Information Security Analyst
Job Description
The Information Security Analyst role is a remote position within UChicago Medicine's Information Security department in Illinois. The analyst will monitor and respond to security events, participate in incident response on on-call rotations, and contribute to the ongoing enhancement of SOC workflows and documentation.
Responsibilities
- Assist with incident response, triage, and investigations for security events such as malware incidents, phishing campaigns, threats, and related activity.
- Utilize threat intelligence and internal knowledge to proactively hunt for active threats and indicators of malicious activity.
- Prepare incident reports, threat assessments, and security operation documentation for stakeholders.
- Contribute to the continuous improvement of security operations playbooks, documentation, trends, and lessons learned from incidents in collaboration with the Security Operations team.
- Coordinate eDiscovery requests and Insider Threat investigations in partnership with Privacy, Legal, and HR teams.
- Support Threat Hunting and Intelligence efforts, participate in detection development, automation initiatives, and SOC AI workflows.
- Investigate and respond to email-based threats such as phishing, business email compromise, malware delivery, and account takeover.
- Monitor the Security Operations service and the incident queue to ensure timely handling.
- Join the on-call rotation and respond to critical security events as required.
Requirements
- BS or BA degree in Computer Science, Engineering, or an equivalent education with relevant training or work experience.
- Four years of security experience, or an equivalent combination of training and education.
- Strong knowledge of computing systems, data network communications, and network architecture.
- Experience with security information and event management (SIEM) platforms and query languages, including Yara-L, CQL, and SPL.
- Solid understanding of network security fundamentals, Network Detection and Response (NDR), intrusion detection, incident detection/response, malware analysis, cyber forensics, SIEM concepts, and security best practices; additional duties as assigned.
- Scripting or programming skills preferred, with experience in Python, PowerShell, or Go.
- Demonstrated service orientation with strong verbal, written, and reporting abilities.
- High integrity and sound judgment regarding security and privacy.
Technologies
Key tools and languages: Yara-L, CQL, SPL, Python, PowerShell, Go, SIEM
Position Details
- Job Type / FTE: Full Time, 1.0 FTE
- Shift: Day
- Location: Remote
- Unit / Department: Information Security
- CBA Code: Non-Union