{"21663732":{"jobPath":"/jobs/21663732/senior-director-privacy-and-cybersecurity","source":"naylor","job":"21663732","jobTitle":"Senior Director, Privacy and Cybersecurity"},"21682198":{"jobPath":"/jobs/21682198/clinical-application-professional-4-beaker-is-epic-ft-day-remote","source":"naylor","job":"21682198","jobTitle":"Clinical Application Professional 4 -Beaker - IS - Epic - FT - Day - Remote"},"21634238":{"jobPath":"/jobs/21634238/associate-vice-president-of-audit-services-and-institute-compliance-chief-compliance-officer","source":"naylor","job":"21634238","jobTitle":"Associate Vice President of Audit Services and Institute Compliance & Chief Compliance Officer"},"21600937":{"jobPath":"/jobs/21600937/senior-it-auditor","source":"naylor","job":"21600937","jobTitle":"Senior IT Auditor"},"21568027":{"jobPath":"/jobs/21568027/it-audit-manager","source":"naylor","job":"21568027","jobTitle":"IT Audit Manager"},"21653924":{"jobPath":"/jobs/21653924/information-systems-auditor-auditor-iv","source":"naylor","job":"21653924","jobTitle":"Information Systems Auditor (Auditor IV)"},"21681559":{"jobPath":"/jobs/21681559/computer-science-and-information-technology-tenure-track-instructor","source":"naylor","job":"21681559","jobTitle":"Computer Science and Information Technology (Tenure Track) Instructor"},"21623566":{"jobPath":"/jobs/21623566/senior-internal-audit-data-analyst","source":"naylor","job":"21623566","jobTitle":"Senior Internal Audit Data Analyst"},"21681557":{"jobPath":"/jobs/21681557/museum-security-guard-part-time","source":"naylor","job":"21681557","jobTitle":"Museum Security Guard (Part-Time)"},"21680962":{"jobPath":"/jobs/21680962/information-security-engineer-intermediate","source":"naylor","job":"21680962","jobTitle":"Information Security Engineer Intermediate"},"21521706":{"jobPath":"/jobs/21521706/it-audit-division-director","source":"naylor","job":"21521706","jobTitle":"IT Audit Division Director"},"21636806":{"jobPath":"/jobs/21636806/senior-it-and-data-analytics-internal-auditor","source":"naylor","job":"21636806","jobTitle":"Senior IT and Data Analytics Internal Auditor"},"21681550":{"jobPath":"/jobs/21681550/assistant-professor-of-government-american-politics","source":"naylor","job":"21681550","jobTitle":"Assistant Professor of Government (American Politics)"},"21680980":{"jobPath":"/jobs/21680980/tier-2-support-analyst-it-service-center","source":"naylor","job":"21680980","jobTitle":"Tier 2 Support Analyst, IT Service Center"},"21682186":{"jobPath":"/jobs/21682186/clinical-application-professional-3-beaker-is-epic-ft-day-hybrid","source":"naylor","job":"21682186","jobTitle":"Clinical Application Professional 3 - Beaker - IS Epic - FT - Day - Hybrid"},"21670759":{"jobPath":"/jobs/21670759/vice-president-office-of-audit-compliance-and-privacy","source":"naylor","job":"21670759","jobTitle":"Vice President, Office of Audit, Compliance and Privacy"},"21620258":{"jobPath":"/jobs/21620258/technology-audit-manager","source":"naylor","job":"21620258","jobTitle":"Technology Audit Manager"},"21653811":{"jobPath":"/jobs/21653811/chief-regulatory-and-government-affairs-officer-crgao","source":"naylor","job":"21653811","jobTitle":"Chief Regulatory and Government Affairs Officer (CRGAO)"},"21680999":{"jobPath":"/jobs/21680999/tier-1-support-analyst-it-service-center","source":"naylor","job":"21680999","jobTitle":"Tier 1 Support Analyst, IT Service Center"},"21681545":{"jobPath":"/jobs/21681545/cybersecurity-analyst","source":"naylor","job":"21681545","jobTitle":"Cybersecurity Analyst"},"21681765":{"jobPath":"/jobs/21681765/liaison-it-user-support-office-of-medical-computing","source":"naylor","job":"21681765","jobTitle":"Liaison IT User Support, Office of Medical Computing"},"21681920":{"jobPath":"/jobs/21681920/information-security-operations-analyst","source":"naylor","job":"21681920","jobTitle":"Information Security Operations Analyst"},"21680212":{"jobPath":"/jobs/21680212/cybersecurity-engineer-it-security-specialist-3-provisional","source":"naylor","job":"21680212","jobTitle":"Cybersecurity Engineer (IT Security Specialist 3) - Provisional"},"21681587":{"jobPath":"/jobs/21681587/security-officer","source":"naylor","job":"21681587","jobTitle":"Security Officer"},"21682753":{"jobPath":"/jobs/21682753/cyber-security-engineer","source":"naylor","job":"21682753","jobTitle":"Cyber Security Engineer"}}
The Information Security Operations Analyst supports security operations for the Ohio Technology Consortium (OH-TECH) and will work as part of a team responsible for operational cybersecurity across a consortium of technology organizations supporting research, education, and public services in Ohio.
The Information Security Operations Analyst position plays a pivotal role in driving vulnerability prioritization, secure configuration compliance, and organizational risk reduction. It is essential to the ongoing protection and integrity of the organizations digital infrastructure.
Responsibilities of the position include:
Conduct regular scans of endpoints, servers, and network devices to identify weaknesses in systems, networks, and applications. Analyze the results and track remediation efforts to ensure vulnerabilities are resolved or appropriately mitigated by collaborating with IT teams to develop and implement mitigation strategies, including patch management, configuration changes, and system hardening.
Utilize Splunk for proactive threat hunting, analyzing security logs and system data to identify anomalies, detect potential threats, and support incident response. Leverage advanced search queries, dashboards, and correlation rules to uncover indicators of compromise and enhance situational awareness across the environment.
Implementation and testing of incident response plans, including engaging tabletop exercises, are supported to ensure preparedness and effective handling of security incidents.
The candidate should possess an analytical mindset and an inquisitive nature. Strong troubleshooting and problem-solving abilities are essential, along with the capacity to work under pressure and meet multiple deadlines while being patient with non-technical end users. This role involves working in a fast-paced, ever-changing environment with talented teams.
The Information Security Operations Analyst must quickly grasp new concepts, collaborate effectively, and adapt to working with diverse teams. They should follow established processes and create defensible procedures when none exist. Strong project management, organizational, and communication skills are essential to work with cross-functional teams and balance competing priorities.
The Security Operations Analyst is often required to be accessible via phone when not in the office and have internet access to perform certain work duties from home; after hours and weekend work may be required. The Analyst needs to bring a combination of technical expertise, critical thinking, and a strong commitment to the organizations mission. This role requires excellent communication and collaboration skills to convey technical information to diverse audiences. This position reports to the Security Program Director.
OH-TECH, the technology and information division of the Ohio Department of Higher Education (ODHE), serves as the central organization for Ohios statewide technology infrastructure entities: OARnet, the Ohio Supercomputer Center (OSC), and OhioLINK (Ohio Library and Information Network). OH-TECH delivers advanced technological solutions to Ohios higher education institutions, catalyzing innovation in the modern knowledge economy. The organization prides itself on being a welcoming and supportive work environment.
Because The Ohio State University serves as OH-TECHs fiscal and legal agent, OH-TECH staff enjoy the same benefits as other Ohio State employees, including participation in the Ohio Public Employees Retirement System (OPERS), the Ohio State Health Plan, employee wellness and work-life balance programs, educational benefits, discount programs and more.
Required Education/Experience:
Bachelor's degree or equivalent combination of education and experience in information technology, information security, cybersecurity, digital forensics, or other relevant fields.
2 years of demonstrated experience with vulnerability scanning tools (Qualys, Tenable/Nessus, Rapid7).
Knowledge of computer security concepts, procedures, and best practices for security and security operations including VMS, incident response, threat management, and log analysis.
Excellent problem-solving, analytical, and troubleshooting skills.
Strong understanding of operating systems, networks, secure application development concepts.
Demonstrated working knowledge of NIST Special Publication 800 series (e.g., NIST 800-53, NIST 800-63, and NIST 800-171), and other regulatory and legislative authorities including but not limited to HIPAA, FERPA, FISMA.
Desired Education/Experience:
Experience with Spirion/Identify Finder, Splunk, CIS Benchmarks, computer imaging, and data recovery processes; Linux and Windows systems administration; authentication (including multifactor) and encryption systems.
Experience creating and managing Jira boards, workflows, and dashboards.
Familiarity with Confluence for maintaining project documentation, knowledge bases, and team collaboration spaces.
Service Now ITSM.
Security+, CySA+, CISSP, CRISC, CISM , CISA, or other relevant security certifications.
Function: Information Technology
Subfunction: Information Security and Risk Management
Career Band: Individual Contributor Specialized
Career Level: S2 Experienced
OSU and OH-TECH will not sponsor applicants for work visas for this position.