Cybersecurity Analyst
| Job Name | Cybersecurity Analyst |
| Department | 4111270 - F IT Security and Policy |
| Job ID | 7590 |
| Job Code | IT SCRTY ANL 3 TX (005353) |
| IAP | Staff Plan (target potential payout of $900, maximum of $1,800) |
| Bargaining Unit | TX |
| Job Family | Information Technology |
| Organization | UCSF Campus BU |
| Primary Location | San Francisco, CA, United States |
| Detail URL | https://careers.ucsf.edu/careers/JobDetail/San-Francisco-CA-United-States/3755 |
|---|
Job Description
Job Description:
Certain terms and conditions of employment for this position, including the rate of pay, benefits, etc., are currently subject to negotiation with the appropriate union. We are seeking an experienced and versatile Cybersecurity Analyst to join our Cyber Risk Management team and help strengthen cybersecurity across a complex academic, healthcare, and research environment. This position will play a key role in our Human Risk and Cybersecurity Awareness program, developing and operating engaging security awareness initiatives, simulated phishing campaigns, communications, and outreach designed to measurably reduce human-related cyber risk. The analyst will work with diverse communities—including healthcare professionals, researchers, faculty, staff, and students—to transform emerging threats into practical, audience-appropriate guidance that improves security behavior and strengthens our overall security culture. Beyond Human Risk, this is a well-rounded cybersecurity role with opportunities to contribute across Cyber Risk Management, governance, compliance, research security, and enterprise security initiatives. The analyst will support cybersecurity policies and standards, risk assessments, compliance and audit activities, and cross-functional security initiatives in partnership with IT, Privacy, Compliance, Research, and other stakeholders. We are looking for a security professional who can operate independently, communicate effectively with both technical and non-technical audiences, manage multiple initiatives, and translate cybersecurity risks into actionable recommendations. Experience working in regulated or complex enterprise environments is highly desirable, with familiarity in areas such as HIPAA, cybersecurity GRC, NIST frameworks, data privacy, security risk management, and security awareness technologies considered valuable. Department Overview UCSF Cybersecurity protects and responds to both internal and external threats. It monitors for vulnerabilities, risks, and exposures and mitigates issues prior to exploitation. If an incident does occur, IT Security investigates, determines impact, and recommends controls for reduced recurrence likelihood. Vulnerability Management Network Security Application Security E-Discovery service Incident response and forensic analysis Threat hunting and event analysis Establishing policies and standards for information security Providing guidance and conducting risk assessments of systems and solutions Governance, risk, and compliance Architecting secure business solutions Architecting threat detection, security monitoring and forensic solutions Outreach and security awareness training and education Endpoint security, such as encryption, anti-malware, endpoint detection and response
Qualifications:
REQUIRED QUALIFICATIONS - Bachelor’s degree in Computer Science, Information Security, Education, Communications, or a related field (or equivalent experience). - Minimum related experience, 5+ years - Communication: Able to translate complex security concepts into clear, concise messages for diverse audiences (students, faculty, clinicians, IT staff) - Security Expertise: Broad knowledge of information security principles, risk management and threat landscape. Familiarity with NIST or similar frameworks. Understanding of healthcare and research privacy requirements (HIPAA, FERPA) and how to incorporate them into training - Project Management: Strong organizational and planning skills. Experience managing projects from conception through implementation, including scheduling, resource coordination, and reporting - Collaboration: Proven ability to work cross-functionally with IT, legal/compliance, clinical, and academic stakeholders. Skilled at coordinating people and tasks across departments to achieve security goals. REQUIRED CERTIFICATIONS - Relevant professional certifications preferred (e.g. CISSP, CISM, Security+). Certification or coursework in security awareness, instructional design, or project management is desirable. PREFERRED QUALIFICATIONS - Training & Education: Proficiency with training design and delivery (e.g. adult learning, e-learning platforms, phishing simulation tools). Ability to evaluate training effectiveness and metrics (completion rates, assessment results). - Analytical Skills: Problem-solving mindset and attention to detail. Able to assess program outcomes, identify areas for improvement, and adapt strategies accordingly. Basic understanding of information risk concepts is required