Information Security Operations Analyst , Berkeley IT
Listed on 2026-07-05
-
IT/Tech
Cybersecurity, Information Security, Network Security, IT Consultant
Information Security Operations Analyst (0661U), Berkeley IT - 87198 Departmental Overview
The Information Security Office (ISO) coordinates the risk management process for UC Berkeley's information systems and directs campus-wide efforts to adequately secure institutional data. ISO is led by the Chief Information Security Officer and consists of five teams:
Policy and Outreach, Security Operations, Development and Engineering, Identity Management, and Security Assessments. This position is part of the Security Operations team and reports to the Information Security Operations Supervisor.
The Information Security Operations team is a close-knit group of talented information security professionals performing critical information security functions for the institution, including monitoring for intrusion, vulnerability scanning, incident/breach response, asset registration, designing and building security systems to help reduce risk, and the management of systems in support of these functions both on‑premises and in multiple cloud environments.
This position supports the activities of the Security Operations team as a Security Analyst, including security log/alert review, incident handling, security consulting, and architecture review. The successful candidate should have sufficient knowledge and experience to analyze and respond to security incidents of moderate scope and complexity, design and build security systems, and deploy commercial security tools and integrate with existing production operations.
PositionSummary
- Strong foundation in IT and a passion for security. At least 5 years of hands‑on experience in general IT supporting systems, troubleshooting issues, and applying security best practices across desktop and server environments.
- At least three years in a Security Operations role, with experience in network log analysis, EDR, SIEM, vulnerability scanning, cloud security, or incident response. Comfortable in several of these areas and eager to keep learning.
- Strong communicator who can explain technical concepts clearly to IT peers and campus partners with less technical background. Capable of collaborating across teams and mentoring less experienced colleagues.
- Solid understanding of information security principles and best practices, including host and network forensics. Ability to think pragmatically, solve problems creatively, and collaborate closely with architects, engineers, developers, and service providers.
- Experience leading or contributing to security efforts across on‑prem and cloud environments, familiar with SaaS, IaaS, and PaaS. Understanding of incident response processes and security frameworks such as NIST and CIS.
- Inclusive mindset, curiosity, adaptability, and genuine appreciation for different perspectives, actively contributing to an inclusive work environment.
- Bachelor’s degree in a related field is preferred but equivalent experience and training are recognized.
- Ability to quickly learn organizational policies and standards and work independently or as part of a collaborative, cross‑functional security team.
- Implement complex and broad‑scale security controls to detect and prevent unauthorized access or changes to campus hardware, software, and network infrastructure using firewalls, network TAPs, IDS/IPS, EDR agents, and SIEM systems.
- Advise and recommend broad‑scope security controls to protect critical information and sensitive systems both on‑premises and in multiple cloud environments.
- Research and address attempts to compromise endpoints using EDR agents.
- Identify, develop, implement, and maintain systems for detecting and identifying malicious activity using IDS/IPS across campus and cloud environments.
- Research and analyze security alerts that may indicate attempts to compromise campus IT resources, and appropriately escalating alerts for further review.
- Design and maintain highly complex security systems, administer advanced security policies and configurations, and apply advanced encryption methods.
- Track and monitor incoming security incidents, applying security concepts and established campus procedures to ensure an appropriate incident…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).