Position Summary
The IT Security Specialist will be responsible for triaging and responding to various IT security incidents to include log analysis, forensic analysis, interviewing, and reporting utilizing industry standard practices. This position is also required to conduct IT security assessments and audits for the UNC School of Medicine. This will involve assessing information systems security to ensure all school policies and regulatory compliance requirements are met, providing guidance and risk mitigation strategies, and communicating risk assessment findings. Information security operations responsibilities include troubleshooting and resolving information security related incident handling and response, researching and evaluating new and updated security technologies, and providing security consultation services to clients and staff. Flexible work arrangements, including remote/hybrid work locations, are an integral part of the School of Medicineβs Working Forward initiative. As such, this positionβs work location is designated as hybrid. Please note that the designated work location is subject to change based on the unitβs business needs.
Required Qualifications, Competencies, And Experience
Demonstrated information security experience in various areas such as - governance/risk/compliance - digital forensics/incident response - information security operations - information security awareness * Excellent communication skills * Excellent interpersonal skills and proven ability to establish and maintain positive working relationships with colleagues and customers * Strong organizational skills, time management and reliability
Preferred Qualifications, Competencies, And Experience
* Three to four years of progressive experience in the field of Information Technology Security * Information security experience in a higher education, medical campus, and/or healthcare setting. * Information security training and/or certification (i.e. CISSP , CISM , vendor-specific certifications). - Experience in information security, IT risk management, IT auditing or related field - Experience with incident handling, forensic analysis and tools, incident response industry standard methods - Experience with SIEM tools - Experience with Endpoint Detection and Response ( EDR ), device encryption, and Anti-virus tools (AV) - Experience within a Security Operations Center ( SOC ) - Experience with vulnerability management systems and programs