Gwynedd Mercy University logo

Information Security Analyst

Gwynedd Mercy University

On-siteGwynedd Valley, PAmidPosted 2h ago

Job description

Position Summary

Gwynedd Mercy University is looking for an Information Security Analyst to help protect the university’s systems, data, and people and continually improve our overall security posture.

This is a broad, hands-on role within a collaborative IT team. The analyst will monitor and respond to security events, identify and remediate vulnerabilities, strengthen identity and access controls, help secure endpoints and infrastructure, review technology and vendors for security risk, and support the university’s security awareness and compliance efforts.

We are looking for someone who takes ownership of problems rather than simply identifying them for someone else to solve. At the same time, this is a team environment. The right person knows when to act independently, when to collaborate, and when to escalate.

This position also works directly with students, faculty, and staff when security issues affect them. We want someone who is patient, respectful, and helpful while remaining professional and security-conscious. Being helpful does not always mean giving someone the answer they want.

We do not expect candidates to arrive knowing every system we use. Experience with our technology environment is a plus, but strong security fundamentals, intellectual curiosity, sound judgment, communication skills, and the ability to learn are more important.

We are looking for someone who brings the curiosity, judgment, initiative, technical foundation, and collaborative mindset that are much harder to teach.

Essential Responsibilities

  • Monitor security alerts, logs, endpoints, accounts, and other sources for suspicious activity; investigate events and take or coordinate appropriate action.

  • Serve as a primary technical resource for cybersecurity incidents, including phishing, compromised accounts, malware, and other security events.

  • Identify, prioritize, and help remediate vulnerabilities and security configuration weaknesses across endpoints, servers, networks, applications, and cloud services.

  • Help secure identity and access systems, including MFA, privileged access, administrative and service accounts, authentication, permissions, and account lifecycle processes.

  • Work with Infrastructure, Technical Services, and other IT staff to improve endpoint, network, server, cloud, and data security.

  • Review software, cloud services, vendors, applications, and integrations for cybersecurity and data-protection risk and recommend practical ways to mitigate identified concerns.

  • Support security frameworks, regulatory requirements, audits, cyber insurance activities, documentation, security awareness, and incident-response planning.

  • Develop and track meaningful security metrics and help identify trends, recurring weaknesses, and opportunities for improvement.

  • Work directly with students, faculty, and staff affected by security incidents, helping them restore secure access while ensuring appropriate security measures are completed.

Who We Are Looking For

The way you approach your work matters as much as the specific products you already know. We are looking for someone who:

  • Is intellectually curious and wants to understand how and why things work.

  • Takes ownership and follows problems through to resolution.

  • Wants to do excellent work and leave the organization better than they found it.

  • Communicates clearly and professionally with both technical and non-technical people.

  • Treats people with patience and respect without compromising appropriate security practices.

  • Uses good judgment when balancing security, usability, and institutional needs.

  • Works well as part of a team and can disagree constructively, explain their reasoning, and listen to other perspectives.

  • Takes initiative without becoming a cowboy and knows when to involve others.

  • Continually learns and adapts as technology and cybersecurity threats change.

Qualifications

Candidates should have professional experience in cybersecurity, systems administration, networking, infrastructure, or a related technical field, along with a strong understanding of cybersecurity fundamentals such as endpoint security, identity and access management, networking, logging and monitoring, vulnerability management, authentication, and incident response.

Experience with EDR, SIEM/logging platforms, vulnerability scanners, firewalls, identity systems, or similar security technologies is expected.

A bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field is welcome but is not required with equivalent relevant professional experience.

Experience with our environment is preferred but not required. Technologies currently used at the university include Microsoft Defender and Microsoft security technologies, Entra ID, Microsoft 365, Intune, Windows and Windows Server, macOS, Linux, MFA/SSO technologies, vulnerability and monitoring tools, and KnowBe4.

Experience with Microsoft security technologies, higher education, NIST/CIS frameworks, FERPA, GLBA, PCI-DSS, or relevant certifications such as Security+, CySA+, CISSP, or GIAC is helpful but not required.

EOE Statement: Gwynedd Mercy University is committed to maintaining a positive learning, working, and living environment that is free from unlawful discrimination and harassment. Gwynedd Mercy University does not discriminate against any applicant for admission to or employment at the University because of race, religion, age, gender, sexual orientation, gender identity, national origin, disability, color, marital status, veteran status, genetic characteristics, or any other characteristic protected by federal, state, or local law (‘Protected Classes’). This includes, but is not limited to, admissions, financial aid, educational services, and student programs and activities, as well as to all terms and conditions of employment including, but not limited to, recruitment, selection, hiring, placement, transfer, promotion, training, compensation, benefits, discipline, and termination. The University will not tolerate unlawful acts of discrimination or harassment based upon Protected Classes, or related retaliation against or by any employee or student.