Logo for Southern New Hampshire University

Information Security Analyst III

Role overview

Qualifications

  • 5+ Years of relevant or specific experience in cybersecurity
  • 4+ years working in a security operations center (SOC) or on a cybersecurity incident response team, with at least one year in a mid to senior level capacity
  • Bachelor's degree in cybersecurity, information technology, data analytics, information assurance, computer science, or related field
  • Professional Certification(s): ISC2 CISSP; ISACA CISM or CISA; CompTIA CySA+, Security+, Network+, Microsoft AZ-900, SC-100, SC-200; SANS GIAC certifications such as GSEC, GCIH, GSOC; and EC Council CEH, CPENT, CIH

Responsibilities

  • Act as the senior escalation point for security alerts and incidents triaged by level I and II analysts
  • Develop SIEM alerts, reports, and dashboard content to enhance detection coverage
  • Serve as the Security Operations technical lead for ITS and enterprise-wide projects
  • Enforce vulnerability remediation compliance standards

Key facts

Hard skills

Other skills

  • Communication
  • Teamwork
  • Problem Solving
  • Detail Oriented

About the company

Southern New Hampshire University logo

Southern New Hampshire University

Education Administration

At SNHU, we believe education is a basic human right and that we must serve learners for whom college is not a guarantee. Since 1932, we’ve been relentlessly reinventing higher education—working to ensure everyone has access to quality education and the support they need to see themselves succeed.

Company details

IndustryEducation Administration
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Southern New Hampshire University is a team of innovators. World changers. Individuals who believe in progress with purpose. Since 1932, our people-centered strategy has defined us — and helped us grow a team that now serves over 180,000 learners worldwide.

Our mission to transform lives is made possible by talented people who bring diverse industry experience, backgrounds and skills to the university. And today, we're ready to expand our reach. All we need is you.

Make an impact — from near or far

At SNHU, you'll have the option to work remotely in the following states: Alabama, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Mississippi, Missouri, Nebraska, New Hampshire, New Mexico, North Carolina, North Dakota, Ohio, Oklahoma, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, West Virginia, Wisconsin and Wyoming.

We ask that our remote employees have access to a reliable internet connection and a dedicated, properly equipped workspace that is free of distractions. Employees must reside in, and work from, one of the above approved states.

The opportunity

The Information Security Analyst III is the senior lead for the Security Operations Center (SOC) team and is responsible for monitoring a large, complex enterprise technology ecosystem, detecting, analyzing, and investigating information security events within that ecosystem, and responding to information security incidents to ensure the protection of SNHU's mission critical technology resources and institutional information.

The critical duties and responsibilities of the SOC team must continue to be performed during crisis situations and contingency operations, which may necessitate extended hours of work, and/or require work during non-business hours.

You will work 100% remotely from any of our approved states. #LI-Remote

What You'll Do:

  • Incident Response
  • Act as the senior escalation point for security alerts and incidents triaged by level I and II analysts.
  • Act as Incident Coordinator in alignment with SNHU's Information Security Incident Response Plan.
  • Act as technical lead for investigation of complex or high severity security threats or incidents.
  • Lead, define, and authorize incident containment and eradication activities like endpoint isolation, malware remediation, forensic analysis, malware analysis, community member interviews, and network traffic analysis.
  • Understand the incident response lifecycle and possess the analytical mindset needed when it comes to escalated investigations and investigation into novel security incidents.
  • Work cross-functionally across ITS and all SNHU business units to provide support, guidance, and technical implementations where appropriate, to include triage, containment, and remediation when applicable.
  • Analyze digital evidence to identify indicators of compromise, adversary activity, root cause, incident timelines, and attack vector(s).
  • Remain calm and function at the highest level during a crisis.
  • Detection Engineering
  • Develop SIEM alerts, reports, and dashboard content to enhance detection coverage and increase the efficiency and effectiveness of level I and II analysts.
  • Partner with other ITS and business partners to develop and maintain monitoring content relevant to their use cases related to academic integrity investigations, financial aid fraud, and system/network administration.
  • Analyze, implement, and approve tuning of alert content and security tools.
  • Remain up to date on emerging threat intelligence.
  • Security Operations Engineering
  • Serves as the Security Operations technical lead for ITS and enterprise-wide projects
  • Develop strategies and solutions that remediate or mitigate the risks associated with threats identified during the incident response process and other programs such as vulnerability management, threat intelligence, and risk management.
  • Identify, prioritize, and onboard log data pertinent for monitoring SNHU's complex, virtualized, multi-site computing environment and expansive technology ecosystem.
  • Develop and implement logging baselines for operating systems, software applications, network infrastructure, cloud-based resources, security tools, and other technology resources.
  • Develop and implement data pipelines for log data, ensuring compliance with log retention requirements while increasing SIEM efficiency.
  • Implement, configure, deploy, and manage security operations tools (e.g. Splunk, Cribl, Halcyon, Microsoft Defender XDR, Tenable).
  • Develop and maintain automation scripts and other tools to enhance security operations efficiency and effectiveness.
  • Vulnerability and Risk Management
  • Enforce vulnerability remediation compliance standards
  • Review and process false positive detections reported by remediation owners
  • Perform risk analyses on software vulnerabilities and prioritize vulnerability remediation efforts
  • Provide technical vulnerability remediation assistance to resource owners
  • Generate and provide regular reporting to management on key Security Operations metrics related to incident response, continuous monitoring, and vulnerability management.
  • Excel at documentation and detailed notetaking, including SOP writing, incident reporting, e-mail and instant messaging etiquette, and most importantly, documenting incident actions appropriately.
  • Communicate with stakeholders, in a non-technical manner, at all organizational levels as part of incident response and remediation activities.
  • Provide customer support in alignment with SNHU's Core Values and understand how and when to appropriately escalate potential issues.

Other duties and responsibilities as assigned. Job duties and responsibilities can change at any time, with or without notice.

What We're Looking For:

  • 5+ Years of relevant or specific experience: in cybersecurity

4 + years working in a security operations center (SOC), a cybersecurity operations center or on a cybersecurity incident response team, and a minimum one year working in a mid to senior level in this capacity.

  • Academic Degree(s) and/ areas of study: Bachelor's degree in cybersecurity, information technology, data analytics, information assurance, computer science, or related field.

Equivalent of experience in lieu of degree acceptable

  • Professional Certification(s): ISC2 CISSP; ISACA CISM or CISA; CompTIA CySA+, Security+, Network+, Microsoft AZ-900, SC-100, SC-200; SANS GIAC certifications such as GSEC, GCIH, and GSOC; and EC Council CEH, CPENT, and CIH.
  • Experience collecting, organizing, and analyzing data gathered from firewalls, vulnerability scanners, Windows/Linux operating systems, software application logs, Azure cloud-resources, email platforms, Endpoint Detection and Response (EDR) tools, and other platforms in the environment that enable enterprise-wide security monitoring.
  • Experience implementing, writing, deploying, and maintaining scripts used for security operations automation.

We believe real innovation comes from inclusion - where different experiences, perspectives and talents are celebrated. So if you're wondering whether SNHU is right for you, take the leap and apply. You might be just the person we're looking for.


If you have a disability and require a reasonable accommodation to fully engage in any part of the application or hiring process, please complete the Accommodation Request form or contact us at 603-626-9447. A member from the Employee Accommodation Support Center will be in contact with you within two business days to discuss your request.


Compensation


The annual pay range for this position is $106,684.00 - $170,727.00. Actual offer will be based on skills, qualifications, experience and internal equity, in addition to relevant business considerations. We expect this position to be hired in the following target hiring range $117,887.00 - $159,493.00.

Exceptional benefits (because you’re exceptional)

You’re the whole package. Your benefits should be, too. As a full-time employee at SNHU, you’ll get:

  • High-quality, low-deductible medical insurance

  • Low to no-cost dental and vision plans

  • 5 weeks of paid time off (plus almost a dozen paid holidays)

  • Employer-funded retirement

  • Free tuition program

  • Parental leave

  • Mental health and wellbeing resources

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Information Security Analyst Related jobs

Other jobs at Southern New Hampshire University

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.