Senior IT Security Analyst - Cybersecurity Operations
![]() | |
![]() | |
![]() | |
![]() United States, Virginia, Charlottesville | |
![]() 1215 Lee Street (Show on map) | |
![]() | |
The Senior IT Security Analyst - Cybersecurity Operations is a highly skilled and technically proficient member of the Cybersecurity Operations team within the University of Virginia Health System Health IT (HIT) organization. This role is critical in deploying, configuring, operating, troubleshooting, and evaluating the effectiveness of a wide array of cybersecurity controls and services. The ideal candidate will have deep technical expertise and a passion for defending complex environments against evolving cyber threats.
Key Responsibilities: *Maintain cybersecurity technologies supporting cyber defense and Security Operations Center (SOC) functions. *Lead and support cybersecurity incident response, threat hunting, and detection engineering efforts. *Manage SIEM and SOAR platforms, including development of detection rules and automation playbooks. * Conduct digital forensics and analyze cyber threat intelligence to inform proactive defense strategies. *Implement and manage technologies that deliver UVA Health's information protection and insider risk strategy including data loss prevention (DLP), UEBA, CASB, and email protection. *Perform vulnerability and attack surface management and ensure risks are addressed in a timely manner. *Endpoint security engineering to ensure appropriate OS hardening and security configuration of servers and workstations. *Secure Medical IoT and mobile/BYOD devices through policy configuration and enforcement using technical controls and passive vulnerability assessment tools. *Review and approve firewall changes, conduct firewall ruleset reviews, and manage network security configurations. *Conduct and facilitate third party offensive security testing and security control validation as needed, including penetration testing, application security testing, and adversary simulation. *Validate the effectiveness of security controls through continuous testing and measurement. *Participate in purple team and blue team exercises to validate and enhance security posture. *Collaborate with DevOps teams to integrate security into the software development lifecycle and CI/CD pipelines (DevSecOps). *Monitor and manage web application firewalls *Implement cloud security guardrails, security posture management, and security monitoring. In addition to the minimum requirements the ideal candidate will have: *Strong knowledge of cybersecurity frameworks, tools, and technologies across multiple domains. *Experience with SIEM, SOAR, EDR, DLP, CASB, vulnerability management, and cloud security platforms. *Proficiency in scripting and automation (e.g., Python, PowerShell). *One or more certifications: CISSP, GIAC, OSCP, GCIA, GCIH.
MINIMUM REQUIREMENTS Benefits
UVA Health is a world-class Magnet Recognized academic medical center and health system with a level 1 trauma center. 2023-2024 U.S. News & World Report "Best Hospitals" guide rates UVA Health University Medical Center as "High Performing" in 5 adult specialties and 14 conditions/procedures. We are one of 70 National Cancer Institute designated cancer centers. UVA Health Children's is named by 2023-2024 U.S. News & World Report as the best children's hospital in Virginia with 9 specialties ranked among the best in the nation. Our footprint also encompasses 3 community hospitals and an integrated network of primary and specialty care clinics throughout Charlottesville, Culpeper, Northern Virginia, and beyond. |