UC Berkeley’s Information Security Office is hiring an IT Security Analyst to support the Security Engineering team. In this onsite role in Berkeley, you will help manage and administer security engineering systems, implement security controls, and provide technical support for investigations and incident response, including work that may occur outside standard hours.
Role Overview
As a seasoned analyst, you will research and deploy security solutions, implement best-practice controls, and support systems management through automation. The position also involves assisting with DevOps processes to provision and manage systems, as well as writing and executing complex scripts for log analysis and security operations across integrated systems.
Responsibilities
- Manage Information Security Office systems, including installation, configuration, maintenance, and ongoing support for systems and software.
- Implement security controls based on best practices to prevent malicious intrusion.
- Research, evaluate, and implement systems, services, and technologies that support Information Security Office systems and services.
- Support system and device enhancements such as software, hardware, and network configuration, including updates and installations for projects or services of moderately complex scope.
- Write and execute complex scripts to support systems management, log analysis, and other duties across multiple integrated systems.
- Assist in implementing and maintaining DevOps processes that automate systems provisioning and management.
- Implement complex, broad-scale security controls to prevent and detect unauthorized access or changes to campus hardware, software, and network infrastructure, including FireWalls, IDS/IPS, EDR agents, vulnerability scanners, and SIEM.
- Provide research, analysis, and solutions to address attempted compromises of security protocols.
- Advise the campus community on security prevention, best practices, and secure software.
- Act as a subject matter expert by providing analysis and context for security investigations and incidents.
- Triages security incidents and support tickets as part of periodic analyst rotation; may participate in responding to security events and operational issues requiring immediate attention during and/or outside standard hours, including evenings, weekends, and holidays.
- Participate in professional development and training to maintain expertise in information security, security engineering, and related technologies.
- Stay current on evolving threats and tools, contribute to team knowledge sharing and documentation, and perform other duties as assigned.
Required Qualifications
- Experience reading and interpreting logs from enterprise IT applications and services, with focus on security-relevant logs.
- Ability to follow and/or learn department processes and procedures.
- Interpersonal skills to work effectively with both technical and non-technical stakeholders at multiple levels.
- Experience using IT security systems and tools, including IDS, vulnerability scanners, firewalls, and SIEM.
- Advanced knowledge of computer security best practices and policies, with demonstrated experience securing server-based software.
- Demonstrated skill administering complex security controls and configurations across computer hardware, software, and networks.
- Knowledge of hardware, software, and network security issues and approaches.
- Experience with Linux systems, particularly Red Hat Enterprise Linux.
- Familiarity with web servers, load balancers, firewalls, and DNS.
- Ability to write clear and concise technical documentation.
- Understanding of system performance monitoring and actions to improve or correct performance.
- General knowledge of other IT areas.
- Thorough understanding of systems and security issues and corrective actions.
- Experience automating systems build and provisioning using tools such as Ansible and Terraform.
- Bachelor’s degree in a related area and/or equivalent experience or training.
Technologies
Intrusion Detection Systems, Vulnerability Scanners, Firewalls, SIEM, Linux systems, Redhat Enterprise Linux, web servers, load balancers, DNS, Ansible, Terraform, FireWalls, IDS/IPS, Endpoint Detection and Remediation (EDR agents), Kafka, Elasticsearch, containerized systems, Ruby, Python, Go, Logstash, Kibana, Elastic Security.
Preferred Qualifications
- Experience in incident response and digital forensics, including data collection, examination, and analysis.
- Experience designing, deploying, and maintaining distributed systems, particularly Kafka and Elasticsearch.
- Experience deploying containerized systems in a production environment.
- Ability to read and write code in one or more of Ruby, Python, Go.
- Experience with the Elastic ecosystem, particularly Logstash, Kibana, and Elastic Security.
Compensation and Employment Details
- Location: Berkeley, CA 94720 (onsite)
- Salary: USD 91,500 - 120,000 per year (budgeted annual range)
- Employment: Full-time (40 hours/week), exempt monthly-paid career position eligible for UC benefits
Application Review Information
- First review date: August 7, 2026 (apply on or before this date for full consideration)