IT Security Specialist II
Listed on 2026-07-23
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Opportunity
The University of Miami Health System (“UHealth”) IT Department has an exciting opportunity for an IT Security Specialist II to join its team in Miami in a full-time capacity.
The Security Specialist II is primarily responsible for the end user and technical security training and awareness program s position will also provide technical support for all activities related to the CISO office, including PCI‑DSS compliance tasks, auditing, risk management, and security assessments. The CISO Security Specialist II will partner with risk management activities as authorized by the Chief Information Security Officer (CISO), independently and in teams.
The Security Specialist II will be assigned to tasks of a highly technical nature that require expert understanding of security technologies and strategies. This individual is expected to provide technical direction in the identification and remediation of system and application vulnerabilities and controls to successfully accomplish the objectives and goals of the CISO office.
Core Responsibilities- Provide support to technical and non‑technical teams on security findings while maintaining industry best practice standards.
- Collect, analyze threat intelligence reports, and get escalated depending on the risk level.
- Draft comprehensive reports, including assessment‑based findings and outcomes, and propositions for further system security enhancements.
- Performs vulnerability scans, assesses impact and risk, and owns remediation efforts end‑to‑end, ensuring timely resolution and alignment with security priorities.
- Monitors and analyzes emerging security threats and related vulnerabilities for the University’s vulnerability management program.
- Develop and implement standard operating procedures to monitor vulnerabilities, including CISA advisories, vendor’s vulnerability disclosures, ISACs threat reports, and security vendors’ reports.
- Adheres to University and unit‑level policies and procedures and safeguards University assets.
- Support the incident response process to the resolution of the incident.
- Ensures the delivery of threat intelligence collected from incident engagements to threat intelligence teams and content creators for operationalization.
- Maintain and enhance threat and vulnerability management program to discover and track current cyber‑threats.
- Process and enrich information to ensure timely, actionable high‑confidence IOCs are ingested and shared with key stakeholders.
- Produce actionable intelligence and proactively drive threat hunting, detection and prevention.
- Responsible for working within the security operations team and providing direct risk intelligence support in cross‑functional areas of business resilience, physical security, supply chain, business continuity, illegal trade, criminal investigations, and other initiatives.
- Stay informed and provide subject‑matter expertise regarding recent attacks/exploits—especially against the healthcare industry and relevant web applications, databases, and common desktop tools.
- Partner closely with other functions within the cybersecurity and IT management teams and collaborate with the security operations center and Managed Security Services Provider to ensure consistent and quality Incident Response services are provided to the organization.
- Produce, maintain, and disseminate threat intelligence summaries.
- Be available for on‑call duty to handle high‑impact cybersecurity incidents.
Minimum Qualifications
- Bachelor’s degree in Computer Science, Mathematics, Statistics, or a related field. A master’s degree is highly desirable.
- Preferred industry certifications including CompTIA CySA+, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM) or the equivalent, Cloud Computing Security Certification, GIAC Certified Incident Handler (GCIH).
- 5–7+ years of progressive cybersecurity experience with 3+ years directly related to threat and vulnerability management, threat…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).