Senior IT Security Analyst - Cybersecurity Operations
University of Virginia
IT, Operations
Charlottesville, VA, USA
USD 91,312-146,099.2 / year
Posted on Jul 10, 2025
The Senior IT Security Analyst – Cybersecurity Operations is a highly skilled and technically proficient member of the Cybersecurity Operations team within the University of Virginia Health System Health IT (HIT) organization. This role is critical in deploying, configuring, operating, troubleshooting, and evaluating the effectiveness of a wide array of cybersecurity controls and services. The ideal candidate will have deep technical expertise and a passion for defending complex environments against evolving cyber threats.
Key Responsibilities:
• Maintain cybersecurity technologies supporting cyber defense and Security Operations Center (SOC) functions.
• Lead and support cybersecurity incident response, threat hunting, and detection engineering efforts.
• Manage SIEM and SOAR platforms, including development of detection rules and automation playbooks.
• Conduct digital forensics and analyze cyber threat intelligence to inform proactive defense strategies.
• Implement and manage technologies that deliver UVA Health’s information protection and insider risk strategy including data loss prevention (DLP), UEBA, CASB, and email protection.
• Perform vulnerability and attack surface management and ensure risks are addressed in a timely manner.
• Endpoint security engineering to ensure appropriate OS hardening and security configuration of servers and workstations.
• Secure Medical IoT and mobile/BYOD devices through policy configuration and enforcement using technical controls and passive vulnerability assessment tools.
• Review and approve firewall changes, conduct firewall ruleset reviews, and manage network security configurations.
• Conduct and facilitate third party offensive security testing and security control validation as needed, including penetration testing, application security testing, and adversary simulation.
• Validate the effectiveness of security controls through continuous testing and measurement.
• Participate in purple team and blue team exercises to validate and enhance security posture.
• Collaborate with DevOps teams to integrate security into the software development lifecycle and CI/CD pipelines (DevSecOps).
• Monitor and manage web application firewalls
• Implement cloud security guardrails, security posture management, and security monitoring.
In addition to the minimum requirements the ideal candidate will have:
• Strong knowledge of cybersecurity frameworks, tools, and technologies across multiple domains.
• Experience with SIEM, SOAR, EDR, DLP, CASB, vulnerability management, and cloud security platforms.
• Proficiency in scripting and automation (e.g., Python, PowerShell).
• One or more certifications: CISSP, GIAC, OSCP, GCIA, GCIH.
Key Responsibilities:
• Maintain cybersecurity technologies supporting cyber defense and Security Operations Center (SOC) functions.
• Lead and support cybersecurity incident response, threat hunting, and detection engineering efforts.
• Manage SIEM and SOAR platforms, including development of detection rules and automation playbooks.
• Conduct digital forensics and analyze cyber threat intelligence to inform proactive defense strategies.
• Implement and manage technologies that deliver UVA Health’s information protection and insider risk strategy including data loss prevention (DLP), UEBA, CASB, and email protection.
• Perform vulnerability and attack surface management and ensure risks are addressed in a timely manner.
• Endpoint security engineering to ensure appropriate OS hardening and security configuration of servers and workstations.
• Secure Medical IoT and mobile/BYOD devices through policy configuration and enforcement using technical controls and passive vulnerability assessment tools.
• Review and approve firewall changes, conduct firewall ruleset reviews, and manage network security configurations.
• Conduct and facilitate third party offensive security testing and security control validation as needed, including penetration testing, application security testing, and adversary simulation.
• Validate the effectiveness of security controls through continuous testing and measurement.
• Participate in purple team and blue team exercises to validate and enhance security posture.
• Collaborate with DevOps teams to integrate security into the software development lifecycle and CI/CD pipelines (DevSecOps).
• Monitor and manage web application firewalls
• Implement cloud security guardrails, security posture management, and security monitoring.
In addition to the minimum requirements the ideal candidate will have:
• Strong knowledge of cybersecurity frameworks, tools, and technologies across multiple domains.
• Experience with SIEM, SOAR, EDR, DLP, CASB, vulnerability management, and cloud security platforms.
• Proficiency in scripting and automation (e.g., Python, PowerShell).
• One or more certifications: CISSP, GIAC, OSCP, GCIA, GCIH.
- Maintenance of data security tables and files used to manage for access controls and identity management systems.
- Assists with investigative process during computer security incident responses.
- Implements and maintains information security infrastructure.
- Collaborates with other HSCS teams to ensure Information Security Plan and Standards are implemented.
- Collaborates with other HSCS teams to ensure facility and physical security is implemented. Coordinates Information Security Awareness program and educational activities.
In addition to the above job responsibilities, other duties may be assigned.
MINIMUM REQUIREMENTS
Education: Bachelor’s degree
Experience: 5-7 years relevant experience. Relevant experience may be considered in lieu of a degree.
Licensure: CISSP or HCISPP or similar preferred.
PHYSICAL DEMANDS
This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend meetings, and programs.
The University of Virginia is an equal opportunity employer. All interested persons are encouraged to apply, including veterans and individuals with disabilities. Click here to read more about UVA’s commitment to non-discrimination and equal opportunity employment.