Enter a job title or keyword

Cybersecurity Analyst


Job Location:

San Francisco, CA - USA

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (Yesterday)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

Description

Certain terms and conditions of employment for this position including the rate of pay benefits etc. are currently subject to negotiation with the appropriate union.

We are seeking an experienced and versatile Cybersecurity Analyst to join our Cyber Risk Management team and help strengthen cybersecurity across a complex academic healthcare and research environment. This position will play a key role in our Human Risk and Cybersecurity Awareness program developing and operating engaging security awareness initiatives simulated phishing campaigns communications and outreach designed to measurably reduce human-related cyber risk. The analyst will work with diverse communitiesincluding healthcare professionals researchers faculty staff and studentsto transform emerging threats into practical audience-appropriate guidance that improves security behavior and strengthens our overall security culture.

Beyond Human Risk this is a well-rounded cybersecurity role with opportunities to contribute across Cyber Risk Management governance compliance research security and enterprise security initiatives. The analyst will support cybersecurity policies and standards risk assessments compliance and audit activities and cross-functional security initiatives in partnership with IT Privacy Compliance Research and other stakeholders. We are looking for a security professional who can operate independently communicate effectively with both technical and non-technical audiences manage multiple initiatives and translate cybersecurity risks into actionable recommendations. Experience working in regulated or complex enterprise environments is highly desirable with familiarity in areas such as HIPAA cybersecurity GRC NIST frameworks data privacy security risk management and security awareness technologies considered valuable.

Department Overview

UCSF Cybersecurity protects and responds to both internal and external threats. It monitors for vulnerabilities risks and exposures and mitigates issues prior to exploitation. If an incident does occur IT Security investigates determines impact and recommends controls for reduced recurrence likelihood.

  • Vulnerability Management
  • Network Security
  • Application Security
  • E-Discovery service
  • Incident response and forensic analysis
  • Threat hunting and event analysis
  • Establishing policies and standards for information security
  • Providing guidance and conducting risk assessments of systems and solutions
  • Governance risk and compliance
  • Architecting secure business solutions
  • Architecting threat detection security monitoring and forensic solutions
  • Outreach and security awareness training and education
  • Endpoint security such as encryption anti-malware endpoint detection and response



Responsibilities

%

of time

Essential Function (Yes/No)

Key Responsibilities

(To be completed by Supervisor)

35

Develop manage and operate security awareness programs. Plan organize and deliver comprehensive cybersecurity training and awareness activities (e.g. phishing simulations workshops e-learning) targeting students faculty healthcare providers and staff. Create engaging content (e.g. videos newsletters campaigns) and ensure training effectively changes user behavior to reduce human risk

15

Governance and policy support. Assist in developing and updating cybersecurity policies standards and guidelines. Ensure awareness initiatives align with regulatory requirements (HIPAA FERPA etc.) and enterprise security policies. Help coordinate policy communication so that all community members understand and follow requirements

10

Regulatory and technical training. Provide specialized training on relevant regulations (e.g. HIPAA data privacy laws research compliance) and IT security concepts (e.g. secure data handling mobile device security) to varied audiences. Work with curriculum and compliance teams to incorporate cybersecurity topics into mandatory training for healthcare workers and research staff.

10

Communications and outreach. Create clear accessible communications (email bulletins web content posters) to reinforce security best practices. Represent the department at campus events (e.g. Cybersecurity Awareness Month training fairs) and engage campus and affiliate communities in security culture. Tailor messages to diverse groups (students researchers clinicians) based on their needs

10

Project management support. Assist the Manager and CISO on departmental projects. Provide project planning scheduling and progress reporting for initiatives like compliance audits risk assessments and security campaigns. Coordinate with IT and operational teams to ensure timely project execution and follow-up.

5

Collaboration with UC and external partners. Participate in UC systemwide security working groups sharing best practices and policies. Maintain relationships with security training vendors and professional networks. Leverage these resources to enhance the awareness program and stay current on effective training techniques.

5

Other related duties as assigned. Performs additional tasks consistent with departmental needs and bargaining-unit guidelines.

10

Cybersecurity Research Security support. Provides miscellaneous Cybersecurity Research Security team support activities as assigned including coordination of research security communications meeting support tracking action items MCA POAM documentation updates training records compliance evidence collection stakeholder follow-up and other audit/assessment related program support duties consistent with the IT Security Analyst classification and departmental needs.

0%

(To update total % enter the amount of time in whole numbers (without the % symbol - e.g. 15 20) then highlight the total sum (e.g. 1%) at the bottom of the column and press F9. The total sum should add up to 100%.)


Qualifications

REQUIRED QUALIFICATIONS

  • Bachelors degree in Computer Science Information Security Education Communications or a related field (or equivalent experience).

  • Minimum related experience 5 years
  • Communication: Able to translate complex security concepts into clear concise messages for diverse audiences (students faculty clinicians IT staff)
  • Security Expertise: Broad knowledge of information security principles risk management and threat landscape. Familiarity with NIST or similar frameworks. Understanding of healthcare and research privacy requirements (HIPAA FERPA) and how to incorporate them into training
  • Project Management: Strong organizational and planning skills. Experience managing projects from conception through implementation including scheduling resource coordination and reporting
  • Collaboration: Proven ability to work cross-functionally with IT legal/compliance clinical and academic stakeholders. Skilled at coordinating people and tasks across departments to achieve security goals.

REQUIRED CERTIFICATIONS

  • Relevant professional certifications preferred (e.g. CISSP CISM Security). Certification or coursework in security awareness instructional design or project management is desirable.

PREFERRED QUALIFICATIONS

  • Training & Education: Proficiency with training design and delivery (e.g. adult learning e-learning platforms phishing simulation tools). Ability to evaluate training effectiveness and metrics (completion rates assessment results).

  • Analytical Skills: Problem-solving mindset and attention to detail. Able to assess program outcomes identify areas for improvement and adapt strategies accordingly. Basic understanding of information risk concepts is required




Required Experience:

IC


About Company

About UCSF The University of California, San Francisco (UCSF) is a leading university dedicated to promoting health worldwide through advanced biomedical research, graduate-level education in the life sciences and health professions, and excellence in patient care. It is the only camp ... View more

View Profile View Profile