Career Opportunities at UDC >> Sr. Security Analyst
Sr. Security Analyst
Summary
Title:Sr. Security Analyst
ID:2635
Department:Information Services and Management
Location:UDC- Main Campus Van Ness Campus – NW
Description

Number of Vacancies: 1

Area of Consideration: Open To The Public 

Position Status: Full-Time, Regular

Pay Plan, Series & Grade: DS0058/2B

Salary Range: $111,593- $125,494

Closing Date: Open Until Filled

Location: 4200 Connecticut Ave NW, Washington, DC 20008

Brief Description of Duties

The Senior Security Analyst and Team Lead is a crucial role within the Information Security team, responsible for leading security operations, managing security analysts, and ensuring the security posture of the organization is consistently maintained and improved.

This role blends technical expertise in security technologies—such as Endpoint Detection and Response (EDR), Cloud Security, and Enterprise Privileged Management (EPM)—with leadership responsibilities to guide a team of security professionals. The Sr. Security Analyst and Team Lead will focus on threat detection, incident response, vulnerability management, and governance, risk, and compliance (GRC), providing direction and mentorship to junior analysts.

As a senior leader in the security team, this position will play an integral role in the design, implementation, and management of security controls that align with business objectives and regulatory requirements. The ideal candidate will have a deep understanding of the threat landscape and will leverage their technical skills to analyze and respond to security events while building a culture of security awareness throughout the organization.

Essential Duties and Responsibilities

Leadership & Team Management:

  • Lead and mentor a team of security analysts, providing guidance on day-to-day operations and career development.
  • Oversee the daily security operations, including monitoring, detection, and response to security incidents.
  • Act as a subject matter expert and escalation point for complex security incidents, ensuring proper investigation, containment, and resolution.
  • Foster a collaborative team environment focused on continuous learning, sharing of knowledge, and improvement of security practices.
  • Manage workload distribution, team assignments, and resource allocation to ensure optimal performance and adherence to security protocols.

Incident Response and Threat Management:

  • Lead the organization’s incident response program, ensuring incidents are detected, triaged, and resolved in a timely manner.
  • Investigate and analyze security events, including threat hunting and forensic analysis, using EDR solutions and other security monitoring tools.
  • Coordinate cross-functional efforts during security incidents, working closely with IT, legal, compliance, and business units to ensure timely communication and resolution.
  • Develop and refine playbooks and runbooks for incident response, ensuring that the team is prepared for emerging threats.

Security Operations and Vulnerability Management:

  • Oversee the vulnerability management program, ensuring that security vulnerabilities are identified, prioritized, and remediated in coordination with IT and DevOps teams.
  • Regularly assess the security posture of cloud environments (AWS, Azure, or GCP) and on-premises infrastructure, ensuring compliance with internal policies and external regulations (e.g., SOC 2, ISO 27001, PCI DSS).
  • Monitor and manage security technologies such as firewalls, IDPS, EDR, DLP, and cloud security controls, ensuring they are configured and performing optimally.
  • Develop and maintain a comprehensive knowledge base of security advisories, threat intelligence, and best practices to stay ahead of emerging security risks.

Zero Trust Security Architecture:

  • Lead the strategy and execution of a Zero Trust security architecture, ensuring continuous verification of user identities, devices, and contextual risk before granting access to resources.
  • Work with IT, DevOps, and other teams to implement Zero Trust principles across network, cloud, and application environments, ensuring that the "least privilege" model is enforced consistently.
  • Continuously monitor and enhance the Zero Trust framework to align with evolving security threats and business requirements.

Governance, Risk, and Compliance (GRC):

  • Serve as member of a distributed GRC team to ensure security operations align with regulatory requirements and industry standards.
  • Conduct regular risk assessments, providing actionable recommendations to mitigate risks and improve security controls.
  • Support audit and compliance efforts by providing evidence of security operations and vulnerability management practices during internal and external audits.
  • Assist in the development, review, and enforcement of security policies and procedures, ensuring compliance with frameworks like NIST, ISO 27001, and CIS.

Security Awareness and Training:

  • Lead efforts to enhance security awareness within the organization, conducting regular training sessions for employees, IT staff, and leadership.
  • Provide guidance on secure coding practices, secure configuration, and data protection to development and IT teams.
  • Communicate complex security concepts and risk assessments to both technical and non-technical stakeholders, ensuring a clear understanding of security priorities and initiatives.

Security Monitoring and Reporting:

  • Develop key performance indicators (KPIs) and metrics for security operations, regularly reporting on security incidents, vulnerabilities, and compliance status to senior management.
  • Continuously improve monitoring and alerting capabilities, ensuring the security operations center (SOC) is equipped with the right tools and processes for effective threat detection and response.
  • Design and implement dashboards for real-time security monitoring, ensuring visibility into critical security events across on-premises and cloud environments.

Minimum Job Requirements

  • A minimum of 5 years of hands-on experience in cybersecurity roles, with a focus on security operations, incident response, and vulnerability management.
  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field; relevant certifications such as CISSP, CEH, GIAC, or GCIH preferred.
  • Experience leading or mentoring a team, with demonstrated leadership capabilities in a security operations setting.
  • Proven experience working with EDR, Cloud Security (AWS, Azure, or GCP), and vulnerability management tools.
  • Strong understanding of security frameworks, including NIST, ISO 27001, and CIS, with experience supporting compliance initiatives (e.g., SOC 2, PCI DSS).
  • Advanced knowledge of network security, endpoint protection, threat intelligence, and incident response methodologies.
  • Hands-on experience with SIEM platforms, security orchestration and automation (SOAR) tools, and cloud security posture management (CSPM).


Information to Applicant

Collective Bargaining Unit (Union): This position is not part of the collective bargaining unit.  

Employment Benefits: Selectee will be eligible for health and life insurance, annual (vacation) and sick leave and will be covered under the University of the District of Columbia' s retirement plan (TIAA).

Equal Opportunity Employer: The District of Columbia Government is an Equal Opportunity Employer. All qualified candidates will receive consideration without regard to race, color, religion, national origin, sex, age, marital status, personal appearance, sexual orientation, family responsibilities, matriculation, physical handicap, or political affiliation.

Notice of Non-Discrimination: In accordance with the D.C. Human Rights Act of 1977, as amended, D.C. Official Code, Section 2-1401.01 et. seq., (Act) the University of the District of Columbia does not discriminate on the basis of actual or perceived actual race, color, religion, national origin, sex, age, disability, sexual orientation, gender identity or expression, family responsibilities, matriculation, political affiliation, marital status, personal appearance, genetic information, familial status, source of income, status as a victim of an intrafamily offense, place of residence or business,  or status as a covered veteran, as provided for and to the extent required by District and Federal statutes and regulations. Sexual harassment is a form of sex discrimination which is also prohibited by the Act.  In addition, harassment based on any of the above protected categories is prohibited by the Act.  Discrimination in violation of the Act will not be tolerated.  Violators will be subject to disciplinary action.

Veterans Preference:  Applicants claiming veterans preference must submit official proof at the time of application.

Visa Sponsorship: At this time, the University of the District of Columbia does not provide sponsorship for visas (e.g. H-1B). This position is also ineligible for Optional Practical Training (OPT).

Residency Preference: A person applying for a position who is a bona fide District resident at the time of application for the position, may be awarded a 10-point residency preference over non-District applicants, unless the person declines the preference points. If selected, the person shall be required to present no less than 8 proofs of bona fide District residency on or before the effective date of the appointment and maintain such residency for 7 consecutive years from the effective date of the appointment. Failure to maintain bona fide District residency for the 7-year period will result in forfeiture of employment.

Drug-Free Workplace: Pursuant to the requirements of the Drug-Free Workplace Act of 1988, the individual selected to fill this position will, as a condition of employment, be required to notify his/her immediate supervisor, in writing, not later than five (5) days after conviction of any criminal drug statute occurring in the workplace.

Background Investigation: Employment with the University of the District of Columbia is contingent upon a satisfactory background investigation.  The determination of a "satisfactory background investigation" is made at the sole discretion of the University of the District of Columbia.  The University may refuse to hire a finalist, rescind an offer of employment to a finalist or review and may terminate the employment of a current employee based on the results of a background investigation.

Disposition of Resume: Resumes received outside the area of consideration and/or after the closing date will not be given consideration. You must resubmit your resume to receive consideration for any subsequent advertised position vacancies. For the purpose of employment, resumes are not considered job applications. Therefore, if selected for employment a UDC application will be required.

Job Offers: Official Job Offers are made by the University of the District of Columbia, Office of Human Resources only.

Contact Information:  All inquiries related to employment and job applications should be directed to UDC Office of Human Resources at (202) 274-5380.

The University of the District of Columbia is an Equal Opportunity/Affirmative Action institution. Minorities, women, veterans and persons with disabilities are encouraged to apply. For a full version of the University’s EO Policy Statement, please visit: https://www.udc.edu/human-resources/equal-opportunity/ .

ApplicantStack powered by Swipeclock