Systems and Application Security Analyst

2 weeks ago


Mansfield, United States University of Connecticut Full time

Search #: 498630
Work type: Full-time
Location: Storrs Campus
Categories: Information Technology
JOB SUMMARY
Under the direction of the Chief Information Security Officer, the Systems and Application Security Analyst (Information Security Analyst 2 or 3) is responsible for the development and operation of UConn's Application Security (AppSec) and Systems Assessment programs. The analyst develops policy recommendations, standards, risk assessments, scanning and monitoring mechanisms, and technical solutions to address secure code development, application security, and systems security at the university. This role will assess, develop, and maintain control standards designed to improve UConn's application security posture through periodic assessments and integration of industry best practices.
The Systems and Application Security Analyst is responsible for investigating a diverse range of technical issues across multiple platforms, working with a wide range of clients who have minimal to a broad range of technical skills. The Analyst works among a team of skilled technicians to address problems within a complex network environment and develops solutions that fit into that environment.
The Systems and Application Security Analyst is responsible for processes and procedures to ensure the continuous improvement of monitoring, detection, and mitigation capabilities specifically around software, systems, and databases. The Analyst plans, organizes and establishes priorities related to an assignment; works independently with minimal outside support; and handles sensitive information in a confidential manner.
DUTIES AND RESPONSIBILITIES FOR INFORMATION SECURITY ANALYST 2

  • Identify and document security controls during the requirements phase to integrate security within the software and systems development/deployment process.
  • Identify security implications and apply methodologies within centralized and decentralized environments across the University's computer systems.
  • Identify security issues in the operations and management of software and incorporate security measures that must be taken over the lifecycle of systems/software, including proactively identifying security considerations of decommissioning end of life systems and software.
  • Apply coding and testing standards and employ tools including static-analysis code scanning (SAST) and dynamic analysis security testing (DAST) to information systems and advise on improvements/issues regarding application vulnerabilities.
  • Translate security requirements into application design elements including documenting the elements of the software attack surfaces, conducting threat modeling, and defining specific security criteria.
  • Consult with peers across the institution about software system design, maintenance, and risk assessments.
  • Plan, implement, upgrade, and monitor security measures for the protection of data and information systems ensuring appropriate security controls are in place.
  • Develop secure software testing and validation procedures.
  • Perform penetration testing as required for new or updated applications and systems.
  • Identify security gaps, perform risk assessments, and recommend solutions to ensure best practices and security measures are being met.
  • Monitor security incident and event management (SIEM) and logging environments for security events and alerts for potential (or active) threats, intrusions, and/or compromises.
  • Document event analysis and author comprehensive reports of incident investigations.
  • Perform risk analysis (threat, vulnerability, and probability of occurrence) related to internal and vendor provided solutions. Perform vendor risk assessments and system security assessments.
  • Develops security metrics to proactively monitor cyber threats and provide trend data.
  • Assist with triage of service requests from customers and internal teams.
  • Integrate data for use between various applications.
  • Participate in and/or lead incident response activities, as required, for cyber security incidents.
  • Promote security awareness to improve and ensure system security.
  • Other related duties as assigned.
ADDITIONAL DUTIES AND RESPONSIBILITIES FOR INFORMATION SECURITY ANALYST 3 ONLY
  • Serves as domain and subject matter expert in one or more information security domains.
  • Design, implement, and maintain new information security solutions.
  • Lead major projects / initiatives related to information security and/or cybersecurity.
  • Integrate data for use between various applications and systems.
  • Identify enterprise level security gaps, perform risk assessments, and recommend solutions to ensure best practices and security measures are being met across and between enterprise level systems.
  • Create custom code, api/rest integrations, or other maintainable integrations to facilitate data gathering / sharing across applications and platforms.
  • Ability to operate autonomously and with limited supervision.
MINIMUM QUALIFICATIONS FOR INFORMATION SECURITY ANALYST 2 AND 3
Note: Applicants must meet all minimum requirements of a specific level to be considered for the position.
  • Must be a US Citizen.
  • Associates degree and four (4) years of related experience, OR Bachelor's degree and two (2) years of related experience, OR Six (6) years of related experience.
  • One (1) to three (3) years of experience working in an information security role or supporting an information security program.
  • Experience overseeing or materially contributing to projects designed to improve institutional security maturity, adherence to security policies, and/or regulatory compliance.
  • Significant experience administering an information security tool / platform, interpreting the systems output, and assisting others to leverage the capabilities of that platform.
  • Experience using a SAST, DAST and/or IAST application vulnerability platform (Invicti Netsparker, Acunetix, Burp Suite Enterprise, HCL AppScan, or similar).
  • Experience with web server configuration, SSL/TLS, certificate management and web application stack dependencies. Ability to troubleshoot and identify security related misconfigurations.
  • Experience developing and debugging code in at least one programming language. Knowledge and experience with secure coding practices.
  • Knowledge of current security regulatory requirements (HIPAA, CMMC 2.0, NIST 800-171, PCI-DSS, or similar).
  • Experience applying knowledge of application security risks (OWASP Top 10, MITRE, or similar).
  • Experience and competency in threat management and protection protocols.
  • Experience using common enterprise security tools and controls (e.g., Firewalls, IPS/IDS/NDR, Network Segmentation, Vulnerability Scanners, EDR, SIEM/SIM, IAM, MFA, and/or similar).
  • Experience weighing business needs against security concerns and making actionable recommendations.
  • Excellent communication skills and attention to detail.
  • Ability to operate under pressure and manage multiple priorities/deadlines.
ADDITIONAL MINIMUM QUALIFICATIONS FOR INFORMATION SECURITY ANALYST 3 ONLY
  • Associate's degree and six (6) years of related experience, OR Bachelor's degree and four (4) years of related experience, OR Eight (8) years of related experience.
  • More than (3) years of experience working in an information security role actively supporting secure software development.
  • Experience developing and debugging code in more than one programming language. Knowledge and experience with secure coding practices.
  • Experience leading complex projects involving multiple information security domains.
  • Senior level practical and technical information security experience.
PREFERRED QUALIFICATIONS FOR INFORMATION SECURITY ANALYST 2 AND 3
  • Relevant information security certification(s) in one or more applicable information security domains (CSSLP, GPEN, GWAPT, or similar).
  • Experience developing software in an enterprise environment.
  • Experience developing or implementing a secure software development lifecycle (SSDLC).
  • Experience developing and operationalizing an application security program in a complex enterprise environment.
  • Experience administering a SAST, DAST and/or IAST application vulnerability platform at an enterprise level (Invicti Netsparker, Acunetix, Burp Suite Enterprise, HCL AppScan, or similar).
  • Experience conducting penetration tests in the application security domain.
  • Experience in higher education.
  • Enterprise scale project management experience.
ADDITIONAL PREFERRED QUALIFICATIONS FOR INFORMATION SECURITY ANALYST 3 ONLY
  • Master's degree in information security, computer science, information management or a related discipline.
  • Experience leading software development in an enterprise environment.
  • CISSP certification or equivalent.
APPOINTMENT TERMS
This is a full-time, permanent position with opportunity for hybrid schedule. The University offers a competitive salary, and outstanding benefits, including employee and dependent tuition waivers at UConn, and a highly desirable work environment. For additional information regarding benefits visit: . Other rights, terms . click apply for full job details

  • Storrs Mansfield, CT, United States University of Connecticut Full time

    Search #: 498630Work type: Full-timeLocation: Storrs CampusCategories: Information Technology JOB SUMMARY Under the direction of the Chief Information Security Officer, the Systems and Application Security Analyst (Information Security Analyst 2 or 3) is responsible for the development and operation of UConn's Application Security (AppSec) and Systems...


  • Mansfield, Ohio, United States InsideHigherEd Full time

    About the RoleWe are seeking a highly skilled Information Security Analyst to join our team at InsideHigherEd. As a key member of our cybersecurity team, you will be responsible for developing and implementing security policies, procedures, and controls to protect our systems and data from cyber threats.Key ResponsibilitiesDevelop and Implement Security...

  • Fire Alarm

    3 months ago


    Mansfield, United States Summit Fire & Security Full time

    Job DescriptionJob DescriptionAre you interested in working for the nation’s leading fire protection company and beginning a rewarding and satisfying career that helps save the lives of thousands each year? Do you want to be a part of a growing and expanding team of industry experts? If so, exploring career opportunities with Summit Fire & Security may be...


  • Mansfield, Ohio, United States KOORSEN FIRE & SECURITY INC. Full time

    Job SummaryWe are seeking an experienced Fire Alarm Technician to join our team at Koorsen Fire & Security Inc. as a key member of our fire and security team.Key ResponsibilitiesSystem Maintenance: Perform routine maintenance and repairs on Fire Alarm systems and their components to ensure optimal functionality.System Troubleshooting: Troubleshoot systems to...


  • Mansfield, Texas, United States Summit Fire & Security Full time

    Job SummaryWe are seeking a highly skilled Fire Sprinkler System Specialist to join our team at Summit Fire & Security. As a Fire Sprinkler System Specialist, you will be responsible for designing, installing, and maintaining fire sprinkler systems to ensure the safety of our customers and their properties.Key ResponsibilitiesDesign and install fire...


  • Mansfield, Ohio, United States Samsonite Full time

    About the RoleWe are seeking a highly skilled and experienced Senior Systems Analyst to join our dynamic team at Samsonite. As a key member of our SAP MM WM team, you will be responsible for providing ongoing support, implementing, customizing, and optimizing SAP Materials Management, Warehouse Management, and Logistics processes and projects.Key...

  • Sr. Systems Analyst

    2 months ago


    Mansfield, United States Samsonite Full time

    Job Description We are seeking a results-driven Senior Systems Analyst - SAP MM WM to join our dynamic team. This role is responsible for ongoing support as well as implementing, customizing, and optimizing SAP Materials Management, Warehouse Management and Logistics processes and projects. As a Senior Systems Analyst, you will collaborate with clients,...

  • Sr. Systems Analyst

    3 weeks ago


    Mansfield, United States Samsonite Full time

    Who we are: Samsonite is the worldwide leader in superior travel bags, luggage, and accessories combining notable style with the latest design technology and the utmost attention to quality and durability. For more than 100 years, Samsonite has leveraged its rich heritage to create unparalleled products that fulfill the travel lifestyle needs of conscious...


  • Mansfield, Texas, United States Fusion Dynamics Full time

    About the Role:Fusion Dynamics is seeking a highly motivated and skilled IT System and Application Administrator to join our team. As an IT System and Application Administrator, you will be responsible for providing on-site support for IT workstations, installing and maintaining PC hardware, and troubleshooting software and hardware issues.Key...

  • Financial Analyst

    4 weeks ago


    Mansfield, United States Stoneridge Full time

    Since 1965, Stoneridge has designed and manufactured advanced, award-winning technologies including driveline and transmission actuation systems, vision systems, emissions control systems, safety systems, and security and monitoring systems for vehicle OEMs in the commercial vehicle, automotive, off-highway and agricultural vehicle markets. We're focused on...


  • Mansfield, United States Summit Fire & Security Full time

    Job DescriptionJob DescriptionAre you interested in working for the nation’s leading fire protection company and beginning a rewarding and satisfying career that helps save the lives of thousands each year? Do you want to be a part of a growing and expanding team of industry experts? If so, exploring career opportunities with Summit Fire & Security may be...


  • Mansfield, United States Summit Fire & Security Full time

    Job DescriptionJob DescriptionAre you interested in working for the nation’s leading fire protection company and beginning a rewarding and satisfying career that helps save the lives of thousands each year? Do you want to be a part of a growing and expanding team of industry experts? If so, exploring career opportunities with Summit Fire & Security may be...


  • Mansfield, Texas, United States Summit Fire & Security Full time

    Job SummaryThe Fire Suppression Technician is a critical role within Summit Fire & Security, responsible for providing installation, inspection, service, and repair of Fire Extinguishers and Pre-Engineered Suppression Systems, as well as Fire Alarm & Security systems with minimal supervision.Key ResponsibilitiesInstallation and Maintenance: Use required...


  • Mansfield, Texas, United States Summit Fire & Security Full time

    Job SummaryThe Fire Suppression Technician is a critical role within Summit Fire & Security, responsible for providing installation, inspection, service, and repair of Fire Extinguishers and Pre-Engineered Suppression Systems, as well as Fire Alarm & Security systems with minimal supervision.Key ResponsibilitiesInstallation and Maintenance: Use required...


  • Mansfield, United States Starr Insurance Companies Full time

    Starr Insurance Companies is a leading insurance and investment organization, providing commercial property and casualty insurance, including travel and accident coverage, to almost every imaginable business and industry in virtually every part of the world. Cornelius Vander Starr established his first insurance company in Shanghai, China in 1919. Today, we...


  • Mansfield, United States Stoneridge Full time

    Since 1965, Stoneridge has designed and manufactured advanced, award-winning technologies including driveline and transmission actuation systems, vision systems, emissions control systems, safety systems, and security and monitoring systems for vehicle OEMs in the commercial vehicle, automotive, off-highway and agricultural vehicle markets. We're focused on...

  • Financial Analyst

    3 months ago


    Mansfield, United States NexDine Full time

    Job DescriptionJob DescriptionAre you passionate about creating amazing experiences in the hospitality industry? Then consider NEXDINE Hospitality for an amazing hospitality journey! We deliver trusted dining, hospitality, fitness center, and facility management services nationwide. Experience the NEXDINE difference with authentic and transparent programs....

  • Financial Analyst

    3 months ago


    Mansfield, United States NexDine Full time

    Job DescriptionJob DescriptionAre you passionate about creating amazing experiences in the hospitality industry? Then consider NEXDINE Hospitality for an amazing hospitality journey! We deliver trusted dining, hospitality, fitness center, and facility management services nationwide. Experience the NEXDINE difference with authentic and transparent programs....


  • Mansfield, United States Summit Fire & Security Full time

    Are you interested in working for the nation's leading fire protection company and beginning a rewarding and satisfying career that helps save the lives of thousands each year? Do you want to be a part of a growing and expanding team of industry experts? If so, exploring career opportunities with Summit Fire & Security may be right for you! We are...


  • Mansfield, United States Summit Fire & Security Full time

    Job DescriptionJob DescriptionAre you interested in working for the nation’s leading fire protection company and beginning a rewarding and satisfying career that helps save the lives of thousands each year? Do you want to be a part of a growing and expanding team of industry experts? If so, exploring career opportunities with Summit Fire & Security may be...