{"21427573":{"jobPath":"/jobs/21427573/cybersecurity-engineer-it-security-specialist-3-provisional","source":"naylor","job":"21427573","jobTitle":"Cybersecurity Engineer (IT Security Specialist 3) - Provisional"},"21427571":{"jobPath":"/jobs/21427571/senior-virtualization-it-architect-it-architect-3-provisional","source":"naylor","job":"21427571","jobTitle":"Senior Virtualization IT Architect (IT Architect 3) - Provisional"},"21424462":{"jobPath":"/jobs/21424462/senior-network-services-engineer-it-infrastructure-engineer-3-provisional","source":"naylor","job":"21424462","jobTitle":"Senior Network Services Engineer (IT Infrastructure Engineer 3) - Provisional"},"21429776":{"jobPath":"/jobs/21429776/enterprise-applications-security-business-analyst","source":"naylor","job":"21429776","jobTitle":"Enterprise Applications Security Business Analyst"},"21441641":{"jobPath":"/jobs/21441641/merit-soc-analyst","source":"naylor","job":"21441641","jobTitle":"Merit SOC Analyst"},"21440772":{"jobPath":"/jobs/21440772/senior-risk-analyst","source":"naylor","job":"21440772","jobTitle":"Senior Risk Analyst"},"21427574":{"jobPath":"/jobs/21427574/linux-system-administrator-it-sr-associate-3-temporary","source":"naylor","job":"21427574","jobTitle":"Linux System Administrator (IT Sr Associate 3) - Temporary"},"21429972":{"jobPath":"/jobs/21429972/analyst-programmer-analyst-programmer-career-information-technology-service-digital-transformation","source":"naylor","job":"21429972","jobTitle":"Analyst/Programmer (Analyst/Programmer - Career), Information Technology Service, Digital Transformation"},"21427833":{"jobPath":"/jobs/21427833/information-security-compliance-analyst-iii-526822","source":"naylor","job":"21427833","jobTitle":"Information Security Compliance Analyst III - 526822"},"21442531":{"jobPath":"/jobs/21442531/senior-research-analyst-center-for-security-and-emerging-technology-walsh-school-of-foreign-service-georgetown-university","source":"naylor","job":"21442531","jobTitle":"Senior Research Analyst - Center for Security and Emerging Technology - Walsh School of Foreign Service - Georgetown University"},"21429932":{"jobPath":"/jobs/21429932/security-incident-response-analyst","source":"naylor","job":"21429932","jobTitle":"Security Incident Response Analyst"},"21442530":{"jobPath":"/jobs/21442530/senior-research-analyst-center-for-security-and-emerging-technology-walsh-school-of-foreign-service-georgetown-university","source":"naylor","job":"21442530","jobTitle":"Senior Research Analyst - Center for Security and Emerging Technology - Walsh School of Foreign Service - Georgetown University"},"21436173":{"jobPath":"/jobs/21436173/manager-cybersecurity-operations","source":"naylor","job":"21436173","jobTitle":"Manager, Cybersecurity Operations"},"21426849":{"jobPath":"/jobs/21426849/global-data-management-and-governance-director-advisory","source":"naylor","job":"21426849","jobTitle":"Global Data Management and Governance Director - Advisory"},"21438056":{"jobPath":"/jobs/21438056/it-support-manager","source":"naylor","job":"21438056","jobTitle":"IT Support Manager"},"21438039":{"jobPath":"/jobs/21438039/it-implementations-communcations-analyst-3","source":"naylor","job":"21438039","jobTitle":"IT Implementations Communcations Analyst 3"},"21442609":{"jobPath":"/jobs/21442609/security-analyst","source":"naylor","job":"21442609","jobTitle":"Security Analyst"},"21433881":{"jobPath":"/jobs/21433881/devsecops-engineer-it-infrastructure-engineer-3-provisional","source":"naylor","job":"21433881","jobTitle":"DevSecOps Engineer (IT Infrastructure Engineer 3) - Provisional"},"21433265":{"jobPath":"/jobs/21433265/data-governance-manager","source":"naylor","job":"21433265","jobTitle":"Data Governance Manager"},"21440808":{"jobPath":"/jobs/21440808/security-operations-center-soc-analyst","source":"naylor","job":"21440808","jobTitle":"Security Operations Center (SOC) Analyst"},"21424590":{"jobPath":"/jobs/21424590/it-hosting-facilities-analyst","source":"naylor","job":"21424590","jobTitle":"IT Hosting Facilities Analyst"},"21442529":{"jobPath":"/jobs/21442529/senior-data-research-analyst-center-for-security-and-emerging-technology-cset-walsh-school-of-foreign-service-sfs-georgetown-university","source":"naylor","job":"21442529","jobTitle":"Senior Data Research Analyst - Center for Security and Emerging Technology (CSET), Walsh School of Foreign Service (SFS) - Georgetown University"},"21427547":{"jobPath":"/jobs/21427547/information-technology-spec-1-information-technology-support-analyst","source":"naylor","job":"21427547","jobTitle":"Information Technology Spec 1 - Information Technology Support Analyst"},"21442521":{"jobPath":"/jobs/21442521/senior-research-analyst-center-for-security-and-emerging-technology-cset-walsh-school-of-foreign-service-sfs-georgetown-university","source":"naylor","job":"21442521","jobTitle":"Senior Research Analyst, Center for Security and Emerging Technology (CSET), Walsh School of Foreign Service (SFS) - Georgetown University"},"21442522":{"jobPath":"/jobs/21442522/senior-research-analyst-center-for-security-and-emerging-technology-walsh-school-of-foreign-service-georgetown-university","source":"naylor","job":"21442522","jobTitle":"Senior Research Analyst - Center for Security and Emerging Technology - Walsh School of Foreign Service - Georgetown University"}}
Are you passionate about cybersecurity and eager to make a tangible impact in protecting vital networks? Join Merit Network, Inc. as a Merit SOC Analyst and play a critical role in safeguarding our member institutions.
Merit Network, Inc. is a nonprofit, member-owned organization providing high-performance networking and services to educational, government, and nonprofit communities. Our mission is to foster innovation and collaboration by providing secure, high-quality network services, and we are seeking a driven SOC Analyst to be part of this effort.
As a Merit SOC analyst, you will be responsible for performing the operations of the Merit Security Operations Center (Merit SOC), a component of the Merit Support Center (MSC). Reporting to the Chief Information Security Officer, you will be analyzing and responding to directed incoming threats and alerts against our members, as well as staying informed on general cybersecurity news, information, and trends. You will work with various internal and external teams to analyze current and applicable security threats, assist with threat hunting and proactive cybersecurity functions, and document remediation plans of discovered weaknesses. Additionally, you will be responsible for recommending information security related tools for overall SOC operations and utilizing automation to streamline processes and improve response times to threats.
Have questions about the role or want to learn more before applying? Join our informal, open-forum Zoom sessions to connect with the hiring team! Drop in at any time during the hour and stay as long as you'd like - whether you have specific questions or just want to listen in.
Essential Functions for this position are followed by an (E).
As a Merit SOC Analyst, this position's key responsibilities include, but are not limited to, the following:
Merit SOC Security Support (90%):
Deliver exceptional customer service to Merit Members, external and internal customers, and Merit Partners, aiming to exceed their expectations through technical resolution and support (E);
Review and analyze cybersecurity alerts generated by the Merit SOC system for accuracy and criticality (E);
Understand network and application protocols with respect to analyzing accuracy and applicability of generated alerts (E);
Perform appropriate notifications of members of security alerts given predetermined notification agreements (E);
Perform documented isolation and containment actions for cyber threats when necessary according to pre-agreed on playbooks (E);
Review public security alerts and bulletins and understand daily and overall cybersecurity landscape and threat trends (E);
Recommend changes to SOC applications, processes, and data flows to increase productivity and accuracy and decrease time to notification;
Manage documentation and documentation workflow for internal and customer facing security practices, projects, and initiatives;
Under the leadership of Information Security team members, perform regular threat hunts of member environments to search for latent threats (E);
Develop scripts to automate instances of system auditing, monitoring and alerting;
Maintain subject matter expertise in cyber security products utilized by the Merit SOC (E);
Continually maintain professional relationships with external stakeholders and members as a trusted member of the information security community (E);
Communicate effectively with Merit SOC leadership, escalating issues as needed and providing required information and context during escalations (E);
Assist in the operation and execution of projects and initiatives as necessary;
Maintain understanding of current member cyber security needs and capabilities in relation to delivering effective SOC services;
Attend off-site meetings, conferences, and training sessions as required;
Assist with the acquisition and deployment of information security tools;
Provide clear, concise, and comprehensive updates for service tickets and all communications, tailoring messages for audiences with varying levels of technical understanding (E);
Utilize trouble tickets for response and resolution (E).
Merit MSC and Cybersecurity Support (10%):
Work with the Chief Information Security Officer in conducting internal audits, risk assessments, and cyber security projects on Merit and member IT systems and processes (E);
Assist with developing and establishing policies, procedures, and standards to maintain an appropriate cyber security risk level on Merit's internal LAN, data center environments, and service provider WAN environment;
Assist with providing member service with supported applications including hosted DNS and the Routing Assets Database (RADb).
Other Duties Please note this job description is not designated to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Supervisory Responsibility This position has no supervisory responsibilities.
Work Environment Requires working in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, cloud-based systems, and AV/teleconferencing software & equipment.
Physical Demands The physical demands described here are representative of those that must be met by an employee (with or without accommodations) to successfully perform the essential functions of this job. You must frequently work at a computer station, answering telephone calls, emails, and/or other forms of customer/client communication. You may on occasion be required to move items throughout the office or building.
Proficient in engaging with customers in a positive and supportive manner, regardless of the situation.
Associate's degree in Information Technology, IT Security, Information Assurance or related field or equivalent combination of education, certifications, and relevant experience.
Knowledge and experience with cybersecurity best practices, particularly in threat analysis, response, and mitigation.
Strong analytical, detail-oriented, and problem solving skills applicable to a cybersecurity role.
Ability to work independently, prioritize multiple projects, and achieve objectives by required deadlines while maintaining high-quality outcomes.
Hold or be willing to obtain industry leading certifications such as Security+, GIAC, or similar certifications, to ensure up-to-date competencies in cybersecurity practices.
Previous experience working within an information security team.
Familiarity with applicable laws and regulatory requirements such as HIPAA, HITECH, PCI, FERPA, ITAR, which have implications for cybersecurity operations.
Understanding of cybersecurity frameworks such as NIST, CIS or ISO cybersecurity frameworks, which help standardize security practices.
Experience with vulnerability and configuration management tools which are essential in maintaining secure systems.
Familiarity with scripting and programming languages such as Bash, Perl, PowerShell, or Python to aid in security automation tasks.
Familiarity with Docker containerization to support deploying security tools.
Experience working with higher education, K-12 educational institutions, libraries, government, healthcare, research institutions and other public sector non-profit organizations.
The University of Michigan is an equal employment opportunity employer.
A great university is made so by its faculty and staff, and Michigan is recognized as one of the best universities to work for in the country. The Michigan culture is known for engaging faculty and staff in all facets of the university to create a workplace that is vibrant and stimulating.For two consecutive years, the Chronicle of Higher Education has placed U-M in its "Great Colleges to Work For" survey. In particular, the university earns high marks for strong relations between faculty and administrators, a collaborative system of governance, strong pay and benefits, and a healthy work/life balance.