Information Security Analyst/Engineer
Job Description
The University at Albany is seeking an Information Security Analyst/Engineer to help protect critical infrastructure, institutional data, and research assets. This hybrid role supports end-to-end incident response and security engineering activities, working closely with a senior team and the Chief Information Security Officer (CISO) to strengthen detection, response, and preventive controls.
Key responsibilities
- Monitor and triage security alerts across endpoints, identity, and cloud workloads using tools such as Microsoft Defender and Microsoft Sentinel.
- Investigate and respond to incidents end-to-end, including scope, contain, eradicate, and recover; document actions and escalate when needed.
- Build and improve incident response workflows, including cloud automation playbooks using SOAR, along with scripts that reduce time-to-detect and time-to-respond.
- Partner with network, systems, and application teams to contain threats, remediate root causes, and improve detections and preventive controls.
- Design, review, and maintain next-generation firewall policies and exceptions (Palo Alto) and web application protections (Cloudflare), including change control and documentation.
- Analyze network telemetry for anomalies, creating detections and workflows that correlate network, endpoint, identity, and cloud signals.
- Conduct regular vulnerability scans using Tenable (and similar tools).
- Automate vulnerability tracking and reporting, and coordinate remediation with system owners and technical teams.
- Support risk assessments, audits, and policy updates.
- Promote security awareness and best practices across campus.
- Develop and maintain scripts and automation workflows supporting incident response and network security.
- Integrate security tools and data sources (firewall, cloud, and EDR) to improve correlation and response automation.
- Evaluate emerging capabilities to enhance detection, response, and network controls, prioritizing solutions that can be operationalized and automated.
- Perform other reasonable duties as assigned.
Required qualifications
- Excellent communication skills and the ability to work effectively with infrastructure teams in a fast-paced environment while balancing security, availability, and operational needs.
- Strong troubleshooting and organizational skills, including the ability to prioritize work and independently solve complex problems.
- Demonstrated ability to develop inclusive and equitable relationships within a diverse campus community, and to support diversity, equity, access, inclusion, and belonging relative to the role.
- Bachelor’s degree from a college or university accredited by a U.S. Department of Education (DOE) institution or an internationally recognized accrediting organization.
- At least 3 years of professional experience in modern incident response, including investigation, containment, remediation, and use of enterprise security tooling such as Microsoft Defender, Microsoft Sentinel, or comparable platforms.
- At least 3 years of professional experience in network security, including hands-on work with technologies and practices such as next-generation firewalls, IDS/IPS, segmentation, traffic analysis, or related controls.
- Demonstrated experience collaborating with infrastructure, systems, or application teams to implement security controls, support remediation efforts, or improve operational processes in an enterprise environment.
- Experience using scripting (such as Python or PowerShell), Artificial Intelligence, automation, or security workflows to improve detection, response, or efficiency.
Technologies
- Microsoft Defender, Microsoft Sentinel
- Palo Alto
- Cloudflare
- SOAR (security orchestration, automation, and response)
- Tenable
- Python, PowerShell
- Artificial Intelligence
- EDR (endpoint detection and response)
- SIEM, XDR
- Microsoft Azure, Amazon Web Services (AWS), Google Cloud
- Burp Suite, OWASP
Reporting and supervision
- Reports to: Chief Information Security Officer
- May supervise employees as assigned
Preferred qualifications
- Relevant security certifications (examples include CISSP, CEH, or GCDA).
- Experience securing cloud and web application environments, including platforms and tools such as Microsoft Azure, AWS, Google Cloud, Cloudflare, Burp Suite, or OWASP-based practices.
- Experience with enterprise detection and response platforms, such as SIEM, XDR, or AI-assisted security operations tools.
- Experience working in higher education or similarly complex environments, including support for institutional AI use, risk management, or compliance initiatives.
Working environment
- Available for scheduled after-hours support, including occasional evenings, weekends, or holidays.
- On-site in Albany Mondays, Wednesdays, and Fridays (and as needed). Telecommuting on Tuesdays and Thursdays may be available after a probationary period with supervisor approval.
Compensation, rank, and location
- Location: Albany, NY (hybrid)
- Salary: USD 90,000 to 95,000 per year
- Professional rank and salary grade: Senior Programmer/Analyst, SL4, $90,000 to 95,000
Additional information
- Promotional opportunity for current UAlbany employees.
- Visa sponsorship is not available for this position.
- UAlbany is not an E-Verify employer.
Eligibility for consideration
- Must be employed at the University at Albany campus.
- Must be in a State-funded UUP professional position (MC employees are not eligible).
- Must have a permanent, term, or probationary appointment. Only temporary employees employed by UAlbany for three or more consecutive years can be considered eligible.