures, standards, documentation, and technical training programs.
  • Identify emerging security, operational, and access-management risks and recommend appropriate solutions.
  • Provide technical recommendations to management when matters require broader policy, organizational, or strategic decisions.
  • 7/24 On Call for User Security and Access Team rotation.

Decision Making & Independence

Operates with a high degree of independence and professional judgment. Develops recommendations and solutions for complex situations where precedent may not exist or established procedures may require enhancement. Provides expert technical recommendations while appropriately engaging the Supervisor or Manager for matters requiring management authority, policy decisions, organizational direction, or significant risk acceptance.

Technical Knowledge

Expert or highly advanced knowledge of:

  • Identity and Access Management (IAM)
  • Epic security architecture and provisioning
  • SailPoint, Okta, Microsoft Entra ID (Azure AD), and Epic Security
  • Role-Based Access Control and least privilege
  • Access governance and lifecycle management
  • Security risk assessment
  • Regulatory and compliance requirements
  • Audit controls and remediation
  • Enterprise provisioning strategies
  • Process automation and standardization
  • Security policy and governance frameworks

Technical Leadership

Provides technical leadership rather than people management. The role is expected to mentor junior analysts, lead technical work, coordinate complex initiatives, and serve as an escalation resource based on expertise. The position does not replace the Supervisor or Manager as the team's formal leadership or final organizational decision-making authority.

MINIMUM QUALIFICATIONS
  • Nine (9) years of related experience, education/training, OR a Bachelor’s degree in related area plus five (5) years of related experience/training.
  • Advanced interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.
  • Advanced experience using IT security systems and tools.
  • Knowledge of department processes and procedures.
  • Demonstrated skills applying security controls to computer software and hardware.
  • Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks.
  • Advanced knowledge of data encryption technologies and experience selecting and applying appropriate data encryption technologies.
  • Advanced knowledge of IT security.
  • Broad knowledge of other areas of IT.
  • Demonstrated knowledge of secure hardware, software and network design techniques.
  • Demonstrated skill at analyzing and preventing security incidents of high complexity.
  • In-depth knowledge of computer hardware, software and network security issues and approaches.
  • Advanced experience in incident response and digital forensics including reporting.
PREFERRED QUALIFICATIONS
  • 7+ years of progressively responsible experience in Identity and Access Management (IAM), Epic Security, information security, or enterprise access management.
  • Advanced experience with Epic Security and enterprise identity platforms, such as SailPoint, Okta, Microsoft Entra ID, and Active Directory.
  • Advanced knowledge of RBAC, least privilege, identity lifecycle management, access governance, provisioning, and security risk assessment.
  • Demonstrated experience leading resolution of highly complex or high-impact access issues and developing secure, scalable solutions.
  • Experience leading access governance, role/template optimization, audit remediation, process improvement, or automation initiatives, preferably in a healthcare environment.
  • Demonstrated ability to serve as a technical SME, provide technical guidance and mentorship, and communicate recommendations to leadership and cross-functional stakeholders.
  • Epic Security, IAM, or related security certification/training.
SPECIAL CONDITIONS
  • 7/24 On Call for User Security and Access Team rotation.
  • Must be able to work various hours and locations based on business needs.
  • Employment is subject to a criminal background check and pre-employment physical.

Pay Transparency Act

Annual Full Pay Range: Unclassified - No data available (will be prorated if the appointment percentage is less than 100%)

Hourly Equivalent: Unclassified - No data available

Factors in determining the appropriate compensation for a role include experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. The Hiring Pay Scale referenced in the job posting is the budgeted salary or hourly range that the University reasonably expects to pay for this position. The Annual Full Pay Range may be broader than what the University anticipates to pay for this position, based on internal equity, budget, and collective bargaining agreements (when applicable).

If employed by the University of California, you will be required to comply with our Policy on Vaccination Programs, which may be amended or revised from time to time. Federal, state, or local public health directives may impose additional requirements.

If applicable, life-support certifications (BLS, NRP, ACLS, etc.) must include hands-on practice and in-person skills assessment; online-only certification is not acceptable.

UC San Diego Health is the only academic health system in the San Diego region, providing leading-edge care in patient care, biomedical research, education, and community service. Our facilities include two university hospitals, a National Cancer Institute-designated Comprehensive Cancer Center, Shiley Eye Institute, Sulpizio Cardiovascular Center, the only Burn Center in the county, and dozens of outpatient clinics. We invite you to join our team!

Applications/Resumes are accepted for current job openings only. For full consideration on any job, applications must be received prior to the initial closing date. If a job has an extended deadline, applications/resumes will be considered during the extension period; however, a job may be filled before the extended date is reached.

To foster the best possible working and learning environment, UC San Diego strives to cultivate a rich and diverse environment, inclusive and supportive of all students, faculty, staff and visitors. For more information, please visit UC San Diego Principles of Community.

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.

For the University of California’s Anti-Discrimination Policy, please visit https://policy.ucop.edu/doc/1001004/Anti-Discrimination

UC San Diego is a smoke and tobacco free environment. Please visit smokefree.ucsd.edu for more information.

UC San Diego Health maintains a marijuana and drug free environment. Employees may be subject to drug screening.

Misconduct Disclosure Requirement:

As a condition of employment, the final candidate who accepts an offer of employment will be required to disclose if they have been subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct; or have filed an appeal of a finding of substantiated misconduct with a previous employer.

a. \"Misconduct\" means any violation of the policies governing employee conduct at the applicant’s previous place of employment, including, but not limited to, violations of policies prohibiting sexual harassment, sexual assault, or discrimination, as defined by the employer. For reference, below are UC’s policies addressing some forms of misconduct:

  • UC Sexual Violence and Sexual Harassment Policy
  • UC Anti-Discrimination Policy
  • Abusive Conduct in the Workplace
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

User Security & Access Analyst - Hybrid - 140760
User Security & Access Analyst - Hybrid - 140760

University of California San Diego • San Diego (CA)

Hybrid
USD 100,000 - 140,000
Hybrid schedule
On-call rotation
Information Security Analyst - Hybrid - 140203
Information Security Analyst - Hybrid - 140203

UC San Diego Health • San Diego (CA)

On-site
USD 125,000 - 165,000
IS Customer Support Analyst - 141360
IS Customer Support Analyst - 141360

University of California San Diego • San Diego (CA)

Hybrid
USD 44,000 - 72,000
IS Customer Support Analyst - 141360
IS Customer Support Analyst - 141360

San Diego Supercomputer Center • San Diego (CA)

On-site
USD 45,000 - 72,000
Sr. Epic Cadence / Referral Analyst - Hybrid - 141252
Sr. Epic Cadence / Referral Analyst - Hybrid - 141252

University of California San Diego • San Diego (CA)

Hybrid
USD 125,000 - 182,000
Sr. Academic Affairs Analyst, VC-Health Sciences - 140588
Sr. Academic Affairs Analyst, VC-Health Sciences - 140588

University of California San Diego • San Diego (CA)

Hybrid
USD 79,200 - 105,000
Executive Operations Administrator - 141266
Executive Operations Administrator - 141266

University of California San Diego • San Diego (CA)

On-site
USD 87,000 - 127,000
Sr. Network Engineer - Hybrid - 140755
Sr. Network Engineer - Hybrid - 140755

University of California San Diego • San Diego (CA)

Hybrid
USD 126,000 - 164,000
JPA Epic Implementation Manager - Hybrid - 141093
JPA Epic Implementation Manager - Hybrid - 141093

UC San Diego Health • San Diego (CA)

Hybrid
USD 125,000 - 167,000
Institute Business Officer, AHI - 141201
Institute Business Officer, AHI - 141201

University of California San Diego • San Diego (CA)

On-site
USD 105,000 - 136,000