Information Security Analyst
Locations:: Binghamton, NY
Posted:: Jul 5, 2019
Closes:: Open Until Filled
Ref. No.:: 05021
About Binghamton University:
Binghamton University is a world-class institution that unites more than 130 broadly interdisciplinary educational programs with some of the most vibrant research in the nation. Our unique character - shaped by outstanding academics, facilities and community life - promotes extraordinary student success.
Binghamton merges rigorous academics, distinguished faculty and state-of-the-art facilities to engage and challenge its 17,000 students. The high-achieving Binghamton student body also represents a great diversity of life experiences, from first-generation college-goers to international students. Beyond their talent, these classmates share a desire to shape the future through technology, insight, intellectual exploration and community service.
Budget Title: Lead Programmer/Analyst (SL-3)
Salary: Commensurate with experience
The Information Security Analyst will be responsible for assisting the Chief Information Security Officer/Director of Information Security in developing and maintaining Binghamton University information security capabilities, implementing security controls, responding to information security incidents, and the monitoring of administrative, academic systems and networks for policy enforcement and compliance. The Information Security Analyst will work with cross-functional teams to design and implement security initiatives; serve as a resource person on specific information security technologies and technology-related compliance requirements.
The Information Security Analyst reports to the Chief Information Security Officer/Director of Information Security and works closely with Information Technology Services (ITS) leadership to build awareness and implementation of security controls, within the department and across the University.
In addition, the information security analyst will:
- Maintain and develop information security software tools (unix/linux, python, php, and sql-based)
- Recommend remediation strategies and technologies for mitigating risks
- Evaluate current and future requirements and develop or recommend technical and operational solutions accordingly
- Support and manage risk mitigation tools as needed
- Develop specifications and standards for equipment, software, and procedures in support of University policies
- Investigate internal and external reports of information security issues
- Assist in analyzing results from intrusion detection systems, intrusion prevention systems, network mapping software, log analysis, and other tools to detect, respond to, and mitigate information security related vulnerabilities and incidents
- Maintain audit and oversight of processes, procedures, and tools used to ensure security controls
- Maintain metrics and prepare reports
- Perform trend and root cause analysis
- Liaison with various University constituencies on behalf of the CISO as needed
- Serves as a resource person in assessing systems, processes, and projects against compliance requirements, control objectives, and security best practices; interacts with internal and external technical staff and consults with project teams at various stages of project cycles
- Must be able to maintain data confidentiality and compliance with regulatory requirements (HIPAA, FERPA, PCI, etc.).
- Bachelor's Degree and two years of relevant experience or an Associate's Degree in Computer Science, Information Systems/Sciences, or related field with IT industry security certifications (i.e. CISSP, GIAC [GCFA, GCIH, GCED, GCWN, and/or GNFA], NIST Cybersecurity Framework [Foundation or Practitioner]) and at least five years of relevant experience (for example, information security analyst, Linux/Unix desktop or server support function, or Windows desktop or server support function)
- Demonstrated strong written and oral communications skills
- Ability to work with multiple constituencies within a culturally diverse environment
- Experience working with programming or scripting languages (e.g., python, php, ruby, bash)
- Practical experience with one or more relational database packages
- A demonstrated understanding of network topologies, architectures, protocols, and addressing schemes
- Knowledge of and a demonstrated ability to operate Unix and Windows-based security tools (e.g., nmap, Snort, group policy)
- Experience in a university-based or a research technology environment
- Experience in working in a large complex organization
- Network management experience is desirable
- The candidate demonstrates competence in the area of information security. This can be in the form of professional certificates or specific work experiences. These experiences should be detailed in a cover letter
Offers of employment may be contingent upon successful completion of a pre-employment background check and verification of degree(s) and credentials.
Binghamton University is a tobacco-free campus.
Pursuant to Executive Order 161, no State entity, as defined by the Executive Order, is permitted to ask, or mandate, in any form, that an applicant for employment provide his or her current compensation, or any prior compensation history, until such time as the applicant is extended a conditional offer of employment with compensation. If such information has been requested from you before such time, please contact the Governor's Office of Employee Relations at (518) 474-6988 or via email at [email protected]
Payroll information can be found on our website http://www.binghamton.edu/human-resources/payroll/
Cover letters may be addressed "To the Search Committee."
Postings active on the website accept applications until closure.
For information on the Dual Career Program, please visit:
Equal Opportunity/Affirmative Action Employer
The State University of New York is an Equal Opportunity/Affirmative Action Employer. It is the policy of Binghamton University to provide for and promote equal opportunity employment, compensation, and other terms and conditions of employment without discrimination on the basis of age, race, color, religion, disability, national origin, gender identity or expression, sexual orientation, veteran or military service member status, marital status, domestic violence victim status, genetic predisposition or carrier status, or arrest and/or criminal conviction record unless based upon a bona fide occupational qualification or other exception.
As required by Title IX and its implementing regulations Binghamton University does not discriminate on the basis of sex in the educational programs and activities which it operates. This requirement extends to employment and admission. Inquiries about sex discrimination may be directed to the University Title IX Coordinator or directly to the Office of Civil Rights (OCR). Contact information for the Title IX Coordinator and OCR, as well as the University's complete Non-Discrimination Notice may be found here.
Deadline for Internal Applicants: July 19, 2019
Deadline for External Applicants: Open until filled
Review of applications will begin immediately and continue until the vacancy is filled.
Persons interested in this position should apply online.
- Cover letter, and
- Contact information for three professional references
You may add additional files/documents after uploading your resume. After you fill out your contact information, you will be directed to the upload page. Please login to check/edit your profile or to upload additional documents: http://binghamton.interviewexchange.com/login.jsp.