| f | Job Description: | f | Job Description: |
| t | Certain terms and conditions of employment for this position, including the rate of pay, benefits, e | t | Certain terms and conditions of employment for this position, including the rate of pay, benefits, e |
| tc., are currently subject to negotiation with the appropriate union. The Cybersecurity Awareness An | | tc., are currently subject to negotiation with the appropriate union. We are seeking an experienced |
| alyst leads the design and execution of the organization’s security awareness and training programs | | and versatile Cybersecurity Analyst to join our Cyber Risk Management team and help strengthen cyber |
| in support of its healthcare and research mission. This role develops and delivers programs that ens | | security across a complex academic, healthcare, and research environment. This position will play a |
| ure faculty, staff, students, and affiliated personnel “know, understand, and follow [security] requ | | key role in our Human Risk and Cybersecurity Awareness program, developing and operating engaging se |
| irements” in order to reduce institutional risk. The Analyst works closely with the Cybersecurity Ri | | curity awareness initiatives, simulated phishing campaigns, communications, and outreach designed to |
| sk Management Manager and CISO to support broader security initiatives, policy development, and comp | | measurably reduce human-related cyber risk. The analyst will work with diverse communities—includin |
| liance (e.g. HIPAA, FERPA, institutional data protection). The position balances communications, tra | | g healthcare professionals, researchers, faculty, staff, and students—to transform emerging threats |
| ining, and technical expertise to foster a culture of security across research, academic, healthcare | | into practical, audience-appropriate guidance that improves security behavior and strengthens our ov |
| , and IT communities. This experienced IT security professional applies specialized expertise in sec | | erall security culture. Beyond Human Risk, this is a well-rounded cybersecurity role with opportunit |
| urity awareness, governance, and training. The Analyst designs and recommends methods and strategies | | ies to contribute across Cyber Risk Management, governance, compliance, research security, and enter |
| to achieve security awareness goals, leveraging advanced knowledge of cybersecurity principles, reg | | prise security initiatives. The analyst will support cybersecurity policies and standards, risk asse |
| ulatory requirements, and learning best practices. The individual works independently to develop cre | | ssments, compliance and audit activities, and cross-functional security initiatives in partnership w |
| ative, long-term awareness solutions and provides technical and strategic support on security policy | | ith IT, Privacy, Compliance, Research, and other stakeholders. We are looking for a security profess |
| implementation throughout the institution. Department Overview UCSF Cybersecurity protects and resp | | ional who can operate independently, communicate effectively with both technical and non-technical a |
| onds to both internal and external threats. It monitors for vulnerabilities, risks, and exposures an | | udiences, manage multiple initiatives, and translate cybersecurity risks into actionable recommendat |
| d mitigates issues prior to exploitation. If an incident does occur, IT Security investigates, deter | | ions. Experience working in regulated or complex enterprise environments is highly desirable, with f |
| mines impact, and recommends controls for reduced recurrence likelihood. Vulnerability Management Ne | | amiliarity in areas such as HIPAA, cybersecurity GRC, NIST frameworks, data privacy, security risk m |
| twork Security Application Security E-Discovery service Incident response and forensic analysis Thre | | anagement, and security awareness technologies considered valuable. Department Overview UCSF Cyberse |
| at hunting and event analysis Establishing policies and standards for information security Providing | | curity protects and responds to both internal and external threats. It monitors for vulnerabilities, |
| guidance and conducting risk assessments of systems and solutions Governance, risk, and compliance | | risks, and exposures and mitigates issues prior to exploitation. If an incident does occur, IT Secu |
| Architecting secure business solutions Architecting threat detection, security monitoring and forens | | rity investigates, determines impact, and recommends controls for reduced recurrence likelihood. Vul |
| ic solutions Outreach and security awareness training and education Endpoint security, such as encry | | nerability Management Network Security Application Security E-Discovery service Incident response an |
| ption, anti-malware, endpoint detection and response | | d forensic analysis Threat hunting and event analysis Establishing policies and standards for inform |
| | | ation security Providing guidance and conducting risk assessments of systems and solutions Governanc |
| | | e, risk, and compliance Architecting secure business solutions Architecting threat detection, securi |
| | | ty monitoring and forensic solutions Outreach and security awareness training and education Endpoint |
| | | security, such as encryption, anti-malware, endpoint detection and response |
| | | |
| Qualifications: | | Qualifications: |
| REQUIRED QUALIFICATIONS - Bachelor’s degree in Computer Science, Information Security, Education, Co | | REQUIRED QUALIFICATIONS - Bachelor’s degree in Computer Science, Information Security, Education, Co |
| mmunications, or a related field (or equivalent experience). - Minimum related experience, 5+ years | | mmunications, or a related field (or equivalent experience). - Minimum related experience, 5+ years |
| - Communication: Able to translate complex security concepts into clear, concise messages for divers | | - Communication: Able to translate complex security concepts into clear, concise messages for divers |
| e audiences (students, faculty, clinicians, IT staff) - Security Expertise: Broad knowledge of infor | | e audiences (students, faculty, clinicians, IT staff) - Security Expertise: Broad knowledge of infor |
| mation security principles, risk management and threat landscape. Familiarity with NIST or similar f | | mation security principles, risk management and threat landscape. Familiarity with NIST or similar f |
| rameworks. Understanding of healthcare and research privacy requirements (HIPAA, FERPA) and how to i | | rameworks. Understanding of healthcare and research privacy requirements (HIPAA, FERPA) and how to i |
| ncorporate them into training - Project Management: Strong organizational and planning skills. Exper | | ncorporate them into training - Project Management: Strong organizational and planning skills. Exper |
| ience managing projects from conception through implementation, including scheduling, resource coord | | ience managing projects from conception through implementation, including scheduling, resource coord |
| ination, and reporting - Collaboration: Proven ability to work cross-functionally with IT, legal/com | | ination, and reporting - Collaboration: Proven ability to work cross-functionally with IT, legal/com |
| pliance, clinical, and academic stakeholders. Skilled at coordinating people and tasks across depart | | pliance, clinical, and academic stakeholders. Skilled at coordinating people and tasks across depart |
| ments to achieve security goals. REQUIRED CERTIFICATIONS - Relevant professional certifications pref | | ments to achieve security goals. REQUIRED CERTIFICATIONS - Relevant professional certifications pref |
| erred (e.g. CISSP, CISM, Security+). Certification or coursework in security awareness, instructiona | | erred (e.g. CISSP, CISM, Security+). Certification or coursework in security awareness, instructiona |
| l design, or project management is desirable. PREFERRED QUALIFICATIONS - Training & Education: Profi | | l design, or project management is desirable. PREFERRED QUALIFICATIONS - Training & Education: Profi |
| ciency with training design and delivery (e.g. adult learning, e-learning platforms, phishing simula | | ciency with training design and delivery (e.g. adult learning, e-learning platforms, phishing simula |
| tion tools). Ability to evaluate training effectiveness and metrics (completion rates, assessment re | | tion tools). Ability to evaluate training effectiveness and metrics (completion rates, assessment re |
| sults). - Analytical Skills: Problem-solving mindset and attention to detail. Able to assess program | | sults). - Analytical Skills: Problem-solving mindset and attention to detail. Able to assess program |
| outcomes, identify areas for improvement, and adapt strategies accordingly. Basic understanding of | | outcomes, identify areas for improvement, and adapt strategies accordingly. Basic understanding of |
| information risk concepts is required | | information risk concepts is required |