IT Security Analyst
UCSFCertain terms and conditions of employment for this position, including the rate of pay, benefits, etc., are currently subject to negotiation with the appropriate union.
The Cybersecurity Awareness Analyst leads the design and execution of the organization’s security awareness and training programs in support of its healthcare and research mission. This role develops and delivers programs that ensure faculty, staff, students, and affiliated personnel “know, understand, and follow [security] requirements” in order to reduce institutional risk. The Analyst works closely with the Cybersecurity Risk Management Manager and CISO to support broader security initiatives, policy development, and compliance (e.g. HIPAA, FERPA, institutional data protection). The position balances communications, training, and technical expertise to foster a culture of security across research, academic, healthcare, and IT communities.
This experienced IT security professional applies specialized expertise in security awareness, governance, and training. The Analyst designs and recommends methods and strategies to achieve security awareness goals, leveraging advanced knowledge of cybersecurity principles, regulatory requirements, and learning best practices. The individual works independently to develop creative, long-term awareness solutions and provides technical and strategic support on security policy implementation throughout the institution.
Department Overview
UCSF Cybersecurity protects and responds to both internal and external threats. It monitors for vulnerabilities, risks, and exposures and mitigates issues prior to exploitation. If an incident does occur, IT Security investigates, determines impact, and recommends controls for reduced recurrence likelihood.
- Vulnerability Management
- Network Security
- Application Security
- E-Discovery service
- Incident response and forensic analysis
- Threat hunting and event analysis
- Establishing policies and standards for information security
- Providing guidance and conducting risk assessments of systems and solutions
- Governance, risk, and compliance
- Architecting secure business solutions
- Architecting threat detection, security monitoring and forensic solutions
- Outreach and security awareness training and education
- Endpoint security, such as encryption, anti-malware, endpoint detection and response