Certain terms and conditions of employment for this position, including the rate of pay, benefits, etc., are currently subject to negotiation with the appropriate union.
The Cybersecurity Awareness Analyst leads the design and execution of the organization’s security awareness and training programs in support of its healthcare and research mission. This role develops and delivers programs that ensure faculty, staff, students, and affiliated personnel “know, understand, and follow [security] requirements” in order to reduce institutional risk. The Analyst works closely with the Cybersecurity Risk Management Manager and CISO to support broader security initiatives, policy development, and compliance (e.g. HIPAA, FERPA, institutional data protection). The position balances communications, training, and technical expertise to foster a culture of security across research, academic, healthcare, and IT communities.
Â
This experienced IT security professional applies specialized expertise in security awareness, governance, and training. The Analyst designs and recommends methods and strategies to achieve security awareness goals, leveraging advanced knowledge of cybersecurity principles, regulatory requirements, and learning best practices. The individual works independently to develop creative, long-term awareness solutions and provides technical and strategic support on security policy implementation throughout the institution.
Â
Department OverviewÂ
UCSF Cybersecurity protects and responds to both internal and external threats. It monitors for vulnerabilities, risks, and exposures and mitigates issues prior to exploitation. If an incident does occur, IT Security investigates, determines impact, and recommends controls for reduced recurrence likelihood.Â
Â
- Vulnerability Management
- Network Security
- Application Security
- E-Discovery serviceÂ
- Incident response and forensic analysisÂ
- Threat hunting and event analysisÂ
- Establishing policies and standards for information securityÂ
- Providing guidance and conducting risk assessments of systems and solutionsÂ
- Governance, risk, and complianceÂ
- Architecting secure business solutionsÂ
- Architecting threat detection, security monitoring and forensic solutionsÂ
- Outreach and security awareness training and educationÂ
- Endpoint security, such as encryption, anti-malware, endpoint detection and response
Â
Â
Learn more about this Employer on their Career Site
