Cybersecurity Analyst Tier 2 Job Summary Information Security Analysts The University of Utah has an opportunity for a Cybersecurity Analyst Tier 2 (Security Operations Center) to help support our Information Security and Compliance goals. The Tier 2 SOC analyst will drive mid-tier incident investigations, perform root cause analysis, and help optimize our operational capabilities. Operating as the primary escalation bridge between Tier 1 monitoring and Tier 3 engineering, you will handle
complex security events, collaborate closely with Tier 3 analysts to tune detection rules, refine response playbooks, and mentor junior analysts. About UIT : University Information Technology (UIT) , the central IT service provider for the University of Utah, reports to the U's Chief Information Officer and is responsible for many of the U's shared IT services including the wired and wireless network; Campus Information Services (CIS) portal; UMail, telephone, and online collaboration; digital learning technologies; information security; software licensing; and a host of other IT systems and services. About the University of Utah : Located in Salt Lake City, the U is the flagship institution of the State of Utah's system of higher education, home to arts and museum venues and a member of the BIG-12 Conference . Skiing and snowboarding opportunities are a short distance from campus, and opportunities to pursue activities from biking to hiking to fishing abound . Salt Lake City is home to the Utah Symphony and Opera , Ballet West , professional sports teams , and a wide range of other cultural and recreational activities. Responsibilities Information Security Analyst II Incident Response: - Perform in-depth investigations, root cause analysis, and containment activities for escalated, complex, or multi-vector security incidents across endpoint, network, cloud, and identity domains - Serve as the primary escalation point for Tier 1 analysts, providing technical guidance during active triage and validating escalation quality. - Perform initial scoping and technical artifact analysis to support response actions and prevent incident propagation. - Draft clear, detailed incident postmortem reports and document technical findings for internal stakeholders. Detection & Playbook Optimization: - Partner with Tier 3 analysts to tune, refine, and update existing detection logic across SIEM, EDR, and cloud security platforms to reduce false positives and improve alert fidelity. - Identify detection coverage gaps and telemetry blind spots during investigations, providing actionable recommendations to Tier 3 for new rules or detection enhancements. - Assist Tier 3 analysts in testing, providing feedback on, and maintaining automated response workflows (SOAR) to streamline routine SOC tasks. Threat Analysis: - Analyze complex adversary behavior from escalated alerts, mapping attack paths to the MITRE ATT&CK framework. - Assist Tier 3 analysts in executing structured, hypothesis-driven threat hunting campaigns across corporate and cloud environments. - Operationalize threat intelligence updates by executing indicator-of-compromise (IOC) sweeps (threat hunting) and validating threat exposure. Leadership & Team Support: - Mentor and develop Tier 1 SOC analysts through regular shift handovers, technical guidance, and investigation peer reviews. - Identify operational bottlenecks and propose improvements to SOC workflows and triage procedures. - Partner with internal IT and platform teams to address logging gaps and remediate host- or network-level security weaknesses. Job Code: P34212Grade: P17 Minimum Qualifications EQUIVALENCY STATEMENT: 1 year of higher education can be substituted for 1 year of directly related work experience (Example: bachelor's degree = 4 years of directly related work experience). Information Security Analyst, II: Requires a bachelor's (or equivalency) + 4 years or a master's (or equivalency) + 2 years of directly related work experience. Preferences Experience: 4 years dedicated cybersecurity operations, threat triage, or incident response experience in a SOC environment. Technical mastery: Strong expertise analyzing logs across Windows/Linux, cloud environments (AWS, Azure, GCP), network traffic (PCAP, NetFlow), and identity platforms (Entra ID, Okta). Querying & Log Analysis: Proficiency using platform query languages (e.g. KQL, SPL, YARA) for deep investigation, log correlation, and evaluating rule performance. Framework Alignment: Practical working knowledge of applying the MITRE ATT&CK framework to real-world investigations, triage workflows, and post-incident reporting. Certifications (Preferred): GCIH, GCFA, GSOC, SC-200, CCSP. Soft Skills: Excellent analytical problem-solving skills and a strong passion for teaching and elevating junior team members. A demonstrated ability to write complex technical reports for a non-technical audience. Special Instructions Requisition Number: PRN46212B Full Time or Part Time? Full Time Work Schedule Summary: Four ten hour shifts a week. Position will rotate between day and evening shifts to include holidays and weekends. Department: 00954 - UIT Systems & Security Location: Campus Pay Rate Range: $73,000.00 - 93,000.00 Close Date: 09/22/2026 Open Until Filled: To apply, visit https://apptrkr.com/9829262 "">https://utah.peopleadmin.com/postings/209249 je-e4cc9992b5184446be93ad5f762887fc
This is a Preview Listing…
You must sign in to see the full job description, and to apply.
Manage / Upgrade this job to a Full Job Listing.
Find Your Best Opportunity
Tell them AcademicJobs.com sent you!

